ISO/IEC 27005 Risk Manager with EBIOS: managing information security risks
Cybersecurity decisions become more relevant when based on explicit risk analysis. Structure scenarios, assess impacts and select appropriate responses. Develop a method for explaining priorities and connecting protective measures to business concerns.
- Duration
- 5 days 35 hours
- Code
- ISO27005EB Code
- Certification
- PECB ISO/IEC 27005 Certification — Information Security Risk Management Certification
Accredited training for the PECB ISO/IEC 27005 Certification — Information Security Risk Management certification.
Presentation
Managing information security risks is a strategic priority for any organisation seeking to protect its information assets. The ISO/IEC 27005 standard provides guidance for identifying, analysing, evaluating and treating information security risks, complementing the requirements of the ISO/IEC 27001 standard. The EBIOS Risk Manager method, published by ANSSI, provides a practical, operational framework for conducting cyber risk assessments.
This course provides the knowledge and skills to manage information security risks using ISO/IEC 27005:2022 and EBIOS Risk Manager. Case studies and practical exercises develop expertise you can apply directly to risk assessments, risk lifecycle management and supporting an ISMS compliant with ISO/IEC 27001:2022.
By the end of the program, you will be ready to take two official PECB exams: ISO/IEC 27005 Risk Manager and EBIOS Risk Manager, both included in our offer. Depending on your professional experience, you can obtain one of the associated PECB certifications (see the certification tab for details).
Objectives
By the end of this ISO/IEC 27005 Risk Manager with EBIOS course, you will be able to:
- understand and apply information security risk management principles, tools and methodologies under ISO/IEC 27005:2022 and ISO 31000:2018;
- master EBIOS Risk Manager and conduct an end-to-end cyber risk assessment;
- identify, analyse, evaluate, treat and communicate information security risks;
- develop, manage and maintain an information security risk management program within an organisation;
- understand the relationships between information security risk management, security controls and compliance with ISO/IEC 27001:2022;
- compare the main risk assessment methods: OCTAVE, MEHARI, NIST and CRAMM;
- prepare for and pass both official PECB exams to obtain PECB Certified ISO/IEC 27005 Risk Manager and PECB Certified EBIOS Risk Manager certification.
Program
Day 1: Introducing information security risk management under ISO/IEC 27005:2022
- Basic risk management concepts: impact, threat and vulnerability.
- Standards and frameworks: ISO/IEC 27005:2022, ISO/IEC 27001:2022 and ISO 31000:2018.
- Guidance for risk analysis methodologies.
- Reviewing analysis objectives with managers.
- Quantitative and qualitative risk assessment approaches.
Day 2: Assessing, treating and managing risks under ISO/IEC 27005:2022
- Asset classification.
- Risk identification, analysis and evaluation.
- Risk treatment options and reduction plans through security measures.
- Risk management governance.
- Comparing major risk management methodologies: EBIOS Risk Manager, MEHARI, OCTAVE, CRAMM and NIST.
Day 3: Initiating a risk analysis with EBIOS Risk Manager
- Introduction to EBIOS Risk Manager and risk concepts.
- The 5 EBIOS Risk Manager workshops.
- Essential elements of an EBIOS assessment.
Practical exercises
- Applying EBIOS Risk Manager in small groups to a predefined case.
Day 4: Applying EBIOS Risk Manager
- Using the method's results to support:
- the Statement of Applicability (SoA);
- the security policy under ISO/IEC 27001 requirements;
- the ISMS security action plan.
- Conducting a risk analysis.
- Expressing security needs.
- Identifying and analysing vulnerabilities.
Day 5: Concluding a risk analysis with EBIOS Risk Manager
- Residual risk analysis.
- Security objectives.
- Risk coverage and the treatment plan.
Practical exercises
- Applying the full EBIOS Risk Manager method in small groups to a predefined case.
Final half-day
- Reviewing key points covered throughout the course.
- Detailed presentation of both certification exams, including structure, format and topics.
- Exam success guidance: methodology and time management.
Audience
This course is for professionals involved in risk management and information security, including:
- information security managers and consultants responsible for managing information security or aligning it with ISO/IEC 27001:2022;
- information security team members and risk managers involved in a risk management program who want to master EBIOS Risk Manager;
- project managers and consultants seeking dual PECB certification in information security risk management.
Prerequisites
The following prerequisites apply:
- Technical skills: experience in information security or risk management.
- Theoretical background: general knowledge of information security concepts and ISO/IEC 27001:2022 requirements.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- Two PECB certifications included: both official exams, PECB Certified ISO/IEC 27005 Risk Manager and PECB Certified EBIOS Risk Manager, are included in our offer.
- Approved by Club EBIOS: PECB is officially approved by Club EBIOS to award EBIOS Risk Manager certification.
- Practical work on real cases: small-group exercises, case studies and full application of both methods to practical scenarios.
- 21 CPD credits: a certificate of course completion recognising 21 Continuing Professional Development credits.
- Free retake: if you fail either exam, you can retake it free of charge within 12 months.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
![]()
This training content is offered in partnership with PECB
fr
en