Perform a search on the site.

Your currency
BEST
Certification
incluse
Certification is included in the price
Formateurs
certifiés
Formation dispensée par un formateur spécialisé
Take2
Free exam retake in case of failure
Cours officiel
Official training from an Accredited Training Provider

ISO/IEC 27005 Risk Manager with EBIOS: managing information security risks

Cybersecurity decisions become more relevant when based on explicit risk analysis. Structure scenarios, assess impacts and select appropriate responses. Develop a method for explaining priorities and connecting protective measures to business concerns.

Duration
5 days 35 hours
Code
ISO27005EB Code
PECB ISO/IEC 27005 Certification — Information Security Risk Management

Accredited training for the PECB ISO/IEC 27005 Certification — Information Security Risk Management certification.

Presentation


Managing information security risks is a strategic priority for any organisation seeking to protect its information assets. The ISO/IEC 27005 standard provides guidance for identifying, analysing, evaluating and treating information security risks, complementing the requirements of the ISO/IEC 27001 standard. The EBIOS Risk Manager method, published by ANSSI, provides a practical, operational framework for conducting cyber risk assessments.

This course provides the knowledge and skills to manage information security risks using ISO/IEC 27005:2022 and EBIOS Risk Manager. Case studies and practical exercises develop expertise you can apply directly to risk assessments, risk lifecycle management and supporting an ISMS compliant with ISO/IEC 27001:2022.

By the end of the program, you will be ready to take two official PECB exams: ISO/IEC 27005 Risk Manager and EBIOS Risk Manager, both included in our offer. Depending on your professional experience, you can obtain one of the associated PECB certifications (see the certification tab for details).

Objectives

By the end of this ISO/IEC 27005 Risk Manager with EBIOS course, you will be able to:

  • understand and apply information security risk management principles, tools and methodologies under ISO/IEC 27005:2022 and ISO 31000:2018;
  • master EBIOS Risk Manager and conduct an end-to-end cyber risk assessment;
  • identify, analyse, evaluate, treat and communicate information security risks;
  • develop, manage and maintain an information security risk management program within an organisation;
  • understand the relationships between information security risk management, security controls and compliance with ISO/IEC 27001:2022;
  • compare the main risk assessment methods: OCTAVE, MEHARI, NIST and CRAMM;
  • prepare for and pass both official PECB exams to obtain PECB Certified ISO/IEC 27005 Risk Manager and PECB Certified EBIOS Risk Manager certification.
Last update: 23/09/2026

PECB training
This training content is offered in partnership with PECB