ISO/IEC 27005 Security Risk Manager: assessing and treating information security risks
Assessing and treating information security risks using NF ISO 27005 (ISO/IEC 27005 - Security Risk Manager)
Your cybersecurity priorities need to be explained in terms of business risks. Use ISO/IEC 27005 to structure your approach to information security risk. Connect the framework's principles with responsibilities and operational decisions to coordinate action more effectively and justify priorities.
- Duration
- 2.5 days 17 hours
- Code
- ISO27005SRM-RS Code
- CPF
- CPF eligible CPF
Presentation
Today, understanding and managing information systems security risks is essential to running a business effectively. Even a minor incident can have critical consequences for an organisation. Training in ISO 27005 is therefore important for becoming a certified risk manager.
Our ISO/IEC 27005 Security Risk Manager course will provide all the skills needed to master information security assets and processes in accordance with ISO/IEC 27005:2022. You will also explore other risk management methods such as OCTAVE, EBIOS and MEHARI, as well as EMR. The course is also ideal if you wish to implement an ISMS (Information Security Management System) compliant with ISO/IEC 27001:2022.
At the end of the course, you will take the ISO/IEC 27005 Risk Manager certification examination. Passing it demonstrates your professional ability to establish an information systems risk analysis approach within an organisation, based on ISO 27005.

Skills4All is a certification body specialising in digital skills development and digital transformation.
Objectives
Learning objectives:
- Identify sensitive and strategic business processes and their associated information systems using a SWOT analysis.
- Define the scope within which risk analysis is performed.
- Develop malfunction or attack scenarios and rank them by criticality.
- Develop risk treatment plans.
- Support the business in implementing the treatment plan.
- Foster a culture of information systems risk management.
Program
Round-table introductions:
- Individual participant introductions.
- Exploring each participant's expectations and objectives.
- Introduction to the course framework.
- Alignment with the specific objectives and challenges of ISO 27005 training.
- Identifying participants' individual expectations and perspectives.
Part 1: introduction to risk management and ISO 27005
- Understanding and defining risk:
- fundamental definitions of risk and the distinction between risk, threat and vulnerability.
- Understanding ISO/IEC 27005:2022:
- exploring the specific features of the latest version of the standard and its role in information security risk management.
- Identifying sensitive business processes:
- techniques for identifying strategic processes and their associated information systems, using SWOT analysis to align risk treatment decisions with business strategy.
- Establishing a risk management program: steps for developing an ISO 27005-compliant risk management program, including defining responsibilities and the decision-making process.
Part 2: implementing a risk management process based on ISO 27005
- Defining the scope:
- methods for synthesising information from collaborative working groups and documentation to clearly define the scope of risk analysis.
- Developing and prioritising risk scenarios:
- creating malfunction or attack scenarios based on criticality, working with experts to assess their likelihood and impacts.
- Analysing and evaluating risks:
- qualitative and quantitative risk analysis techniques.
- Developing risk treatment plans: creating risk management plans that integrate scenario analysis to propose solutions aligned with the company's strategic objectives.
Part 3: monitoring and risk management culture
- Implementing the treatment plan:
- strategies for implementing risk treatment plans effectively, including establishing monitoring indicators and collecting lessons learned to assess the effectiveness of actions over time.
- Fostering a risk management culture:
- techniques for encouraging information security incident reporting and analysis, thereby strengthening risk management culture within the organisation.
Part 4: other methodologies and certification preparation
- Introduction to risk assessment methods: exploring OCTAVE, MEHARI, EBIOS and EMR, and discussing their integration into the company's risk management strategy.
- Preparing for the ISO 27005 Security Risk Manager certification examination:
- reviewing the main concepts covered, exam practice and strategies for achieving certification.
Audience
This course is intended for:
- managers or consultants involved in or responsible for information security within an organisation;
- people responsible for managing information security risks;
- information security team members, IT professionals and privacy officers;
- people responsible for maintaining compliance with the information security requirements of ISO/IEC 27005 within an organisation;
- project managers, consultants or expert advisers seeking to master information security risk management.
Prerequisites
The ISO 27005 Security Risk Manager course requires the following prerequisite:
- a sound understanding of organisational information systems and information security risk assessment methods.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
- Case study
Course highlights
Internationally recognised certification. Practical work based on real-life cases, with 350 pages of documentation; certification examination included in the course fee.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en