Perform a search on the site.

Your currency
Certification
incluse
Certification is included in the price
CPF
mon compte formation
This course is eligible for the CPF
Formateurs
certifiés
Formation dispensée par un formateur spécialisé

ISO/IEC 27005 Security Risk Manager: assessing and treating information security risks

Assessing and treating information security risks using NF ISO 27005 (ISO/IEC 27005 - Security Risk Manager)

Your cybersecurity priorities need to be explained in terms of business risks. Use ISO/IEC 27005 to structure your approach to information security risk. Connect the framework's principles with responsibilities and operational decisions to coordinate action more effectively and justify priorities.

Duration
2.5 days 17 hours
Code
ISO27005SRM-RS Code
CPF
CPF eligible CPF

Use your CPF entitlement to fund this course

This course is eligible for funding through the French Compte Personnel de Formation (CPF).

Presentation

Today, understanding and managing information systems security risks is essential to running a business effectively. Even a minor incident can have critical consequences for an organisation. Training in ISO 27005 is therefore important for becoming a certified risk manager.

Our ISO/IEC 27005 Security Risk Manager course will provide all the skills needed to master information security assets and processes in accordance with ISO/IEC 27005:2022. You will also explore other risk management methods such as OCTAVE, EBIOS and MEHARI, as well as EMR. The course is also ideal if you wish to implement an ISMS (Information Security Management System) compliant with ISO/IEC 27001:2022.

At the end of the course, you will take the ISO/IEC 27005 Risk Manager certification examination. Passing it demonstrates your professional ability to establish an information systems risk analysis approach within an organisation, based on ISO 27005.

Our certification partner Skills4All

 Skills4All is a certification body specialising in digital skills development and digital transformation.

Objectives

Learning objectives:

  • Identify sensitive and strategic business processes and their associated information systems using a SWOT analysis.
  • Define the scope within which risk analysis is performed.
  • Develop malfunction or attack scenarios and rank them by criticality.
  • Develop risk treatment plans.
  • Support the business in implementing the treatment plan.
  • Foster a culture of information systems risk management.
Last update: 24/09/2026