ISO/IEC 27005 provides a risk management framework for organizations to manage information security risks. Specifically, it provides guidelines on identifying, analyzing, evaluating, treating, and monitoring information security risks.
The standard supports the guidelines of ISO 31000 and is particularly helpful for organizations aiming to safeguard their information assets and achieve information security objectives.
The ISO/IEC 27005 Lead Risk Manager training course provides an information security risk management framework based on ISO/IEC 27005 guidelines, which also supports the general concepts of ISO/IEC 27001. The training course also provides participants with a thorough understanding of other best risk management frameworks and methodologies, such as OCTAVE, EBIOS, MEHARI, CRAMM, NIST, and Harmonized TRA.
The training course is followed by an exam. If you pass, you can apply for a “PECB Certified ISO/IEC 27005 Lead Risk Manager” credential. For more information about the examination process, please refer to the Examination, Certification, and General Information section below.
This training course is intended for:
Managers or consultants involved in or responsible for information security in an organization
Individuals responsible for managing information security risks, such as ISMS professionals and risk owners
Members of information security teams, IT professionals, and privacy officers
Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
Project managers, consultants, or expert advisers seeking to master the management of information security risks
By successfully completing this training course, you will be able to:
Explain the risk management concepts and principles based on ISO/IEC 27005 and ISO 31000
Establish, maintain, and continually improve an information security risk management framework based on the guidelines of ISO/IEC 27005 and best practices
Apply information security risk management processes based on the guidelines of ISO/IEC 27005
Plan and establish risk communication and consultation activities
Record, report, monitor, and review the information security risk management process and framework
The training course provides best practices of risk management that will help participants prepare for real-life situations.
The training course contains essay-type exercises (some of which are based on a case study) and multiple-choice quizzes (some of which are scenario-based).
Participants are encouraged to communicate and discuss with each other when completing stand-alone and scenario-based quizzes and exercises.
The structure of the quizzes is similar to the certification exam.
Day 1: Introduction to ISO/IEC 27005 and information security risk management
Day 2: Risk identification, analysis, evaluation, and treatment based on ISO/IEC 27005
Day 3: Information security risk communication and consultation, recording and reporting, and monitoring and review
Day 4: Risk assessment methods
Day 5: Certification exam
.avif)