Courses

ISO/IEC 27005 - Information Security Lead Risk Manager

ISO/IEC 27005 - Information Security Lead Risk Manager

ISO/IEC 27005 provides a risk management framework for organizations to manage information security risks. Specifically, it provides guidelines on identifying, analyzing, evaluating, treating, and monitoring information security risks.

The standard supports the guidelines of ISO 31000 and is particularly helpful for organizations aiming to safeguard their information assets and achieve information security objectives.

The ISO/IEC 27005 Lead Risk Manager training course provides an information security risk management framework based on ISO/IEC 27005 guidelines, which also supports the general concepts of ISO/IEC 27001. The training course also provides participants with a thorough understanding of other best risk management frameworks and methodologies, such as OCTAVE, EBIOS, MEHARI, CRAMM, NIST, and Harmonized TRA.

The training course is followed by an exam. If you pass, you can apply for a “PECB Certified ISO/IEC 27005 Lead Risk Manager” credential. For more information about the examination process, please refer to the Examination, Certification, and General Information section below.

Who Can Attend?

This training course is intended for:

Managers or consultants involved in or responsible for information security in an organization

Individuals responsible for managing information security risks, such as ISMS professionals and risk owners

Members of information security teams, IT professionals, and privacy officers

Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization

Project managers, consultants, or expert advisers seeking to master the management of information security risks

Learning objectives

By successfully completing this training course, you will be able to:

Explain the risk management concepts and principles based on ISO/IEC 27005 and ISO 31000

Establish, maintain, and continually improve an information security risk management framework based on the guidelines of ISO/IEC 27005 and best practices

Apply information security risk management processes based on the guidelines of ISO/IEC 27005

Plan and establish risk communication and consultation activities

Record, report, monitor, and review the information security risk management process and framework

Educational approach

The training course provides best practices of risk management that will help participants prepare for real-life situations.

The training course contains essay-type exercises (some of which are based on a case study) and multiple-choice quizzes (some of which are scenario-based).

Participants are encouraged to communicate and discuss with each other when completing stand-alone and scenario-based quizzes and exercises.

The structure of the quizzes is similar to the certification exam.

Course Contents

Day 1: Introduction to ISO/IEC 27005 and information security risk management

Day 2: Risk identification, analysis, evaluation, and treatment based on ISO/IEC 27005

Day 3: Information security risk communication and consultation, recording and reporting, and monitoring and review

Day 4: Risk assessment methods

Day 5: Certification exam

Enroll in this course

Buy now

Hear from professionals we’ve trained