Courses

ISO/IEC 27005 - Risk Management Foundation

ISO/IEC 27005 - Risk Management Foundation

ISO/IEC 27005 provides a risk management framework for organizations to manage information security risks. Specifically, it provides guidelines on identifying, analyzing, evaluating, treating, and monitoring information security risks.

The standard supports the guidelines of ISO 31000 and is particularly helpful for organizations aiming to safeguard their information assets and achieve information security objectives.

ISO/IEC 27005 Foundation is a two-day training course that focuses on the information security risk management process introduced by ISO/IEC 27005 and the structure of the standard. It provides an overview of the guidelines of ISO/IEC 27005 for managing information security risks, including context establishment, risk assessment, risk treatment, communication and consultation, recording and reporting, and monitoring and review.

After attending the training course, you can sit for the exam. If you successfully pass the exam, you can apply for the “PECB Certificate Holder in ISO/IEC 27005 Foundation” designation. This certificate demonstrates that you have a general knowledge of ISO/IEC 27005 guidelines for information security risk management.

Who Can Attend?

The ISO/IEC 27005 Foundation training course is intended for:

Risk management professionals

Professionals wishing to get acquainted with the guidelines of ISO/IEC 27005 for information security risk management

Personnel tasked with managing information security risks in their area of responsibility

Individuals interested in pursuing a career in information security risk management

Learning objectives

Upon successful completion of this training course, you will be able to:

Describe the main risk management concepts, principles, and definitions

Interpret the guidelines of ISO/IEC 27005 for managing information security risks

Identify approaches, methods, and techniques used for the implementation and management of an information security risk management program

Educational approach

The training course is participant centered and:

Contains lecture sessions illustrated with examples and discussions

Encourages interaction between participants by means of questions and suggestions

Includes quizzes with similar structure to the exam

Course Contents

Day 1: Introduction to ISO/IEC 27005 and fundamental concepts of information security risk management

Day 2: Information security risk management and certificate exam

Enroll in this course

Buy now

Hear from professionals we’ve trained