Get in Touch

Course Outline

Learning objectives 
Upon the successful completion of this training course, you will be able to:
  • Explain the risk management concepts and principles outlined by ISO/IEC 27005:2022 and ISO 31000
  • Establish, maintain, and improve an information security risk management framework based on the guidelines of ISO/IEC 27005:2022
  • Apply information security risk management processes based on the guidelines of ISO/IEC 27005:2022
  • Plan and establish risk communication and consultation activities
Day 1:

Introduction to ISO/IEC 27005:2022 and risk management
 

  • Training course objectives and structure
  • Standards and regulatory frameworks
  • Fundamental concepts and principles of information security risk management
  • Information security risk management program
  • Context establishment
Day 2:
Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005:2022
  • Risk identification
  • Risk analysis
  • Risk evaluation
  • Risk treatment
  • Information security risk communication and consultation
Day 3:
Risk recording and reporting, monitoring and review, and risk assessment methods
  • Information security risk recording and reporting
  • Information security risk monitoring and review
  • OCTAVE and MEHARI methodologies
  • EBIOS method and NIST framework
  • CRAMM and TRA methods
  • Closing of the training course

PECB ISO/IEC 27005 Risk Manager Certification Requirements

To qualify for a PECB ISO/IEC 27005 Risk Manager designation, all candidates must successfully pass the PECB Certified ISO/IEC 27005 Risk Manager exam (or an approved equivalent) and formally sign the PECB Code of Ethics.

Depending on your professional background and hands-on risk assessment history, you can apply for one of two credential levels:

1. Provisional Risk Manager

  • Credential Title: PECB Certified ISO/IEC 27005 Provisional Risk Manager

  • Professional Experience: None required.

  • Risk Management Experience: None required.

  • Best Suited For: Individuals who have successfully passed the exam but have not yet completed the field work or active hours required for full certification.

2. Risk Manager

  • Credential Title: PECB Certified ISO/IEC 27005 Risk Manager

  • Professional Experience: Two years of overall professional experience, with at least one year focused specifically on Information Security Risk Management.

  • Risk Management Experience: A cumulative total of at least 200 hours of active information security risk management activities.

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005/iso-iec-27005-risk-manager

Requirements

This training course is intended for:
  • Managers or consultants involved in or responsible for information security in an organization
  • Individuals responsible for managing information security risks
  • Members of information security teams, IT professionals, and privacy officers
  • Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
  • Project managers, consultants, or expert advisers seeking to master the management of information security risks
 21 Hours

Number of participants


Price per participant

Testimonials (5)

Upcoming Courses

Related Categories