A fundamental understanding of ISO/IEC 27005 and comprehensive knowledge of Risk Assessment and Information Security.
ISO/IEC 27005 Lead Risk Manager training enables you to acquire the necessary expertise to support an organization in the risk management process related to all assets of relevance for Information Security using the ISO/IEC 27005 standard as a reference framework. During this training course, you will gain a comprehensive knowledge of a process model for designing and developing an Information Security Risk Management program. The training will also contain a thorough understanding of best practices of risk assessment methods such as OCTAVE, EBIOS, MEHARI and harmonized TRA. This training course supports the implementation process of the ISMS framework presented in the ISO/IEC 27001 standard.
After mastering all the necessary concepts of Information Security Risk Management based on ISO/IEC 27005, you can sit for the exam and apply for a “PECB Certified ISO/IEC 27005 Lead Risk Manager” credential. By holding a PECB Lead Risk Manager Certificate, you will be able to demonstrate that you have the practical knowledge and professional capabilities to support and lead a team in managing Information Security Risks.
Who should attend?
- Information Security risk managers
- Information Security team members
- Individuals responsible for Information Security, compliance, and risk within an organization
- Individuals implementing ISO/IEC 27001, seeking to comply with ISO/IEC 27001 or individuals who are involved in a risk management program
- IT consultants
- IT professionals
- Information Security officers
- Privacy officers
Examination - Duration: 3 hours
The “PECB Certified ISO/IEC 27005 Lead Risk Manager” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). The exam covers the following competency domains:
- Domain 1 Fundamental principles and concepts of Information Security Risk Management
- Domain 2 Implementation of an Information Security Risk Management program
- Domain 3 Information security risk assessment
- Domain 4 Information security risk treatment
- Domain 5 Information security risk communication, monitoring and improvement
- Domain 6 Information security risk assessment methodologies
General Information
- Certification fees are included on the exam price
- Training material containing over 350 pages of information and practical examples will be distributed
- A participation certificate of 21 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months for free
Day 1 Introduction to ISO 27005, concepts and implementation of a risk management program
- Section 01: Course objectives and structure
- Section 02: Standard and regulatory framework
- Section 03: Concepts and definitions of risk
- Section 04: Implementing a risk management programme
- Section 05: Context establishment
Day 2 Risk identification, evaluation, and treatment as specified in ISO 27005
- Section 06: Risk Identification
- Section 07: Risk Analysis
- Section 08: Risk Evaluation
- Section 09: Risk Assessment with a quantitative method
- Section 10: Risk Treatment
Day 3 Information Security Risk Acceptance, Communication, Consultation, Monitoring and Review
- Section 11: Information security risk acceptance
- Section 12: Information security risk communication and consultation
- Section 13: Information security risk monitoring and review
Day 4 Risk Assessment Methodologies
- Section 14: OCTAVE Method
- Section 15: MEHARI Method
- Section 16: EBIOS Method
- Section 17: Harmonized Threat and Risk Assessment (TRA) Method
- Section 18: Applying for certification and closing the training
Day 5 Certification Exam
United Arab Emirates - ISO/IEC 27005 Lead Risk Manager
Qatar - ISO/IEC 27005 Lead Risk Manager
Egypt - ISO/IEC 27005 Lead Risk Manager
Saudi Arabia - ISO/IEC 27005 Lead Risk Manager
South Africa - ISO/IEC 27005 Lead Risk Manager
Brasil - ISO/IEC 27005 Lead Risk Manager
Canada - ISO/IEC 27005 Lead Risk Manager
Czech Republic - ISO/IEC 27005 Lead Risk Manager
Ireland - ISO/IEC 27005 Lead Risk Manager
Lithuania - ISO/IEC 27005 Lead Risk Manager
Nederland - ISO/IEC 27005 Lead Risk Manager
Norway - ISO/IEC 27005 Lead Risk Manager
Portugal - ISO/IEC 27005 Lead Risk Manager
Sverige - ISO/IEC 27005 Lead Risk Manager
Malta - ISO/IEC 27005 Lead Risk Manager
Belgique - ISO/IEC 27005 Lead Risk Manager
Argentina - ISO/IEC 27005 Lead Risk Manager
Chile - ISO/IEC 27005 Lead Risk Manager
Costa Rica - ISO/IEC 27005 Lead Risk Manager
Ecuador - ISO/IEC 27005 Lead Risk Manager
Guatemala - ISO/IEC 27005 Lead Risk Manager
Colombia - ISO/IEC 27005 Lead Risk Manager
México - ISO/IEC 27005 Lead Risk Manager
Panama - ISO/IEC 27005 Lead Risk Manager
Peru - ISO/IEC 27005 Lead Risk Manager
Uruguay - ISO/IEC 27005 Lead Risk Manager
Venezuela - ISO/IEC 27005 Lead Risk Manager
Polska - ISO/IEC 27005 Lead Risk Manager
United Kingdom - ISO/IEC 27005 Lead Risk Manager
Bolivia - ISO/IEC 27005 Lead Risk Manager
Indonesia - ISO/IEC 27005 Lead Risk Manager
Kazakhstan - ISO/IEC 27005 Lead Risk Manager
Moldova - ISO/IEC 27005 Lead Risk Manager
Morocco - ISO/IEC 27005 Lead Risk Manager
Tunisia - ISO/IEC 27005 Lead Risk Manager
Kuwait - ISO/IEC 27005 Lead Risk Manager
Oman - ISO/IEC 27005 Lead Risk Manager
Slovakia - ISO/IEC 27005 Lead Risk Manager
Kenya - ISO/IEC 27005 Lead Risk Manager
Nigeria - ISO/IEC 27005 Lead Risk Manager
Botswana - ISO/IEC 27005 Lead Risk Manager
Slovenia - ISO/IEC 27005 Lead Risk Manager
Croatia - ISO/IEC 27005 Lead Risk Manager
Serbia - ISO/IEC 27005 Lead Risk Manager
Bhutan - ISO/IEC 27005 Lead Risk Manager