Course Code: iso27005riskman
Duration: 21 hours
Prerequisites:
This training course is intended for:
  • Managers or consultants involved in or responsible for information security in an organization 
  • Individuals responsible for managing information security risks
  • Members of information security teams, IT professionals, and privacy officers
  • Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
  • Project managers, consultants, or expert advisers seeking to master the management of information security risks
Overview:

The ISO/IEC 27005:2022 Risk Manager training course provides valuable information on risk management concepts and principles outlined by ISO/IEC 27005:2022 and also ISO 31000. The training course provides participants with the necessary knowledge and skills to identify, evaluate, analyze, treat, and communicate information security risks based on ISO/IEC 27005:2022. Furthermore, the training course provides an overview of other best risk assessment methods, such as OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA. 

The PECB ISO/IEC 27005:2022 Risk Manager certification demonstrates that you comprehend the concepts and principles of information security risk management. The training course is followed by an exam. After passing the exam, you can apply for the “PECB Certified ISO/IEC 27005:2022 Risk Manager” credentia

Course Outline:
Learning objectives 
Upon the successful completion of this training course, you will be able to:
  • Explain the risk management concepts and principles outlined by ISO/IEC 27005:2022 and ISO 31000
  • Establish, maintain, and improve an information security risk management framework based on the guidelines of ISO/IEC 27005:2022
  • Apply information security risk management processes based on the guidelines of ISO/IEC 27005:2022
  • Plan and establish risk communication and consultation activities
Day 1:

Introduction to ISO/IEC 27005:2022 and risk management
 

  • Training course objectives and structure
  • Standards and regulatory frameworks
  • Fundamental concepts and principles of information security risk management
  • Information security risk management program
  • Context establishment
Day 2:
Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005:2022
  • Risk identification
  • Risk analysis
  • Risk evaluation
  • Risk treatment
  • Information security risk communication and consultation
Day 3:
Risk recording and reporting, monitoring and review, and risk assessment methods
  • Information security risk recording and reporting
  • Information security risk monitoring and review
  • OCTAVE and MEHARI methodologies
  • EBIOS method and NIST framework
  • CRAMM and TRA methods
  • Closing of the training course
Sites Published:

Brasil - PECB ISO 27005 Risk Manager

Canada - PECB ISO 27005 Risk Manager

Magyarország - PECB ISO 27005 Risk Manager

Ireland - PECB ISO 27005 Risk Manager

Nederland - PECB ISO 27005 Risk Manager

Portugal - PECB ISO 27005 Risk Manager

România - PECB ISO 27005 Risk Manager

Malta - PECB ISO 27005 Risk Manager

Argentina - PECB ISO 27005 Risk Manager

Chile - PECB ISO 27005 Risk Manager

Costa Rica - PECB ISO 27005 Risk Manager

Ecuador - PECB ISO 27005 Risk Manager

Guatemala - PECB ISO 27005 Risk Manager

Colombia - PECB ISO 27005 Risk Manager

México - PECB ISO 27005 Risk Manager

Panama - PECB ISO 27005 Risk Manager

Peru - PECB ISO 27005 Risk Manager

Uruguay - PECB ISO 27005 Risk Manager

Venezuela - PECB ISO 27005 Risk Manager

United Kingdom - PECB ISO 27005 Risk Manager

Bulgaria - PECB ISO 27005 Risk Manager

Bolivia - PECB ISO 27005 Risk Manager

Moldova - PECB ISO 27005 Risk Manager

Slovenia - PECB ISO 27005 Risk Manager

Croatia - PECB ISO 27005 Risk Manager

Serbia - PECB ISO 27005 Risk Manager

Uzbekistan - PECB ISO 27005 Risk Manager