Course Outline

Day 1 Introduction to ISO 27005, Concepts, and Implementation of a Risk Management Program for Government

  • Section 01: Course Objectives and Structure
  • Section 02: Standard and Regulatory Framework
  • Section 03: Concepts and Definitions of Risk
  • Section 04: Implementing a Risk Management Program for Government
  • Section 05: Establishing Context

Day 2 Risk Identification, Evaluation, and Treatment as Specified in ISO 27005 for Government

  • Section 06: Risk Identification
  • Section 07: Risk Analysis
  • Section 08: Risk Evaluation
  • Section 09: Quantitative Method for Risk Assessment
  • Section 10: Risk Treatment

Day 3 Information Security Risk Acceptance, Communication, Consultation, Monitoring, and Review for Government

  • Section 11: Information Security Risk Acceptance
  • Section 12: Information Security Risk Communication and Consultation
  • Section 13: Information Security Risk Monitoring and Review

Day 4 Risk Assessment Methodologies for Government

  • Section 14: OCTAVE Method
  • Section 15: MEHARI Method
  • Section 16: EBIOS Method
  • Section 17: Harmonized Threat and Risk Assessment (TRA) Method for Government
  • Section 18: Applying for Certification and Closing the Training

Day 5 Certification Exam for Government

Requirements

A foundational understanding of ISO/IEC 27005, along with thorough knowledge of risk assessment and information security, is essential for government professionals to ensure robust cybersecurity practices and compliance with regulatory requirements.

 35 Hours

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories