Course Outline
- articulate the risk management concepts and principles defined in ISO/IEC 27005:2022 and ISO 31000.
- establish, maintain, and enhance an information security risk management framework aligned with ISO/IEC 27005:2022 guidelines.
- implement information security risk management processes in accordance with ISO/IEC 27005:2022 standards.
- plan and execute risk communication and consultation activities for government and organizational stakeholders.
Introduction to ISO/IEC 27005:2022 and Risk Management Principles
- Course objectives and structural overview.
- Relevant standards and regulatory frameworks.
- Core concepts and principles of information security risk management.
- Development of an information security risk management program.
- Establishment of organizational context.
- Risk identification techniques.
- Risk analysis methodologies.
- Risk evaluation criteria.
- Risk treatment planning.
- Information security risk communication and consultation protocols.
- Documentation and reporting of information security risks.
- Monitoring and review procedures for risk management.
- Application of OCTAVE and MEHARI methodologies.
- Utilization of the EBIOS method and NIST framework.
- Implementation of CRAMM and TRA methods.
Closing remarks and course conclusion.
PECB ISO/IEC 27005 Risk Manager Certification Requirements
To earn the PECB ISO/IEC 27005 Risk Manager designation, all candidates must successfully pass the PECB Certified ISO/IEC 27005 Risk Manager examination (or an approved equivalent) and formally adhere to the PECB Code of Ethics.
Candidates may apply for one of two credential levels based on their professional background and practical experience in risk assessment:
1. Provisional Risk Manager
-
Credential Title: PECB Certified ISO/IEC 27005 Provisional Risk Manager.
-
Professional Experience: No prior professional experience required.
-
Risk Management Experience: No specific risk management experience required.
-
Target Audience: Individuals who have passed the examination but have not yet fulfilled the field work or active hour requirements for full certification.
2. Risk Manager
-
Credential Title: PECB Certified ISO/IEC 27005 Risk Manager.
-
Professional Experience: Two years of overall professional experience, including at least one year dedicated to Information Security Risk Management.
-
Risk Management Experience: A minimum cumulative total of 200 hours of active involvement in information security risk management activities.
Requirements
- Managers or advisors tasked with oversight of organizational information security
- Personnel charged with the management of information security risks
- Members of information security teams, IT specialists, and privacy officers
- Individuals accountable for ensuring compliance with ISO/IEC 27001 standards
- Project managers, consultants, or expert advisers seeking to demonstrate proficiency in information security risk management for government
Testimonials (5)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
The quizzes to reinforce the reading and the ability to ask questions at any time
Jonathan
Course - ISO 9001 Lead Auditor
Speed of response and communication