Get in Touch

Course Outline

Course Objectives
Upon successful completion of this training program, participants will be able to:
  • articulate the risk management concepts and principles defined in ISO/IEC 27005:2022 and ISO 31000.
  • establish, maintain, and enhance an information security risk management framework aligned with ISO/IEC 27005:2022 guidelines.
  • implement information security risk management processes in accordance with ISO/IEC 27005:2022 standards.
  • plan and execute risk communication and consultation activities for government and organizational stakeholders.
Day 1:

Introduction to ISO/IEC 27005:2022 and Risk Management Principles

  • Course objectives and structural overview.
  • Relevant standards and regulatory frameworks.
  • Core concepts and principles of information security risk management.
  • Development of an information security risk management program.
  • Establishment of organizational context.
Day 2:
Risk Assessment, Risk Treatment, and Communication Based on ISO/IEC 27005:2022
  • Risk identification techniques.
  • Risk analysis methodologies.
  • Risk evaluation criteria.
  • Risk treatment planning.
  • Information security risk communication and consultation protocols.
Day 3:
Risk Documentation, Reporting, Monitoring, Review, and Assessment Methods
  • Documentation and reporting of information security risks.
  • Monitoring and review procedures for risk management.
  • Application of OCTAVE and MEHARI methodologies.
  • Utilization of the EBIOS method and NIST framework.
  • Implementation of CRAMM and TRA methods.
  • Closing remarks and course conclusion.

PECB ISO/IEC 27005 Risk Manager Certification Requirements

To earn the PECB ISO/IEC 27005 Risk Manager designation, all candidates must successfully pass the PECB Certified ISO/IEC 27005 Risk Manager examination (or an approved equivalent) and formally adhere to the PECB Code of Ethics.

Candidates may apply for one of two credential levels based on their professional background and practical experience in risk assessment:

1. Provisional Risk Manager

  • Credential Title: PECB Certified ISO/IEC 27005 Provisional Risk Manager.

  • Professional Experience: No prior professional experience required.

  • Risk Management Experience: No specific risk management experience required.

  • Target Audience: Individuals who have passed the examination but have not yet fulfilled the field work or active hour requirements for full certification.

2. Risk Manager

  • Credential Title: PECB Certified ISO/IEC 27005 Risk Manager.

  • Professional Experience: Two years of overall professional experience, including at least one year dedicated to Information Security Risk Management.

  • Risk Management Experience: A minimum cumulative total of 200 hours of active involvement in information security risk management activities.

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005/iso-iec-27005-risk-manager

Requirements

This training program is designed for:
  • Managers or advisors tasked with oversight of organizational information security
  • Personnel charged with the management of information security risks
  • Members of information security teams, IT specialists, and privacy officers
  • Individuals accountable for ensuring compliance with ISO/IEC 27001 standards
  • Project managers, consultants, or expert advisers seeking to demonstrate proficiency in information security risk management for government
 21 Hours

Number of participants


Price per participant

Testimonials (5)

Upcoming Courses

Related Categories