ISO/IEC 27005 Lead Information Security Risk Manager (ISO/IEC 27005 Lead Risk Manager).
ISO/IEC 27005 Lead Risk Manager training develops the competency to master the information security risk management process based on ISO/IEC 27005. This training provides an in-depth understanding of the principles, framework, process and techniques of information security risk management. During this training, you will learn how to identify, assess, analyze, evaluate and treat risks in information security, as well as how to use the risk management process to support an Information Security Management System (ISMS).
Issues
-
ISO/IEC 27005
-
Risk management in information security
-
Risk assessment
-
Risk identification
-
Risk analysis
-
Risk evaluation
-
Risk treatment
-
Risk communication
-
Risk monitoring
-
Risk overview
-
Risk management process
Benefits
- Understand the relationship between information security risk management and the ISMS
- Mastery of information security risk management concepts, approaches, methods and techniques
- They will learn how to interpret and apply ISO/IEC 27005 requirements in the specific context of the organization
- They will gain the knowledge to advise organizations on information security risk management
Who is this training for?
Prerequisites
- Basic knowledge of information security and CMS
- Knowledge of the basics of risk management
- Experience working with ISO/IEC 27000 standards (preferred)
- Analytical and risk assessment skills
Training program
Day 1: Introduction to ISO/IEC 27005 and Risk Management Framework
- Introduction to ISO/IEC 27005 — objectives, scope, structure, relationship with ISO/IEC 27001 and ISO 31000
- Risk management concepts — risk, threat, vulnerability, impact, likelihood, acceptable risk level
- Risk management framework — organizational context, scope, risk criteria, risk appetite
- Risk management process — PDCA cycle, process phases, roles and responsibilities, governance
- Context establishment — external and internal context, security objectives, legal and regulatory requirements
- Exercises: defining the risk management context, establishing risk criteria and risk appetite
Day 2: Risk Assessment and Risk Treatment Strategies
- Risk identification — identification of assets, threats, existing controls, vulnerabilities, and consequences
- Risk analysis — qualitative and quantitative methods, likelihood and impact estimation, risk matrix
- Risk evaluation — comparison with acceptance criteria, risk prioritization, risk register
- Risk treatment — options (modification, retention, avoidance, sharing), risk treatment plan
- Residual risk acceptance — decision documentation, management approval, Statement of Applicability (SoA)
- Exercises: conducting a full risk assessment — identification, analysis, evaluation, and treatment plan
Day 3: Communication, Monitoring, and PECB Exam Preparation
- Risk communication and consultation — reporting, escalation, risk awareness, stakeholder engagement
- Risk monitoring and review — KRI indicators, periodic review, risk assessment updates, continuous improvement
- Integration with ISMS — risk management as a foundation of ISO/IEC 27001, Annex A, process continuity
- Case studies — risk management analysis in organizations of various scales and industries
- PECB certification preparation — exam format, question types, passing strategies
- PECB certification exam (optional) — written exam leading to PECB Certified ISO/IEC 27005 Lead Risk Manager certificate
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
What are the prerequisites for this training?
For ISO/IEC 27005 Lead Information Security Risk Manager (ISO/IEC 27005 Lead Risk Manager). we recommend: Basic knowledge of information security and CMS; Knowledge of the basics of risk management; Experience working with ISO/IEC 27000 standards (preferred).
What is the format and duration of this training?
The training lasts 3 days and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.
Who is this training designed for?
This training is designed for: Risk managers and information security managers; Members of information security and privacy teams; Information security consultants and advisors.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.