Skip to content
Security / Governance, Risk & Compliance

ISO/IEC 27005 Lead Information Security Risk Manager (ISO/IEC 27005 Lead Risk Manager).

ISO/IEC 27005 Lead Risk Manager training develops the competency to master the information security risk management process based on ISO/IEC 27005. This training provides an in-depth understanding of the principles, framework, process and techniques of information security risk management. During this training, you will learn how to identify, assess, analyze, evaluate and treat risks in information security, as well as how to use the risk management process to support an Information Security Management System (ISMS).

Issues

Benefits

  • Understand the relationship between information security risk management and the ISMS
  • Mastery of information security risk management concepts, approaches, methods and techniques
  • They will learn how to interpret and apply ISO/IEC 27005 requirements in the specific context of the organization
  • They will gain the knowledge to advise organizations on information security risk management

Who is this training for?

Risk managers and information security managers
Members of information security and privacy teams
Information security consultants and advisors
Persons responsible for compliance with information security requirements

Prerequisites

  • Basic knowledge of information security and CMS
  • Knowledge of the basics of risk management
  • Experience working with ISO/IEC 27000 standards (preferred)
  • Analytical and risk assessment skills

Training program

01

Day 1: Introduction to ISO/IEC 27005 and Risk Management Framework

  • Introduction to ISO/IEC 27005 — objectives, scope, structure, relationship with ISO/IEC 27001 and ISO 31000
  • Risk management concepts — risk, threat, vulnerability, impact, likelihood, acceptable risk level
  • Risk management framework — organizational context, scope, risk criteria, risk appetite
  • Risk management process — PDCA cycle, process phases, roles and responsibilities, governance
  • Context establishment — external and internal context, security objectives, legal and regulatory requirements
  • Exercises: defining the risk management context, establishing risk criteria and risk appetite
02

Day 2: Risk Assessment and Risk Treatment Strategies

  • Risk identification — identification of assets, threats, existing controls, vulnerabilities, and consequences
  • Risk analysis — qualitative and quantitative methods, likelihood and impact estimation, risk matrix
  • Risk evaluation — comparison with acceptance criteria, risk prioritization, risk register
  • Risk treatment — options (modification, retention, avoidance, sharing), risk treatment plan
  • Residual risk acceptance — decision documentation, management approval, Statement of Applicability (SoA)
  • Exercises: conducting a full risk assessment — identification, analysis, evaluation, and treatment plan
03

Day 3: Communication, Monitoring, and PECB Exam Preparation

  • Risk communication and consultation — reporting, escalation, risk awareness, stakeholder engagement
  • Risk monitoring and review — KRI indicators, periodic review, risk assessment updates, continuous improvement
  • Integration with ISMS — risk management as a foundation of ISO/IEC 27001, Annex A, process continuity
  • Case studies — risk management analysis in organizations of various scales and industries
  • PECB certification preparation — exam format, question types, passing strategies
  • PECB certification exam (optional) — written exam leading to PECB Certified ISO/IEC 27005 Lead Risk Manager certificate

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For ISO/IEC 27005 Lead Information Security Risk Manager (ISO/IEC 27005 Lead Risk Manager). we recommend: Basic knowledge of information security and CMS; Knowledge of the basics of risk management; Experience working with ISO/IEC 27000 standards (preferred).

What is the format and duration of this training?

The training lasts 3 days and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: Risk managers and information security managers; Members of information security and privacy teams; Information security consultants and advisors.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90