Risk management in information security
The training focuses on the practical aspects of risk management in information security in accordance with the requirements of international standards ISO/IEC 27005, 27001 and 27002. The program combines theoretical foundations with practical workshops, during which participants will learn methods of risk estimation and IT tools for risk analysis. The classes are conducted in the form of interactive workshops, where theory is interspersed with practical exercises and case analysis.
Issues
-
ISO/IEC standards of the 27000 family
-
Risk analysis methodologies
-
Identification of information assets
-
Information classification
-
Estimating probability and impact
-
Security controls
-
Documentation of the risk management process
-
Information security strategy
-
Risk management plans
-
Indicators of control effectiveness
-
Communication in the risk management process
-
System review and improvement
Benefits
- Acquire practical skills in identifying and assessing information security risks
- Effective risk management methods in accordance with international standards
- Tools to support the risk analysis process
- Creating and documenting risk handling plans
- The area of information security
- Obtaining a certificate of qualification in risk management
Who is this training for?
Prerequisites
- Basic knowledge of information security issues
- Understand the organization's business processes
- Knowledge of the basics of management systems
- Experience in working with system documentation
Training program
Information security basics
- Structure of the ISO/IEC 27000 family of standards
- Legal and regulatory requirements
- Principles of information protection
Risk management process
- Establish a risk management context
- Identification of resources and their valuation
- Risk assessment methodologies
Documenting the risk management process
- Risk estimation and analysis
- Identification of threats and vulnerabilities
- Probability estimation methods
- Determining the level of risk
Risk acceptance criteria
- Dealing with risks
- Strategies for dealing with risk
Risk management plans
- Risk monitoring and review
- Communication and exchange of risk information
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Who is the Risk management in information security training for?
This training is designed for professionals looking to develop skills in risk management in information security. Required level: intermediate.
How long is the Risk management in information security training?
The training lasts 3. Available in online or on-site format.
Will I receive a certificate?
Yes — every participant receives a completion certificate confirming acquired competencies. EITT holds ISO 9001 accreditation.
Can this training be conducted for a closed group?
Yes — we offer dedicated closed trainings for companies. We customize the program to your team's needs. Contact us for an individual quote.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.