- To understand the concepts, approaches, methods and techniques allowing an effective risk management according to ISO/IEC 27005
- To interpret the requirements of ISO/IEC 27001 on information security risk management
- To understand the relationship between the information security risk management, the security controls and the compliance with the requirements of different stakeholders of an organization
- To acquire the competence to implement, maintain and manage an ongoing information security risk management program according to ISO/IEC 27005
- To acquire the competence to effectively advise organizations on the best practices in information security risk management
ISO 27005 Risk Manager
ISO/IEC 27005 Certification: Learn how to manage information security risks with our comprehensive ISO/IEC 27005 training course
Overview
COURSE DESCRIPTION
This three day intensive course participants develop the competence to master the basic risk management elements related to all assets of relevance for information security using the ISO/IEC 27005:2011 standard as a reference framework. Based on practical exercises and case studies, participants acquire the necessary knowledge and skills to perform an optimal information security risk assessment and manage risks in time by being familiar with their life cycle. During this training, we will also present other risk assessment methods such as OCTAVE, EBIOS, MEHARI and Harmonized TRA. This training fits perfectly with the implementation process of the ISMS framework in ISO/IEC 27001:2013 standard.01.
CERTIFICATION
Upon completion of the course, should you pass the exam successfully, you will receive an internationally recognized certificate.
LEARNING OBJECTIVES
PREREQUISITES
Knowledge on Risk Management and Information Security is preferred.
EDUCATION APPROACH
- This training is based on both theory and practice.
- Sessions of lectures illustrated with examples based on real cases.
- Practical exercises based on a full case study including role playings and oral presentations.
- Review exercises to assist the exam preparation.
- Practice test similar to the certification exam.
GENERAL INFORMATION
- The certification fee is included in the cost of the exam.
- Participants will be issued with a CPD (Continuing Professional Development) certificate.
- In case of failure to pass the exam, participants are allowed to take the exam free of charge under certain conditions.
COURSE AGENDA
- Training course objectives and structure
- Standards and regulatory frameworks
- Fundamental concepts and principles of information security risk management
- Information security risk management program
- Context establishment
- Risk identification
- Risk analysis
- Risk evaluation
- Risk treatment
- Information security risk communication and consultation
- Information security risk recording and reporting
- Information security risk monitoring and review
- OCTAVE and MEHARI methodologies
- EBIOS method and NIST framework
- CRAMM and TRA methods
- Closing of the training course
COURSE DATES AVAILABLE FOR REGISTRATION
ASK OR REGISTER
Do you have questions about the course? — Please fill in your details and we will contact you.
Frequently Asked Questions
PECB credentials are internationally recognized and endorsed by many accreditation bodies, so professionals who pursue them will benefit from our recognition in domestic and international markets.
The value of PECB certifications is validated by the accreditation from the International Accreditation Service (IAS-PCB-111), the United Kingdom Accreditation Service (UKAS-No. 21923) and the Korean Accreditation Board (KAB-PC-08) under ISO/IEC 17024 – General requirements for bodies operating certification of persons. The value of PECB certificate programs is validated by the accreditation from the ANSI National Accreditation Board (ANAB-Accreditation ID 1003) under ANSI/ASTM E2659-18, Standard Practice for Certificate Programs.
PECB is an associate member of The Independent Association of Accredited Registrars (IAAR), a full member of the International Personnel Certification Association (IPC), a signatory member of IPC MLA, and a member of Club EBIOS, CPD Certification Service, CLUSIF, Credential Engine, and ITCC. In addition, PECB is an approved Licensed Partner Publisher (LPP) from the Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB) for the Cybersecurity Maturity Model Certification standard (CMMC), is approved by Club EBIOS to offer the EBIOS Risk Manager Skills certification, and is approved by CNIL (Commission Nationale de l’Informatique et des Libertés) to offer DPO certification.
All certification candidates are responsible for their own study and preparation for the examination. No specific set of courses or curriculum of study is required as part of the certification process. Likewise, the completion of a course or program of study will significantly enhance your chance of passing a PECB certification examination. To learn more about exams, competency domains and knowledge statements please go to: PECB Exam Preparation Guides.
The exam is conducted online using the PECB Exams app
You will have the opportunity to choose a convenient date and time from the list of proposed slots.
Candidates will be required to arrive at least 30 minutes before the start of the certification exam. Candidates arriving late will not be given compensatory time for the late arrival and may be denied to enter the exam. All candidates are required to present a valid identity card such as a national ID card, driver’s license, or passport to the invigilator. The duration of the exam varies according to the type of examination taken (see description of the different exams for more details). Additional time can be provided to candidates taking the exam in a language different than their mother tongue (when requested by the candidates, on the exam day).
For more information about exam details, please visit Examination Rules and Policies
Results will be communicated by email within a period of 6 to 8 weeks from your examination date. The candidate will be provided with only two possible examination results: pass or fail, rather than an exact grade.
In case of a failure, the results will be accompanied with the list of domains where the candidate failed to fully answer the question. This can help the candidate better prepare for a retake the exam.
To qualify for PECB credentials, candidates must not only pass the exam but also meet certain educational and professional prerequisites. Each PECB certification has specific education and a set of experience requirements.
Candidates are required to fill out the online Certification Application Form, and fill out all other online forms (that can be accessed via their PECB online profile), including contact details of references who will be contacted to validate the candidates’ professional experience. Lastly, before the submitting the application, a candidate can choose to pay online or be billed. In case the candidate needs additional information, he/she should contact accounting@pecb.com and/or certification@pecb.com.
The approval of the application occurs as soon as the Certification Department validates that you fulfil all the certification requirements regarding the credential you have applied for. An email will be sent to the email address you provided during your application process to communicate you application status. If approved, you will then be able to download your certificate from your member account.
PECB certifications are valid for three years. To maintain the certification, the applicant shall demonstrate every year that he/she is still performing tasks that are related to the certification. PECB Certified professionals shall annually provide PECB with the number of hours of auditing and/or implementation related tasks they have performed, along with the contact details of individuals who can validate such tasks. Additionally, certified professionals should regularly pay the annual PECB certification maintenance fees.
A notification email is sent to our certified members, who are required to submit their Continuing Professional Development (CPD) along with the Annual Maintenance Fee (AMF) three months before the annual date of their certification. The PECB certified members will then be able to submit their CPDs by visiting their account and providing the required information for the respective certification.
You May Like
ISO 9001 Lead Auditor
ISO 9001 Lead Auditor training enables you to develop the necessary expertise to perform a Quality Management System (QMS) audit by applying widely recognized...
PCI DSS Implementation
This two-day course equips participants with theoretical knowledge and practical skills to implement processes following PCI DSS requirements
Lead Cloud Security Manager
Master the implementation and management of the cloud security program based on ISO/IEC 27017 and ISO/IEC 27018
ISO 9001 Lead Implementer
ISO 9001 Lead Implementer Course enables you to develop the expertise to support an organization in implementing/managing a Quality Management System
ISO 9001 Foundation
Attend ISO 9001 foundation course to learn about the best practices for implementing and managing a Quality Management System as specified in ISO 9001