Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Learning objectives
Upon the successful completion of this training course, you will be able to:
- Explain the risk management concepts and principles outlined by ISO/IEC 27005:2022 and ISO 31000
- Establish, maintain, and improve an information security risk management framework based on the guidelines of ISO/IEC 27005:2022
- Apply information security risk management processes based on the guidelines of ISO/IEC 27005:2022
- Plan and establish risk communication and consultation activities
Day 1:
Introduction to ISO/IEC 27005:2022 and risk management
- Training course objectives and structure
- Standards and regulatory frameworks
- Fundamental concepts and principles of information security risk management
- Information security risk management program
- Context establishment
Day 2:
Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005:2022
- Risk identification
- Risk analysis
- Risk evaluation
- Risk treatment
- Information security risk communication and consultation
Day 3:
Risk recording and reporting, monitoring and review, and risk assessment methods
- Information security risk recording and reporting
- Information security risk monitoring and review
- OCTAVE and MEHARI methodologies
- EBIOS method and NIST framework
- CRAMM and TRA methods
- Closing of the training course
Requirements
This training course is intended for:
- Managers or consultants involved in or responsible for information security in an organization
- Individuals responsible for managing information security risks
- Members of information security teams, IT professionals, and privacy officers
- Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
- Project managers, consultants, or expert advisers seeking to master the management of information security risks
21 Hours
Testimonials (4)
The fact that all the standard was reviewed and discussed with some examples, when needed and required.
Ioana
Course - ISO/IEC 27005 Information Security Risk Management
The training was well put together & very informative.
Siobhan Kavanagh - SEEC MM Ltd.,
Course - ISO 9001 Lead Implementer
The quizzes to reinforce the reading and the ability to ask questions at any time
Jonathan
Course - ISO 9001 Lead Auditor
Dereck's overall preparedness . Dereck has great communications' skills !!