About the ISO/IEC 27005 Risk Manager
The ISO/IEC 27005 Risk Manager programme teaches you to manage information security risk the way ISO/IEC 27001 expects — systematically, and in a way that stands up to audit. Delivered self-paced and online, it covers the full risk management process: establishing context, identifying and analysing risk, evaluating it, and deciding how to treat it.
You’ll work through the guidance of ISO/IEC 27005 and see how it plugs directly into an ISMS, giving you the practical judgement to run credible risk assessments and support certification.
Course Information
What You Will Learn
Course Curriculum
- Risk management concepts and terminology
- The ISO/IEC 27005 approach
- How risk fits within an ISMS
- Establishing the context
- Identifying assets, threats and vulnerabilities
- Analysing likelihood and impact
- Qualitative and quantitative methods
- Building the risk picture
- Evaluating and prioritising risk
- Treatment options and controls
- Risk acceptance
- The Statement of Applicability link
- Risk communication and consultation
- Monitoring and reviewing risk
- Keeping the assessment current
- Reporting to management
- Exam domains overview
- Revision guidance
- Booking and sitting the PECB exam
Get the Full Syllabus as a PDF
Curriculum, exam format & everything included — sent straight to your inbox.
All You Need to Know
This programme suits professionals responsible for information security risk, including:
- Risk managers and information security officers
- ISMS project team members
- Consultants advising on ISO/IEC 27001
- Anyone accountable for security risk decisions
A fundamental understanding of ISO/IEC 27005 or of risk management is recommended.
The programme prepares you for the PECB Certified ISO/IEC 27005 Risk Manager exam, covering the concepts and process of information security risk management.
What Our Learners Say
Great value for the depth of content. The ISO/IEC 27005 Risk Manager training covered ISMS risk assessment thoroughly, and the exam voucher being included made budgeting for it simple.
Solid, well-organized training. The path to strengthen our information security posture was clearly explained, and the practice materials before the exam made a real difference to my confidence.
As someone new to information security, I was worried the material would be too advanced. The course broke down ISMS risk assessment step by step, and support from Profice advisors made the whole process smooth.
The pacing suited a busy schedule, and the focus on ISMS risk assessment meant I could start applying what I learned before I'd even finished the course.
What stood out about this ISO/IEC 27005 Risk Manager training was how practical it was — real case studies, not just theory. I walked away confident about ISMS risk assessment and ready to apply it immediately.
Career Opportunities After This Training
An information security risk manager identifies, analyses and treats the risks facing an organisation's information assets. ISO 27005 Risk Manager training provides the structured, standard-based method employers look for.
Hiring Companies
Average Salary
A governance, risk and compliance (GRC) consultant helps organisations manage risk and meet regulatory obligations. The ISO 27005 course adds a rigorous information-security risk-assessment methodology to your toolkit.
Hiring Companies
Average Salary
A cyber risk analyst quantifies and reports on threats to systems and data so leaders can prioritise defences. ISO/IEC 27005 gives you a repeatable framework for assessing and communicating cyber risk.
Hiring Companies
Average Salary
Frequently Asked Questions
A PECB credential proving you can manage information security risk using the guidelines of ISO/IEC 27005 — identifying, analysing, evaluating and treating risks that affect an ISO 27001 ISMS.
ISO 27001 requires a risk-based approach to information security; ISO 27005 provides the detailed guidance on how to actually perform that risk management. The two are commonly used together.
The exam is an essay-type, open-book paper of roughly 3 hours. You need the passing score set by PECB (generally around 70%). After passing you receive a 'Certificate of Exam Success', and the full certification is issued once you also meet PECB's professional-experience requirements.
Risk managers, information security officers, ISMS implementers and consultants who need a structured, internationally recognised method for information security risk assessment.
PECB certifications are valid for three years. You keep yours active by earning Continuing Professional Development (CPD) credits and paying the annual maintenance fee.