About This Course
The ISO/IEC 27005 Risk Manager programme teaches you to manage information security risk the way ISO/IEC 27001 expects — systematically, and in a way that stands up to audit. Delivered self-paced and online, it covers the full risk management process: establishing context, identifying and analysing risk, evaluating it, and deciding how to treat it.
You’ll work through the guidance of ISO/IEC 27005 and see how it plugs directly into an ISMS, giving you the practical judgement to run credible risk assessments and support certification.
Course Information
What You Will Learn
Course Curriculum
- Risk management concepts and terminology
- The ISO/IEC 27005 approach
- How risk fits within an ISMS
- Establishing the context
- Identifying assets, threats and vulnerabilities
- Analysing likelihood and impact
- Qualitative and quantitative methods
- Building the risk picture
- Evaluating and prioritising risk
- Treatment options and controls
- Risk acceptance
- The Statement of Applicability link
- Risk communication and consultation
- Monitoring and reviewing risk
- Keeping the assessment current
- Reporting to management
- Exam domains overview
- Revision guidance
- Booking and sitting the PECB exam
Get the Full Syllabus as a PDF
Curriculum, exam format & everything included — sent straight to your inbox.
All You Need to Know
This programme suits professionals responsible for information security risk, including:
- Risk managers and information security officers
- ISMS project team members
- Consultants advising on ISO/IEC 27001
- Anyone accountable for security risk decisions
A fundamental understanding of ISO/IEC 27005 or of risk management is recommended.
The programme prepares you for the PECB Certified ISO/IEC 27005 Risk Manager exam, covering the concepts and process of information security risk management.
Frequently Asked Questions
Yes — it’s delivered online and self-paced, so you can study at your own pace.
ISO/IEC 27005 provides the risk management method that an ISO/IEC 27001 ISMS relies on — the two work hand in hand.
A basic understanding of risk management or ISO/IEC 27005 is helpful, but the programme builds the concepts up from the fundamentals.
After passing the exam you can apply for the PECB Certified ISO/IEC 27005 Risk Manager credential.
Yes — the self-paced kit includes one certification exam and one free retake.