Get in Touch

Course Outline

Learning objectives 
Upon successful completion of this training course, you will be able to:
  • Explain the risk management concepts and principles outlined in ISO/IEC 27005:2022 and ISO 31000
  • Establish, maintain, and enhance an information security risk management framework based on ISO/IEC 27005:2022 guidelines
  • Apply information security risk management processes in accordance with ISO/IEC 27005:2022 guidelines
  • Plan and implement risk communication and consultation activities
Day 1:

Introduction to ISO/IEC 27005:2022 and risk management
 

  • Training course objectives and structure
  • Standards and regulatory frameworks
  • Fundamental concepts and principles of information security risk management
  • Information security risk management programme
  • Context establishment
Day 2:
Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005:2022
  • Risk identification
  • Risk analysis
  • Risk evaluation
  • Risk treatment
  • Information security risk communication and consultation
Day 3:
Risk recording and reporting, monitoring and review, and risk assessment methodologies
  • Information security risk recording and reporting
  • Information security risk monitoring and review
  • OCTAVE and MEHARI methodologies
  • EBIOS method and NIST framework
  • CRAMM and TRA methods
  • Course conclusion

Requirements

This training course is designed for:
  • Managers or consultants involved in, or responsible for, information security within an organisation
  • Individuals tasked with managing information security risks
  • Members of information security teams, IT professionals, and privacy officers
  • Individuals responsible for ensuring compliance with the information security requirements of ISO/IEC 27001 within an organisation
  • Project managers, consultants, or expert advisers seeking to master the management of information security risks
 21 Hours

Testimonials (2)

Related Categories