Hanligent Education
Back to courses

Information Security

ISO/IEC 27005 — Information Security Risk Management

Levels available

Course types, duration & fees

Course typeWho should attendWhat your company benefitsDurationFee
FoundationThose who wish to learn the basis of implementing the management system and its processesProvide the organization with best-practice based orientation and mindset culture by understanding the main important elements of ISO standards2 daysHKD 4,400
Lead ManagerManagers in the relevant field who wish to master the guidelines specified by best practicesLead your organization to follow the guidelines specified by ISO standards that can help you increase the skills of your staff and improve efficiency3 daysHKD 9,600

About the standard

ISO/IEC 27005 provides a risk management framework for information security, giving organizations guidelines for identifying, analyzing, evaluating, treating, and monitoring information security risks. It supports the guidelines of ISO 31000 and is especially useful for organizations working to meet ISO/IEC 27001's risk management requirements. Applying an ISO/IEC 27005-based process involves an iterative risk assessment approach, risk treatment, ongoing stakeholder communication, and documentation of the whole process.

Levels available

  • Foundation — Introduces the core concepts of information security risk management and ISO/IEC 27005's framework.
  • Risk Manager — Builds practical skills to identify, analyze, evaluate, and treat information security risks within an organization.
  • Lead Risk Manager — For those responsible for leading an information security risk management process, developing advanced skills to align it with an ISMS and drive continual improvement.

Who should attend

This track suits information security officers, risk managers, and ISMS implementation team members responsible for managing information security risk. It's also relevant to consultants and auditors who assess how well an organization identifies and treats risk to its information assets.

Learning objectives

  • Understand the risk management concepts and principles set out in ISO/IEC 27005
  • Learn to manage information security risks based on recognized best practices
  • Gain the competence to establish an information security risk management process aligned with an ISMS
  • Understand how to integrate risk management into an organization's broader activities and functions
  • Learn to support the continual improvement of information security risk management and the ISMS

Why attend

Properly protecting information assets starts with a rigorous, repeatable way to identify and treat the risks that threaten them. This training builds the competence to establish a risk management process appropriate to an organization's context, gives professionals a competitive edge in the information security field, and demonstrates globally recognized expertise in managing information security risk.

PECB link

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005

Official PECB page