Learning objectives
- Define the risk context and criteria
- Identify assets, events, threats and consequences
- Analyse and assess risks through a documented method
- Build a treatment plan and monitoring mechanism
Who should attend
Risk managers, CISOs, compliance managers, auditors and security project managers.
Prerequisites
Foundational knowledge of information security and risk management.
Course outline
- Risk governance and integration with the ISMS
- Context, scope, criteria and risk appetite
- Identification of assets, sources, events and consequences
- Qualitative and quantitative analysis, likelihood and impact
- Assessment, treatment, acceptance and communication
- Risk register, indicators, monitoring and practical workshop
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: ISO, famille ISO/IEC 27005:2022 ↗
Introductory programme aligned with the ISO 27005 family. It includes neither a copy of the standard nor a third-party certification exam.
Introductory programme aligned with the ISO 27005 family. It includes neither a copy of the standard nor a third-party certification exam.
