Rabat, MoroccoOn-site · Virtual classroom · Corporate training
contact@avnorysacademy.com

Cybersecurity GRC

Risk management based on ISO/IEC 27005

Establish a coherent process for identifying, analysing, assessing and treating security risks.

Learning objectives

  • Define the risk context and criteria
  • Identify assets, events, threats and consequences
  • Analyse and assess risks through a documented method
  • Build a treatment plan and monitoring mechanism

Who should attend

Risk managers, CISOs, compliance managers, auditors and security project managers.

Prerequisites

Foundational knowledge of information security and risk management.

Course outline

  • Risk governance and integration with the ISMS
  • Context, scope, criteria and risk appetite
  • Identification of assets, sources, events and consequences
  • Qualitative and quantitative analysis, likelihood and impact
  • Assessment, treatment, acceptance and communication
  • Risk register, indicators, monitoring and practical workshop

Learning approach

Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.

Reference source: ISO, famille ISO/IEC 27005:2022 ↗
Introductory programme aligned with the ISO 27005 family. It includes neither a copy of the standard nor a third-party certification exam.