PECB CERTIFIED ISO/IEC 27005 Lead Risk Manager


The target audience for training
This course is designed for :
- Managers or consultants involved in or responsible for information security in an organisation
- Persons responsible for information security risk management
- Members of information security teams, IT professionals and privacy officers
- Persons responsible for maintaining compliance with the information security requirements of standard/IEC 27001 within an organisation
- Project managers, consultants or expert advisers seeking to master information security risk management
What you will learn
Risk management is an essential component of any information security programme. An effective information security risk management programme enables organisations to detect, treat, mitigate and even prevent information security risks.
The ISO/IEC 27005 Lead Risk Manager course provides an information security risk management framework in accordance with the guidelines of ISO/IEC 27005, which also supports the general concepts of ISO/IEC 27001. The course also provides participants with an in-depth understanding of other leading risk management frameworks and methodologies, such as OCTAVE, EBIOS, MEHARI, CRAMM, NIST and the harmonised EMR methodology.
The PECB ISO/IEC 27005 Lead Risk Manager certificate demonstrates that the participant has acquired the skills and knowledge necessary to successfully execute the processes required for an effective information security risk management program. It also demonstrates the holder's ability to help organizations maintain and continually improve their information security risk management program.
This training is followed by an examination. If you pass the exam, you can apply for certification. "PECB Certified ISO/IEC 27005 Lead Risk Manager. For more information on the examination process, please refer to the Examination, certification and general information section below.
Training programme
- Duration: 5 days
Day 1: Introduction to ISO/IEC 27005 and risk management
- Objectives and structure of the course
- Standards and regulatory frameworks
- Fundamental concepts and principles of information security risk management
- Risk management programme
- Defining the context
Day 2: Identification, assessment and treatment of risks in accordance with ISO/IEC 27005
- Identifying risks
- Risk analysis
- Risk assessment
- Risk management
Day 3: Acceptance, communication, consultation, monitoring and review of information security risks
- Acceptance of information security risks
- Communication and consultation on information security risks
- Monitoring and reviewing information security risks
Day 4: Risk assessment methods
- OCTAVE and MEHARI methodologies
- EBIOS method h NIST framework
- CRAMM and EMR methods
- Closing the course
Day 5: Certification exam
Examination "PECB Certified ISO/IEC 27005 Lead Risk Manager fully meets the requirements of the PECB Examination and Certification Programme (ECP). It covers the following areas of competence: Duration: 2 hours
- Area 1: Fundamental principles and concepts of information security risk management
- Area 2: Implementation of an information security risk management programme
- Area 3: Information security risk assessment
- Area 4: Dealing with information security risks
- Area 5: Communication, monitoring and improvement of information security risks
- Area 6: Information security risk assessment methodologies
Training objectives:
At the end of this course, you will be able to :
- Explain the concepts and principles of risk management as defined by the ISO/IEC 27005 and ISO 31000 standards
- Implement, maintain and improve an information security risk management framework in accordance with the guidelines of standard/IEC 27005
- Applying information security risk management processes in accordance with the guidelines of standard/IEC 27005
- Plan and implement risk communication and consultation activities
- Monitor, review and improve the information security risk management framework and process based on the results of information security risk management activities.
Training prerequisites
Participation in this course requires a fundamental understanding of the IEC 27005 standard and in-depth knowledge of risk management and information security.
Examination guide
Download the exam guide
Tarif
- 3800 €
- Language : French
- Level : Fundamental
- Certification body : 0
- Certification: Yes
- Accessibility : Yes
- Duration: 5 days
Important information:
Our courses are not registered with the Répertoire National des Certifications Professionnelles (RNCP), but they do comply with the requirements of the Répertoire Spécifique (RS).