logo-img
ISO 27005:2022 - Certified Risk Manager (PECB)

ISO 27005:2022 - Certified Risk Manager (PECB)

3 days Classroom Engels, Nederlands

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

The ISO/IEC 27005 Risk Manager training enables participants to understand the process of developing, establishing, maintaining, and improving an information security risk management framework based on the guidelines of ISO/IEC 27005:2022. The training provides valuable information about risk management concepts and principles as described in ISO/IEC 27005 and also ISO 31000, making it an ideal tool for ISO 27001 implementations or the maintenance of an ISMS.

In this training, you will acquire the necessary knowledge and skills to identify, assess, analyze, treat, and communicate information security risks based on ISO/IEC 27005. On the additional third day, you will receive an overview of other common risk assessment methods, such as:

  • OCTAVE
  • MEHARI
  • EBIOS
  • NIST
  • CRAMM
  • Harmonized TRA

This training and the methodology taught within it help you to get to know your organization in detail. When focusing on risk management for a successful ISMS, you must be very clear about what you are doing, how you are doing it, when and why you are doing it, and who is involved. The goal of the training is to instill the investigative mindset that a good risk manager needs.

The lesson days consist of a combination of theory and practice:

  • Lessons that are richly filled with practical examples based on real cases
  • Practical assignments based on a full case study including role play
  • A mock exam that is comparable to the actual certification exam

In the ISO 27005 Risk Manager exam, you will be tested on the following domains, for which the training will obviously prepare you:

  • Domain 1: Fundamental principles and concepts of information security risk management
  • Domain 2: Implementation of an information security risk management program
  • Domain 3: Framework and processes for information security risk management based on ISO/IEC 27005
  • Domain 4: Other methods for assessing information security risks

Working method

The training is a combination of theory and practice and is illustrated with examples based on real cases. To fully benefit from the various practical assignments, the number of participants per group is limited. You will complete the training directly with the subsequent exam after which, depending on your performance, you can apply for the corresponding certification and title based on your experience. Our trainers have extensive practical experience with risk management in various sectors.

ISO 27005 Certified Risk Manager is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it is just like being present in the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend it again in the classroom with us free of charge within a year.

Certification

By passing the included "ISO/IEC 27005:2022 Certified Risk Manager" exam, which is held on the last day of the training, you will obtain the corresponding PECB Certified ISO/IEC 27005 (Provisional/Senior) Risk Manager certification from PECB. This exam can be taken both on-site with us and online from home. If you prefer not to take the exam immediately after the training, you can still do so at a later time, up to a year after the training.

Training Requirements

  • Verantwoordelijken in een organisatie voor Risk Management of Informatiebeveiliging,
  • IT (Security) Consultants of Adviseurs,
  • personen die zich bezighouden met ISO 27001 implementatie(s)

Training Content

Doelstellingen en opzet van de training

Normen en regelgevende kaders

Fundamentele concepten en principes van informatiebeveiligingsrisicomanagement

Programma voor informatiebeveiligingsrisicomanagement

Vaststellen van de context

Risico-identificatie

Risicoanalyse

Risicobeoordeling

Risicobehandeling

Communicatie en consultatie over informatiebeveiligingsrisico’s

Registratie en rapportage van informatiebeveiligingsrisico’s

Monitoring en evaluatie van informatiebeveiligingsrisico’s

OCTAVE- en MEHARI-methodologieën

EBIOS-methode en NIST-framework

CRAMM- en TRA-methoden

Description

The ISO/IEC 27005 Risk Manager training enables participants to understand the process of developing, establishing, maintaining, and improving an information security risk management framework based on the guidelines of ISO/IEC 27005:2022. The training provides valuable information about risk management concepts and principles as described in ISO/IEC 27005 and also ISO 31000, making it an ideal tool for ISO 27001 implementations or the maintenance of an ISMS.

In this training, you will acquire the necessary knowledge and skills to identify, assess, analyze, treat, and communicate information security risks based on ISO/IEC 27005. On the additional third day, you will receive an overview of other common risk assessment methods, such as:

  • OCTAVE
  • MEHARI
  • EBIOS
  • NIST
  • CRAMM
  • Harmonized TRA

This training and the methodology taught within it help you to get to know your organization in detail. When focusing on risk management for a successful ISMS, you must be very clear about what you are doing, how you are doing it, when and why you are doing it, and who is involved. The goal of the training is to instill the investigative mindset that a good risk manager needs.

The lesson days consist of a combination of theory and practice:

  • Lessons that are richly filled with practical examples based on real cases
  • Practical assignments based on a full case study including role play
  • A mock exam that is comparable to the actual certification exam

In the ISO 27005 Risk Manager exam, you will be tested on the following domains, for which the training will obviously prepare you:

  • Domain 1: Fundamental principles and concepts of information security risk management
  • Domain 2: Implementation of an information security risk management program
  • Domain 3: Framework and processes for information security risk management based on ISO/IEC 27005
  • Domain 4: Other methods for assessing information security risks

Working method

The training is a combination of theory and practice and is illustrated with examples based on real cases. To fully benefit from the various practical assignments, the number of participants per group is limited. You will complete the training directly with the subsequent exam after which, depending on your performance, you can apply for the corresponding certification and title based on your experience. Our trainers have extensive practical experience with risk management in various sectors.

ISO 27005 Certified Risk Manager is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it is just like being present in the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend it again in the classroom with us free of charge within a year.

Certification

By passing the included "ISO/IEC 27005:2022 Certified Risk Manager" exam, which is held on the last day of the training, you will obtain the corresponding PECB Certified ISO/IEC 27005 (Provisional/Senior) Risk Manager certification from PECB. This exam can be taken both on-site with us and online from home. If you prefer not to take the exam immediately after the training, you can still do so at a later time, up to a year after the training.

Training Requirements

  • Verantwoordelijken in een organisatie voor Risk Management of Informatiebeveiliging,
  • IT (Security) Consultants of Adviseurs,
  • personen die zich bezighouden met ISO 27001 implementatie(s)

Training Content

Doelstellingen en opzet van de training

Normen en regelgevende kaders

Fundamentele concepten en principes van informatiebeveiligingsrisicomanagement

Programma voor informatiebeveiligingsrisicomanagement

Vaststellen van de context

Risico-identificatie

Risicoanalyse

Risicobeoordeling

Risicobehandeling

Communicatie en consultatie over informatiebeveiligingsrisico’s

Registratie en rapportage van informatiebeveiligingsrisico’s

Monitoring en evaluatie van informatiebeveiligingsrisico’s

OCTAVE- en MEHARI-methodologieën

EBIOS-methode en NIST-framework

CRAMM- en TRA-methoden

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The ISO 27005:2022 - Certified Risk Manager (PECB)?

  • Explain the concepts and principles of risk management as described in ISO/IEC 27005 and ISO 31000.
  • Planning and setting up risk communication and consultation activities
  • Establishing, maintaining, and improving an information security risk management framework based on the guidelines of ISO/IEC 27005.
  • Applying information security risk management processes based on the guidelines of ISO/IEC 27005

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Date: 16 - 18 november 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: In overleg

Location: TSTC Veenendaal - Klassikaal & Live Online

1

Applicant Information

2

Billing Information

Shape

Frequently Asked Questions

ISO/IEC 27005 provides a framework for risk management that allows organizations to manage information security risks. It specifically offers guidelines for identifying, analyzing, evaluating, treating, and monitoring information security risks. The standard supports the guidelines of ISO 31000 and is particularly useful for organizations that want to protect their information assets and achieve their information security objectives.

ISO/IEC 27005 can be very useful for organizations that want to comply with the requirements of ISO/IEC 27001 regarding risk management. By implementing a risk management process based on ISO/IEC 27005, organizations increase the effectiveness of their ISMS, address information security risks, and implement appropriate procedures for information security risk management.

A PECB ISO/IEC 27005 certification demonstrates that you have the necessary competencies to: • Explain and apply the concepts and principles of risk management based on ISO/IEC 27005 • Manage information security risks based on best practices • Establish an information security risk management process based on the guidelines of ISO/IEC 27005 • Align the information security risk management process with the ISMS • Support an organization in continuously improving its information security risk management processes and ISMS • Integrate risk management into the activities and functions of organizations

ISO 31000 and ISO 27005 differ mainly in scope and application. ISO 31000 focuses on risk management at the organizational level (enterprise risk management), making it broadly applicable regardless of sector or type of risk, and provides general principles, frameworks, and processes. ISO 27005 specifically addresses information security risks, is part of the Information Security Management System (ISMS) domain, closely aligns with ISO/IEC 27001, and delves deeper into threats, vulnerabilities, and security controls. In short: ISO 31000 = general risk management ISO 27005 = risk management specifically for information security

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino