About
ISO®/IEC 27005:2022 provides a comprehensive framework for organizations to manage information security risks effectively. This standard aligns with ISO®/IEC 27001, guiding organizations in establishing, implementing, maintaining, and continually improving their Information Security Management System (ISMS). It emphasizes the importance of a structured risk management process that includes risk assessment and treatment, ensuring organizations can navigate the complex landscape of information security threats and vulnerabilities.
Certification Body: International Organization for Standardization (ISO®)
Learning Objective
Participants in ISO®/IEC 27005:2022 training will:
- Gain an understanding of information security risk management principles.
- Learn how to implement risk management processes aligned with ISO/IEC 27001.
- Develop skills to identify, analyze, evaluate, and treat information security risks.
- Understand the context of the organization and the requirements of interested parties.
- Acquire the ability to formulate and implement risk treatment plans effectively.
Exam Information
- Format: Online, closed-book, remotely proctored
- Number of Questions: 40 multiple-choice questions
- Passing Score: 70%
- Duration: 60 minutes to complete the exam
Recertification
- Frequency: Required every three years
- Ongoing Education: Engage in continuous education and training in information security risk management
- Demonstration of Competence: Must show continued competence in the field
- Requirements:
- Accumulate a specified number of continuing education credits, or
- Retake the certification exam
Curriculum
- 6 Sections
- 19 Lessons
- 40 Hours
Expand all sectionsCollapse all sections
- Introduction to Information Security Risk Management3
- Risk Management Process4
- Context Establishment3
- Risk Assessment3
- Risk Treatment3
- Monitoring and Review3
Requirements
- Prerequisites: Generally, no strict prerequisites for attending training courses
- Recommended Knowledge: Foundational understanding of information security concepts is beneficial
- Familiarity: Knowledge of ISO/IEC 27001 is advantageous
Target audiences
- Information security professionals looking to implement or improve risk management practices.
- Management personnel responsible for overseeing information security policies and procedures.
- Auditors and compliance officers who need to understand the risk management processes outlined in ISO/IEC 27005.
- IT and security managers seeking to develop a robust ISMS within their organizations.