Home/V-Academy/ISO/IEC 27005

ISO/IEC 27005

Run information security risk management that leadership can read and act on.

Overview

ISO/IEC 27005: what it is and why it matters

International standard (guidance) · Information Security

ISO/IEC 27005 gives guidance on managing information security risks, from establishing context through assessment, treatment, acceptance, communication and monitoring. It supports the risk requirements of ISO/IEC 27001 without prescribing one method.

The value of the subject is practical: a risk process that produces decisions, owners and treatment plans rather than a spreadsheet nobody reads.

TypeInternational standard, guidance
SubjectInformation security risk management
Edition referenced2022 edition
SupportsISO/IEC 27001 risk requirements
Who should attend

Built for the people who carry the work

  • Risk managers and information security officers
  • ISMS implementers responsible for risk treatment
  • Consultants running risk workshops
  • Internal auditors reviewing risk processes
Learning outcomes

What you will be able to do

  • Establish risk criteria, scope and context
  • Identify assets, threats, vulnerabilities and consequences
  • Estimate and evaluate risk with a repeatable method
  • Choose treatment options and record residual risk and acceptance
  • Communicate risk to management in business terms
  • Monitor and review risk over time
Topics covered

Subject outline

  1. 01

    Risk management process and its place in an ISMS

  2. 02

    Context, criteria and scope

  3. 03

    Risk identification: event-based and asset-based approaches

  4. 04

    Risk analysis and evaluation

  5. 05

    Risk treatment and residual risk

  6. 06

    Communication, consultation, monitoring and review

  7. 07

    Choosing and comparing risk methods

Practical relevance

How it supports real work

01

Building a risk register tied to business services

02

Making treatment plans with named owners and dates

03

Showing an auditor how risk drove control selection

Certification pathway

Training, examination and certification are different steps

ISO/IEC 27005 is guidance, so there is no organisational certificate for it. Personal credentials in risk management are offered by several bodies, each with its own prerequisites and exams.

  • Attending training does not award a credential.
  • Personal credentials depend on the issuing body and normally need an exam.
  • We confirm the route and requirements with you before you enrol.
Delivery and questions

What is confirmed, and what people ask

Delivery information

Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.

Enquire About This Course

Frequently asked questions

Does ISO/IEC 27005 prescribe a single risk method?

No. It describes a process and allows several methods. EBIOS Risk Manager is one example of a method that can be used.

How does it relate to ISO 31000?

ISO 31000 is the general risk management guideline. ISO/IEC 27005 applies that thinking to information security.

Is it only for ISO/IEC 27001 projects?

No. Any organisation managing information risk can use it.

Related courses

Related Valtrenix services

Enquire

Request course information

Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for ISO/IEC 27005.

  • Individual and team training enquiries welcome
  • No fees, dates or formats are published until confirmed
  • We confirm the certification route before you enrol

Your enquiry

We use these details only to reply to your enquiry about ISO/IEC 27005. Read our privacy policy.