
Welcome to this online course on information security risk management according to the provisions of ISO/IEC 27005:2022
About the three attributes of information security (confidentiality, integrity and availability). About what represents an ISMS (Information Security Management System)
About the standards in the ISO/IEC 27000 series.
About the purpose of ISO/IEC 27005. About the structure of this standard and its revision history.
About the definition of risk. About what represents risk management. About the steps of the risk management process.
About the identification of stakeholders for the risk management process. About the risk appetite of an organization
About the process to establish risk acceptance criteria
About likelihood and consequence as constitutive elements of risk. About establishing a risk level
The differences between using a qualitative and a quantitative approach to defining potential consequences and examples to illustrate
About the differences between establishing likelihood and calculating a level of risk using a qualitative and a quantitative approach
Details on the requirements for the risk assessment to produce consistent, valid and comparable results
About the method to identify information security risks starting from event scenarios and considering potential attackers, their motivation and ability to act
About the approach to identify information security risks starting from assets and considering the threats and vulnerabilities that may affect them
About who can be a risk owner. About the requirements for risk owners and why it's important to appoint risk owners
About combining consequences and likelihood to calculate a level of risk. About deliberate and accidental risk sources and what is the difference between them. About the basic sources of assessment uncertainty
About comparing the calculated level of risk with the risk acceptance criteria to determine those risks that require treatment
About the most common options available to an organization to treat its information security risks: avoidance, modification, sharing and retention
About the security controls from ISO/IEC 27001 with examples and details about their classification
About the classification of controls considering their purpose and when they are to be applied
About the requirements of ISO/IEC 27001:2022 regarding the Statement of Applicability
About the risk treatment plan required by ISO/IEC 27001:2022 as part of an ISMS
About integrating risk management into the organization's operations. About communication and consultation in relation to information security risk management. About evaluating the information security performance of an organization
Suggestions for improving continually the information security risk management process
About the certification of organizations and persons in the context of information security risk management
Thank you for taking this course!
ISO/IEC 27005 is the international standard for information security risk management — the detailed guidance for the risk assessment and risk treatment process at the core of every ISO/IEC 27001 information security management system (ISMS). Where ISO/IEC 27001 requires organizations to assess and treat information security risks, ISO/IEC 27005 explains how.
This course walks you through that framework step by step, applicable to any organization regardless of size or sector.
Course structure
Foundations — information security management, the ISO/IEC 27000 series of standards, and an introduction to ISO/IEC 27005
Context establishment — defining the organization's risk appetite, setting risk acceptance criteria, and the difference between qualitative and quantitative approaches to defining consequences and likelihood
Risk assessment — the complete process: risk identification using the two approaches of ISO/IEC 27005 (the event-based approach and the asset-based approach), risk analysis, risk evaluation, and the role of risk owners
Risk treatment — the risk treatment options for information security risks, the controls of ISO/IEC 27001:2022, and the key ISMS documents that capture the results: the Statement of Applicability (SoA) and the risk treatment plan
Improvement and certification — continual improvement of the risk management process, plus the certification paths for organizations and individuals
What you will be able to do
By the end of the course you will understand the full information security risk management process — threat and vulnerability analysis, calculating risk levels, selecting risk treatment options — and you will be able to run a risk assessment, document its results in the SoA and risk treatment plan, and support a risk management program that protects the confidentiality, integrity and availability of your organization's information.
Who this course is for
ISMS implementers and information security officers responsible for the risk assessment of ISO/IEC 27001
Risk managers and GRC professionals specializing in information security and cyber risk
IT and cybersecurity professionals moving into risk-based roles
Auditors and consultants who evaluate risk assessments and risk treatment plans
Anyone preparing an organization for ISO/IEC 27001 certification — the risk assessment is where every ISMS begins
Enhance your expertise in information security risk management with the standard that defines how it's done.