Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
ISO/IEC 27005: Information Security Risk Management
Highest Rated
Rating: 4.5 out of 5(2,347 ratings)
7,925 students

ISO/IEC 27005: Information Security Risk Management

Master risk assessment and risk treatment for your ISMS — identify, analyse and evaluate risks with ISO/IEC 27005
Last updated 5/2026
English
Arabic [Auto],German [Auto],

What you'll learn

  • What is an ISMS (Information Security Management System)
  • How to determine the risk appetite of an organization
  • What is risk acceptance criteria and how it can be established
  • The different approaches for information security risk identification
  • The relationship between threats and vulnerabilities
  • How to estimate likelihood and consequences for a risk
  • How to calculate a risk level
  • Why risks should be owned and who can be a risk owner
  • The options for treating information security risks
  • Key documents for an ISMS such as SoA and risk treatment plan

Course content

5 sections26 lectures2h 26m total length
  • Introduction4:04

    Welcome to this online course on information security risk management according to the provisions of ISO/IEC 27005:2022

  • Information security management5:58

    About the three attributes of information security (confidentiality, integrity and availability). About what represents an ISMS (Information Security Management System)

  • The ISO/IEC 27000 series of standards7:30

    About the standards in the ISO/IEC 27000 series.

  • About ISO/IEC 270054:48

    About the purpose of ISO/IEC 27005. About the structure of this standard and its revision history.

  • Information security risk management5:34

    About the definition of risk. About what represents risk management. About the steps of the risk management process.

Requirements

  • Familiarity with the ISO standards on information security management is useful but not mandatory

Description

ISO/IEC 27005 is the international standard for information security risk management — the detailed guidance for the risk assessment and risk treatment process at the core of every ISO/IEC 27001 information security management system (ISMS). Where ISO/IEC 27001 requires organizations to assess and treat information security risks, ISO/IEC 27005 explains how.

This course walks you through that framework step by step, applicable to any organization regardless of size or sector.

Course structure

  • Foundations — information security management, the ISO/IEC 27000 series of standards, and an introduction to ISO/IEC 27005

  • Context establishment — defining the organization's risk appetite, setting risk acceptance criteria, and the difference between qualitative and quantitative approaches to defining consequences and likelihood

  • Risk assessment — the complete process: risk identification using the two approaches of ISO/IEC 27005 (the event-based approach and the asset-based approach), risk analysis, risk evaluation, and the role of risk owners

  • Risk treatment — the risk treatment options for information security risks, the controls of ISO/IEC 27001:2022, and the key ISMS documents that capture the results: the Statement of Applicability (SoA) and the risk treatment plan

  • Improvement and certification — continual improvement of the risk management process, plus the certification paths for organizations and individuals

What you will be able to do

By the end of the course you will understand the full information security risk management process — threat and vulnerability analysis, calculating risk levels, selecting risk treatment options — and you will be able to run a risk assessment, document its results in the SoA and risk treatment plan, and support a risk management program that protects the confidentiality, integrity and availability of your organization's information.

Who this course is for

  • ISMS implementers and information security officers responsible for the risk assessment of ISO/IEC 27001

  • Risk managers and GRC professionals specializing in information security and cyber risk

  • IT and cybersecurity professionals moving into risk-based roles

  • Auditors and consultants who evaluate risk assessments and risk treatment plans

  • Anyone preparing an organization for ISO/IEC 27001 certification — the risk assessment is where every ISMS begins

Enhance your expertise in information security risk management with the standard that defines how it's done.

Who this course is for:

  • Information security officers
  • Information security risk managers and analysts
  • ISO enthusiasts
  • Information security auditors and consultants