- Domain 1: Fundamental principles and concepts of information security risk management
- Domain 2: Implementation of an information security risk management program
- Domain 3: Information security risk assessment
- Domain 4: Information security risk treatment
- Domain 5: Information security risk communication, monitoring, and improvement
- Domain 6: Information security risk assessment methodologies
To be considered valid, the information security risk management activities should follow best implementation and management practices and include the following:
- Defining a risk management approach
- Determining the risk management objectives and scope
- Performing risk assessment
- Developing a risk management program
- Defining risk evaluation and risk acceptance criteria
- Evaluating risk treatment options
- Monitoring and reviewing the risk management program
Certification Rules and Policies
- Certification and examination fees are included in the price of the training course
- Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
- An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
- In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.
Why should you attend?
ISO/IEC 27001
EBIOS
Educational approach
- The training course provides best practices of risk management that will help participants prepare for real-life situations.
- The training course contains essay-type exercises (some of which are based on a case study) and multiple-choice quizzes (some of which are scenario-based).
- Participants are encouraged to communicate and discuss with each other when completing stand-alone and scenario-based quizzes and exercises.
- The structure of the quizzes is similar to the certification exam.
