Skip to main content
ISO 31000

ISO 27005 Lead Risk Manager

ISO 27005 Lead Risk Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead Risk Manager5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants who are involved in or responsible for information security within their organisation
  • Individuals whose role includes managing information security risks, including ISMS professionals and risk owners
  • Members of information security teams, IT professionals, and privacy officers seeking structured risk management skills
  • Professionals responsible for maintaining conformity with ISO/IEC 27001 information security requirements
  • Project managers, consultants, and expert advisers aiming to master information security risk management at a lead level

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no prior exposure to information security or risk management concepts may find the pace too advanced
  • Those seeking a purely technical or hands-on cybersecurity skills course rather than a governance and management focus
  • Professionals looking for a short introductory overview; a three-day option may be a better starting point
  • Learners whose primary interest is auditing application or network security rather than risk management frameworks

What you'll be able to do

  • 1Explain risk management concepts and principles as defined by ISO/IEC 27005 and ISO 31000
  • 2Establish, maintain, and continually improve an information security risk management framework aligned with ISO/IEC 27005 guidelines
  • 3Apply ISO/IEC 27005 risk management processes across the full risk lifecycle within an organisation
  • 4Plan and implement risk communication and consultation activities that engage relevant stakeholders
  • 5Record, report, monitor, and review both the risk management process and the supporting framework
  • 6Select and apply appropriate risk assessment methodologies suited to different organisational contexts
  • 7Distinguish between risk identification, analysis, evaluation, and treatment stages and execute each systematically
  • 8Integrate information security risk management practices with broader organisational governance requirements

Day by day

Day 1Introduction to ISO/IEC 27005 and information security risk management
  • Overview of ISO/IEC 27005 and ISO 31000

    This module introduces the scope, structure, and purpose of ISO/IEC 27005 in the context of information security risk management and its relationship with ISO 31000.

  • Core risk management concepts and principles

    Participants examine fundamental risk terminology, principles, and the value that a structured risk management approach delivers to an organisation.

  • Information security risk management framework

    This module covers the components required to establish an information security risk management framework and how it aligns with broader organisational governance.

By end of day

  • Articulate the key principles of ISO/IEC 27005 and their relationship with ISO 31000
  • Identify the structural elements of an information security risk management framework
  • Explain how risk management supports organisational information security objectives
Day 2Risk identification, analysis, evaluation, and treatment based on ISO/IEC 27005
  • Information security risk identification

    This module covers techniques for identifying information assets, threats, vulnerabilities, and existing controls as inputs to the risk assessment process.

  • Risk analysis and evaluation

    Participants learn how to analyse identified risks using qualitative and quantitative approaches and evaluate them against established risk criteria.

  • Risk treatment planning

    This module examines the four risk treatment options outlined in ISO/IEC 27005 and the process for selecting and documenting appropriate treatment plans.

By end of day

  • Conduct a structured information security risk identification exercise
  • Apply risk analysis and evaluation techniques to prioritise risks against organisational criteria
  • Select and document risk treatment options in line with ISO/IEC 27005 guidance
Day 3Risk communication, consultation, recording, reporting, monitoring, and review
  • Risk communication and consultation

    This module addresses how to plan and execute effective communication and consultation with internal and external stakeholders throughout the risk management process.

  • Recording and reporting risk management activities

    Participants explore documentation requirements and reporting structures that support transparency, accountability, and audit readiness.

  • Monitoring and review of the risk management process

    This module covers the ongoing activities required to monitor risk status, review the effectiveness of treatments, and trigger updates to the framework.

By end of day

  • Design a risk communication and consultation plan tailored to stakeholder needs
  • Produce risk records and reports that meet organisational and ISO/IEC 27005 documentation expectations
  • Establish monitoring and review routines that keep the risk management framework current and effective
Day 4Risk assessment methods
  • Overview of recognised risk assessment methodologies

    This module surveys established risk assessment methods used in information security contexts and examines their respective strengths and limitations.

  • Selecting and adapting methodologies to organisational context

    Participants learn how to evaluate and choose an appropriate risk assessment methodology based on organisational size, sector, and risk appetite.

  • Integrating methodologies within the ISO/IEC 27005 process

    This module explores how specific risk assessment methods can be embedded within the ISO/IEC 27005 risk management process without conflicting with its guidelines.

By end of day

  • Compare multiple risk assessment methodologies and justify selection decisions
  • Adapt a chosen methodology to fit a specific organisational risk management context
  • Align the chosen methodology with the requirements of the ISO/IEC 27005 risk management process
Day 5Exam preparation and review
  • Competency domain review

    This session revisits the six competency domains covered across the course to consolidate understanding before the PECB certification exam.

  • Practice and guided Q&A

    Participants work through practice questions and discuss areas of uncertainty with the trainer to strengthen exam readiness.

By end of day

  • Identify personal knowledge gaps across the six exam competency domains
  • Approach the PECB ISO/IEC 27005 Lead Risk Manager exam with a structured preparation strategy

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security risk management
  • Domain 2: Implementation of an information security risk management program
  • Domain 3: Information security risk assessment
  • Domain 4: Information security risk treatment
  • Domain 5: Information security risk communication, monitoring, and improvement
  • Domain 6: Information security risk assessment methodologies

To be considered valid, the information security risk management activities should follow best implementation and management practices and include the following:

  1. Defining a risk management approach
  2. Determining the risk management objectives and scope
  3. Performing risk assessment
  4. Developing a risk management program
  5. Defining risk evaluation and risk acceptance criteria
  6. Evaluating risk treatment options
  7. Monitoring and reviewing the risk management program

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Why should you attend?

ISO/IEC 27001

EBIOS

Educational approach

  • The training course provides best practices of risk management that will help participants prepare for real-life situations.
  • The training course contains essay-type exercises (some of which are based on a case study) and multiple-choice quizzes (some of which are scenario-based).
  • Participants are encouraged to communicate and discuss with each other when completing stand-alone and scenario-based quizzes and exercises.
  • The structure of the quizzes is similar to the certification exam.

Buyers always ask

What is the difference between completing this training and obtaining a PECB certification?+

Completing this five-day training course means you have participated in all scheduled instruction and activities delivered by Cyber Academy. It does not automatically confer a PECB certification.

To pursue the PECB Certified ISO/IEC 27005 Lead Risk Manager credential, you would need to separately pass the PECB certification exam and satisfy the relevant educational and professional experience requirements defined by PECB. Please consult PECB directly for current exam and certification details.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

How does this five-day Lead Risk Manager course differ from the three-day Risk Manager course?+

The five-day Lead Risk Manager course provides deeper coverage of risk assessment methodologies and is oriented towards professionals who need to lead and manage an organisation's entire information security risk management programme.

The three-day Risk Manager course covers the core ISO/IEC 27005 processes at a foundational level and is better suited to individuals who are newer to the subject or who need a concise introduction rather than lead-level mastery.

Which ISO standards are central to the content of this course?+

The course is built primarily around ISO/IEC 27005, which provides guidelines for information security risk management. It also draws on ISO 31000, the international standard for general risk management principles and guidelines, to contextualise the information security-specific requirements.

References to ISO/IEC 27001 appear where conformity and ISMS integration are discussed, giving participants a joined-up view of how risk management supports a broader information security management system.

What knowledge should I have before attending this course?+

PECB indicates that participants should have a fundamental understanding of ISO/IEC 27005 and comprehensive knowledge of risk management and information security before attending. While no formal prerequisite gate exists, arriving without this background knowledge is likely to make the content more challenging.

If you are relatively new to either topic, consider reviewing introductory ISO/IEC 27005 materials and general risk management frameworks beforehand, or explore whether the three-day Risk Manager course is a more appropriate starting point.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.