Skip to main content
ISO 31000

ISO 27005 Risk Manager

PECB-certified ISO 27005 Risk Manager training. Master information security risk assessment, treatment, and monitoring. Practical methodology with exam inclu...

PECBRisk Manager3 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants involved in or responsible for information security within their organisation
  • Individuals whose responsibilities include managing information security risks day to day
  • Members of information security teams, IT professionals, and privacy officers
  • Professionals responsible for maintaining conformity with ISO/IEC 27001 information security requirements
  • Project managers, consultants, and expert advisers seeking to build competence in information security risk management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Professionals who already manage complex, enterprise-wide risk programmes and are seeking lead-level or advanced mastery may find the five-day Lead Risk Manager course more appropriate
  • Individuals looking for deep coverage of multiple risk assessment methodologies rather than a focused introduction
  • Those whose primary need is network or application security governance rather than risk management frameworks
  • Learners seeking a purely technical cybersecurity skills course with no governance or standards component

What you'll be able to do

  • 1Explain risk management concepts and principles as outlined in ISO/IEC 27005 and ISO 31000
  • 2Establish, maintain, and improve an information security risk management framework following ISO/IEC 27005 guidelines
  • 3Apply the information security risk management processes defined by ISO/IEC 27005 within an organisational context
  • 4Plan and set up effective risk communication and consultation activities with relevant stakeholders
  • 5Record and report risk management activities in a structured and audit-ready manner
  • 6Monitor and review the risk management process to ensure ongoing relevance and effectiveness
  • 7Identify and apply recognised risk assessment methodologies appropriate to the organisational context

Day by day

Day 1Introduction to ISO/IEC 27005 and risk management
  • Scope and structure of ISO/IEC 27005

    This module introduces the purpose, scope, and key terms of ISO/IEC 27005 and explains how it relates to ISO 31000 and information security governance.

  • Core risk management principles

    Participants explore the foundational principles that underpin effective information security risk management and how they translate into organisational practice.

  • Establishing the risk management framework

    This module examines the components needed to set up an information security risk management framework, including scope definition, objectives, and organisational context.

By end of day

  • Describe the purpose and structure of ISO/IEC 27005 and its relationship with ISO 31000
  • Articulate core risk management principles and link them to information security objectives
  • Identify the key components required to establish a risk management framework
Day 2Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005
  • Risk identification and analysis

    This module covers how to identify information assets, threats, and vulnerabilities and analyse their potential impact using techniques aligned with ISO/IEC 27005.

  • Risk evaluation and treatment

    Participants learn how to evaluate identified risks against defined criteria and select appropriate treatment options, including risk modification, avoidance, sharing, and retention.

  • Risk communication and consultation

    This module addresses how to plan and carry out stakeholder communication and consultation activities that support informed risk decision-making throughout the process.

By end of day

  • Conduct risk identification, analysis, and evaluation steps using ISO/IEC 27005 guidance
  • Select and justify risk treatment options appropriate to the organisation's risk appetite
  • Plan a risk communication and consultation approach for key stakeholder groups
Day 3Risk recording and reporting, monitoring and review, and risk assessment methods
  • Recording and reporting risk management activities

    This module explores documentation and reporting obligations within the ISO/IEC 27005 framework, focusing on how to produce clear and traceable risk records.

  • Monitoring and review

    Participants examine how to monitor risk status and the effectiveness of controls, and how to trigger timely reviews of the risk management process and framework.

  • Overview of risk assessment methodologies

    This module surveys recognised information security risk assessment methods, comparing their features to help participants choose the most suitable approach for their context.

By end of day

  • Produce risk records and reports that support transparency and organisational accountability
  • Design a monitoring and review cycle that keeps risk information current and actionable
  • Compare risk assessment methodologies and select one appropriate to the organisational situation

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security risk management
  • Domain 2: Implementation of an information security risk management program
  • Domain 3: Information security risk management framework and processes based on ISO/IEC 27005:2022
  • Domain 4: Other information security risk assessment methods

To be considered valid, these information security activities should follow best implementation and management practices and include the following:

  1. Defining a risk management approach
  2. Determining the risk management objectives and scope
  3. Conducting a risk assessment
  4. Developing a risk management program
  5. Defining risk evaluation and risk acceptance criteria
  6. Evaluating risk treatment options
  7. Monitoring and reviewing the risk management program

Certification Rules and Policies

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 350 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 21 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational approach

  • The training course is based on the theory and the best practices of information security.
  • The training course provides practical examples and scenarios.
  • Participants are encouraged to actively participate and engage in discussions and exercises and quizzes.
  • Quizzes are similar in structure with the certification exam.

Buyers always ask

Does completing this training course mean I am certified as an ISO/IEC 27005 Risk Manager?+

Completing the three-day training course with Cyber Academy confirms your participation in the programme. It does not constitute PECB certification.

To obtain a PECB credential, you would need to separately sit and pass the relevant PECB certification exam and meet the professional experience requirements defined by PECB. Please visit PECB's official website for current details on the certification process.

Is there any formal entry requirement for this course?+

PECB does not state a formal prerequisite for the ISO/IEC 27005 Risk Manager training. The course is therefore accessible to a broad range of professionals, including those relatively new to information security risk management.

That said, having some familiarity with information security concepts and general risk terminology will help you engage more fully with the course content from the first day.

How does this three-day course compare to the five-day Lead Risk Manager course?+

This three-day course covers the core ISO/IEC 27005 risk management processes and is suited to professionals who need a solid working knowledge of information security risk management without necessarily leading an organisation-wide programme.

The five-day Lead Risk Manager course goes further, adding greater depth on risk assessment methodologies and leadership of the overall risk management programme. Professionals who expect to design, govern, or continually improve an organisation's risk management framework at a senior level may find the five-day course a better fit.

Which risk assessment methodologies are covered in this course?+

The course introduces a range of recognised information security risk assessment methodologies on Day 3, providing an overview of their features and applicability rather than exhaustive technical instruction in each.

The goal is to equip participants to compare methodologies and select one that suits their organisational context, in alignment with the broader ISO/IEC 27005 risk management process.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.