• Online, Instructor-Led
Course Description

ISO/IEC 27005 Foundation Training provides a comprehensive introduction to the principles and practices of risk management in the context of information security, as outlined in the ISO/IEC 27005 standard. This course is designed to help professionals understand the methodologies for identifying, assessing, and managing information security risks.

Participants will learn about the risk management process, including risk identification, risk assessment, risk treatment, and risk monitoring, as well as how these processes integrate with an Information Security Management System (ISMS). The training covers key concepts such as risk analysis, evaluation, and the implementation of appropriate controls to mitigate risks.

Ideal for those new to ISO/IEC 27005 or seeking to understand its application within an ISMS, this course lays the groundwork for effective risk management practices and supports the development of a robust information security strategy.

Learning Objectives

After taking this course, you will be able to:

  • Describe the key terms, concepts, and terminology related to risk management.
  • Interpreting ISO/IEC 27005 recommendations for handling information security concerns
  • Establish the strategies, tactics, and procedures used to create and manage an information security risk management program.

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):