ISO/IEC 27005 Lead Risk Manager
I. Overview:
The ISO/IEC 27005 Lead Risk Manager training course enables participants to acquire the necessary competencies to assist organizations in establishing, managing, and improving an information security risk management (ISRM) program based on the guidelines of ISO/IEC 27005.
Apart from introducing the activities required for establishing an information security risk management program, the training course also elaborates on the best methods and practices related to information security risk management.
II. Duration: 05 days (40 hours)
III. Objectives:
By successfully completing this training course, you will be able to:
- Explain the risk management concepts and principles based on ISO/IEC 27005 and ISO 31000
- Establish, maintain, and continually improve an information security risk management framework based on the guidelines of ISO/IEC 27005 and best practices
- Apply information security risk management processes based on the guidelines of ISO/IEC 27005
- Plan and establish risk communication and consultation activities
- Record, report, monitor, and review the information security risk management process and framework
IV. Intended Audience:
This training course is intended for:
- Managers or consultants involved in or responsible for information security in an organization
- Individuals responsible for managing information security risks, such as ISMS professionals and risk owners
- Members of information security teams, IT professionals, and privacy officers
- Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
- Project managers, consultants, or expert advisers seeking to master the management of information security risks
V. Prerequisites:
- The main requirements for participating in this training course are having a fundamental understanding of ISO/IEC 27005 and comprehensive knowledge of risk management and information security.
VI. Course outlines:
- Day 1: Introduction to ISO/IEC 27005 and information security risk management
- Day 2: Risk identification, analysis, evaluation, and treatment based on ISO/IEC 27005
- Day 3: Information security risk communication and consultation, recording and reporting, and monitoring and review
- Day 4: Risk assessment methods
- Day 5: Certification exam
Học trực tuyến
Học tại Hồ Chí Minh
Học tại Hà Nội



