What you'll learn:
- What is an ISMS (Information Security Management System)
- How to determine the risk appetite of an organization
- What is risk acceptance criteria and how it can be established
- The different approaches for information security risk identification
- The relationship between threats and vulnerabilities
- How to estimate likelihood and consequences for a risk
- How to calculate a risk level
- Why risks should be owned and who can be a risk owner
- The options for treating information security risks
- Key documents for an ISMS such as SoA and risk treatment plan
ISO/IEC 27005 is the international standard for information security risk management — the detailed guidance for the risk assessment and risk treatment process at the core of every ISO/IEC 27001 information security management system (ISMS). Where ISO/IEC 27001 requires organizations to assess and treat information security risks, ISO/IEC 27005 explains how.
This course walks you through that framework step by step, applicable to any organization regardless of size or sector.
Course structure
Foundations — information security management, the ISO/IEC 27000 series of standards, and an introduction to ISO/IEC 27005
Context establishment — defining the organization's risk appetite, setting risk acceptance criteria, and the difference between qualitative and quantitative approaches to defining consequences and likelihood
Risk assessment — the complete process: risk identification using the two approaches of ISO/IEC 27005 (the event-based approach and the asset-based approach), risk analysis, risk evaluation, and the role of risk owners
Risk treatment — the risk treatment options for information security risks, the controls of ISO/IEC 27001:2022, and the key ISMS documents that capture the results: the Statement of Applicability (SoA) and the risk treatment plan
Improvement and certification — continual improvement of the risk management process, plus the certification paths for organizations and individuals
What you will be able to do
By the end of the course you will understand the full information security risk management process — threat and vulnerability analysis, calculating risk levels, selecting risk treatment options — and you will be able to run a risk assessment, document its results in the SoA and risk treatment plan, and support a risk management program that protects the confidentiality, integrity and availability of your organization's information.
Who this course is for
ISMS implementers and information security officers responsible for the risk assessment of ISO/IEC 27001
Risk managers and GRC professionals specializing in information security and cyber risk
IT and cybersecurity professionals moving into risk-based roles
Auditors and consultants who evaluate risk assessments and risk treatment plans
Anyone preparing an organization for ISO/IEC 27001 certification — the risk assessment is where every ISMS begins
Enhance your expertise in information security risk management with the standard that defines how it's done.