ISO 27005 Risk Manager Course

ISO/IEC 27005 Risk Manager is a comprehensive course designed to give participants an in-depth understanding of information security risk management based on the ISO/IEC 27005 standard. The programme focuses on analysing, evaluating and managing risks through structured frameworks and methodologies, enabling organisations to make informed decisions about risk exposure and treatment.

«The trainer was the main reason I learned something valuable; made the class entertaining and fronted good discussions.» Course delegate

This course provides participants with practical skills to conduct effective risk assessments, develop risk treatments and embed risk management practices into organisational processes. Through a combination of theory, case studies and practical exercises, participants learn how to identify threats and vulnerabilities, assess risk impact, and design appropriate control strategies that align with business goals and compliance requirements. The course also prepares delegates for the ISO/IEC 27005 Risk Manager certification exam.

Course objectives

Upon completion of this course, participants will be able to:

  • Understand advanced risk concepts and requirements of ISO/IEC 27005
  • Conduct structured risk identification and analysis
  • Evaluate, prioritise and develop risk treatment plans
  • Select and justify appropriate security controls to mitigate risk
  • Integrate risk management processes with wider governance frameworks
  • Prepare for and take the ISO/IEC 27005 Risk Manager certification exam

Prerequisites

Participants should have foundational knowledge of information security risk concepts, preferably through ISO/IEC 27005 Foundation or equivalent experience.

Target audience

This course is suitable for risk professionals, information security practitioners, compliance officers, governance specialists, IT and security staff, consultants and anyone responsible for managing or coordinating risk activities within an organisation.

Advanced risk management principles

Participants start with a deeper exploration of risk theory, including key definitions, principles and the role of structured risk management within information security frameworks.

Conducting risk identification and analysis

This section covers approaches for identifying and analysing risks, helping participants understand how to categorise and document threats, vulnerabilities, impacts and risk scenarios.

Risk evaluation and prioritisation

Participants learn methods for risk evaluation and prioritisation, including qualitative and quantitative techniques, risk scoring and how to interpret results to support decision-making.

Developing risk treatment plans

This part of the course focuses on creating risk treatment strategies, selecting appropriate controls, and designing implementation plans that align with organisational objectives and compliance needs.

Integrating risk processes within governance

Participants explore how to integrate risk management practices across organisational governance models, including alignment with standards like ISO/IEC 27001 and other management systems.

Monitoring and continual improvement

This section covers how to monitor risk environments, evaluate effectiveness of treatments and embed mechanisms for continual improvement in risk practices.

Preparation for exam

The course concludes with guidance on the certification exam, covering exam structure, key topic review and exam-taking strategies.

After successfully completing the exam, you can apply for the credentials shown on the table below. You will receive a certificate once you comply with all the requirements related to the selected credential. For more information about ISO/IEC 27001 certifications and the PECB certification process, please refer to the Certification Rules and Policies.

27005 RM.png

Exam

The exam is will take place at the end of the course on onsite classroom courses

For Virtual courses we will send out a voucher that gives you access to an online exam. This can be booked and taken home monitored by a proctor via camera. More information about the exam rules will be send from PECB

  • Duration: 2 hour (+ 20 min extra time for non-native)

The exams an Multiple Choice exam; candidates are only authorized to use the following reference materials:

  • A copy of the standard (candidates need to bring their own copy of the standard).
  • Course notes from the Participant Handout. (If applicable)
  • Any personal notes made by the student during the course. (If applicable)
  • A hard copy dictionary

Examination rules and policies

Practical information

Duration: 3 days
Price: 20 900
Language: English
Format: Open course and corporate training

FAQ

Hva lærer jeg på dette kurset?
Du lærer avanserte metoder for risikostyring i tråd med ISO/IEC 27005, inkludert identifikasjon, analyse, evaluering, behandling og kontrollvalg for risiko.

Hva kreves for å delta?
Det anbefales at du har grunnleggende kunnskap om informasjonssikkerhet og risikostyring, fortrinnsvis gjennom ISO/IEC 27005 Foundation eller relevant erfaring.

Hvordan gjennomføres eksamen?
Eksamen gjennomføres enten fysisk på kursstedet eller online med voucher og online eksamensvakt.

Hva skjer hvis jeg ikke består første eksamen?
Du får som regel ett nytt eksamensforsøk som tas online.

Får jeg ekstra tid på eksamen?
Ja, ekstra tid gis dersom engelsk ikke er ditt morsmål, i tråd med sertifiseringsreglene.

Hvilken sertifisering får jeg?
Etter godkjent eksamen oppnår du PECB Certified ISO/IEC 27005 Provisional Risk Manager sertifiseringen. For å få full sertifisering kan det også stilles krav til dokumentert arbeidserfaring innen informasjonssikkerhet og ISRM-arbeid. Sjekk tabellen under sertifisering for mer informasjon.

Får jeg ISO-standarden?
Nei, du får tilgang til kursmateriell og rammeverksreferanser som brukes under kurset og eksamen.

Hva er forskjellen på Risk Manager og Foundation?
Risk Manager fokuserer på avanserte risikoaktiviteter som analyse, evaluering og behandling, mens Foundation gir grunnleggende risikokonsepter.

Er dette kurset relevant for ledere?
Ja, kurset er relevant for ledere, risikokoordinatorer og fagpersoner som jobber med risikostyring og governance.

Kan jeg ta dette kurset som e-læring eller selvstudium?
Ja, dette kurset tilbys også som e-læring. Påmelding kan registreres på høyre side.

Andre relevante kurs

23. mars
2 dager
Classroom Virtual
1 dager
Classroom
13. april
5 dager
Classroom Virtual
2. mars
5 dager
Classroom Virtual Startgaranti