HomeCoursesInformation Security › ISO/IEC 27005 Risk Manager
Information Security Risk Manager ES · FR · EN · DE · CS · UK

ISO/IEC 27005 Risk Manager

Build the skill to manage information security risk in line with ISO/IEC 27005. The methodology underpinning every ISMS and the foundation of the risk assessment required by ISO 27001, NIS2 and DORA.

3 daysof training
Risk Managerintermediate level
ES · FR · EN · DE · CS · UKlanguages
OfficialPECB exam incl.

Who is this course for?

  • Consultants and analysts who carry out security risk assessments
  • Security managers who need to justify their decisions on a risk basis
  • Auditors and compliance professionals (NIS2, DORA, ISO 27001)
  • Anyone who wants to master the risk assessment methodology underpinning every ISMS

What you'll gain

  • The PECB Certified ISO/IEC 27005 Risk Manager credential, recognised internationally
  • Command of the full risk management process: identify, analyse, evaluate and treat
  • The ability to apply the methodology in ISO 27001, NIS2 and DORA projects
  • The criteria to justify security decisions before management and auditors

Course programme

Day 1 · Fundamentals and framework of risk management
  • Information security risk concepts; ISO/IEC 27005 and ISO 31000
  • Establishing the context and risk criteria
  • Relationship with the ISO/IEC 27001 ISMS
Day 2 · Risk identification, analysis and evaluation
  • Identifying assets, threats and vulnerabilities
  • Risk analysis and estimation; qualitative and quantitative approaches
  • Risk evaluation and prioritisation
Day 3 · Treatment, acceptance and examination
  • Risk treatment options and the treatment plan
  • Risk acceptance, communication and monitoring
  • Review and official "PECB Certified ISO/IEC 27005 Risk Manager" exam

Exam, credits & certification

2 h
Duration of the official PECB exam
21 CPD
Continuing Professional Development credits granted by the course
Included
Exam, marking and first issue of the certification, included in the price

Once you pass the exam, you can apply for the "PECB Certified ISO/IEC 27005 Risk Manager" credential. The exam includes 2 attempts: the first plus a free retake, usable within the following 12 months. Passing first time is no longer a source of pressure. CPD credits correspond to the course level according to PECB. The exam duration is indicative; ask me for the exact details when you enrol.

Practise before the exam

Our own product

ISO/IEC 27005 Risk Manager practice exams, with a reasoned explanation for every answer.

6 full exams · 360 questions · 4 domains assessed

Try the free demo

RRSG's own material, independent from the official training and not endorsed by any certification body.

Your trainer

Ricardo Coronel Lemus, PECB trainer

Ricardo Coronel Lemus

Practising GRC / vCISO consultant · PECB Certified Trainer (CT6496)

More than 20 years in cybersecurity and compliance, today a vCISO and GRC consultant with real clients in France, Spain and Mexico. This is a standard I teach as a PECB Certified Trainer, and I don't approach it theoretically: I apply it day to day with real clients: that's what I bring to my coaching and exam preparation.

ISO 27001 Lead Auditor / Lead Implementer CISSPCISMCRISCCCISODORA Lead ManagerPCI DSS - PCIP
“Ricardo is skilled, thorough and self-reliant. He knows how to summarise or go deep into security issues depending on the audience: both governance questions and highly technical topics.”
Pierre-Luc M. · Cybersecurity Consulting Manager

Still in the evaluation phase?

Practical ISO 27005 guide (free). The risk management process step by step, with a 5x5 matrix and a filled risk register example.

Download the guide →
🧭 This course is part of the Risk Path: the complete itinerary towards your goal →

Not ready to decide? Get all the information by email

I will send you the full syllabus, available dates and the price of ISO/IEC 27005 Risk Manager, with no obligation.

Frequently asked questions

Do I need any prerequisites?
There are no formal prerequisites. Knowing the fundamentals of ISO 27001 helps, but it is not required.
What language is the exam in?
The official PECB material and exam for this course are available in the languages shown on this page. Coaching is delivered in English to prepare you thoroughly. If you need a specific language, contact us and we will confirm it.
What is the difference between Self-Study and Self-Study + Coaching?
Self-Study includes the official PECB material, the exam and certification, at your own pace. The coaching option adds one-to-one sessions with me, as a PECB Certified Trainer for this standard: real-world case studies and guided exam preparation; I support you until you feel ready to get certified.See the full coaching programme. The coaching option includes up to 5 hours of one-to-one video sessions, spread at your own pace over the 12 months of access. See the full coaching programme.
What if I don't pass the exam?
The PECB exam includes 2 attempts: the first plus a free retake usable within the following 12 months. So a failure doesn't leave you stranded. What's more, with the coaching option we prepare for the exam together with mock exams so that you arrive with confidence.
What is this certification for?
Risk assessment is at the heart of ISO 27001, NIS2 and DORA. Mastering ISO 27005 lets you carry out solid, defensible risk assessments: a skill in high demand in consulting and audit.

Ready to get certified in ISO 27005?

Choose your option above and enrol online. A question or need some advice? Write to me or book a call.