PECB ISO/IEC 27005 Foundation Training Course
Training course is focused on the information security risk management process introduced by ISO/IEC 27005 and the structure of the standard.
The course provides an overview of the guidelines of ISO/IEC 27005 for managing information security risks, including context establishment, risk assessment, risk treatment, communication and consultation, recording and reporting, and monitoring and review.
After attending the training course, you can enroll for the Foundation Exam and, if you successfully pass it, you can apply for a “PECB Certificate Holder in ISO/IEC 27005 Foundation” certificate.
Foundation Exam ( extra cost): Duration: 1 hour, Questions: 40, Where: Online
A PECB Foundation certificate shows that you have knowledge on the fundamental concepts, principles, methodologies, processes, and management approaches used in information security risk management.
This course is available as onsite live training in Croatia or online live training.Course Outline
Introduction to ISO/IEC 27005 and implementation of a risk management program
- Course objectives and structure
- Standard and regulatory framework
- Concepts and definitions of risk
- Risk management programme
- Context establishment
Risk assessment, risk treatment, and risk communication and consultation based on ISO/IEC 27005
- Risk identification
- Risk analysis
- Risk evaluation
- Risk assessment with a quantitative method
- Risk treatment
- Information security risk acceptance
Open Training Courses require 5+ participants.
PECB ISO/IEC 27005 Foundation Training Course - Booking
PECB ISO/IEC 27005 Foundation Training Course - Enquiry
Testimonials (1)
The fact that all the standard was reviewed and discussed with some examples, when needed and required.
Ioana
Course - ISO/IEC 27005 Information Security Risk Management
Upcoming Courses
Related Courses
PECB CISO
35 HoursBy attending the PECB CISO training course, you will gain the necessary expertise to oversee and manage information security, ensuring the implementation of robust security measures, the identification and mitigation of information security risks, and the development of effective security strategies tailored to the organization’s specific needs.
PECB DORA Lead Manager (Digital Operational Resilience Act)
35 HoursThe PECB Certified DORA Lead Manager training course equips you with the necessary skills to lead and oversee the implementation of digital operational resilience strategies within financial entities to help them ensure compliance with European Union’s Digital Operational Resilience Act (DORA)
PECB ISO 22301 Foundation
14 HoursThis training course is designed to help participants understand the fundamental concepts and principles of a business continuity management system (BCMS) based on ISO 22301. By attending this training course, participants will learn more about the structure and requirements of the standard including the BCMS policy, the top management’s commitment, internal audit, management review, and continual improvement process.
PECB ISO 22301 Lead Auditor
35 HoursIn response to the growing prevalence of disruptions and the unpredictable nature of various types of disasters, including those of natural, occupational, or information security nature, organizations are actively pursuing ISO 22301 certification. As more organizations seek compliance with ISO 22301, there is a corresponding demand for skilled auditors who possess the necessary skills and knowledge to assess and verify their compliance.
PECB ISO 22301 Lead Implementer
35 HoursDisasters have various impacts in organizations. Disasters can result from natural events, information security breaches, or various other incidents. They are often unpredictable and that highlights the significance of preparedness in setting your business apart and shaping its future. As such, proper planning is essential in reducing risks, minimizing consequences, and managing the negative impacts of disasters and incidents while ensuring the continuity of daily operations to meet customer needs without interruption.
PECB ISO/IEC 27001 Foundation
14 HoursWhy should you attend?
ISO/IEC 27001 Foundation training allows you to learn the basic elements to implement and manage an Information Security Management System as specified in ISO/IEC 27001. During this training course, you will be able to understand the different modules of ISMS, including ISMS policy, procedures, performance measurements, management commitment, internal audit, management review and continual improvement.
After completing this course, you can sit for the exam and apply for the “PECB Certified ISO/IEC 27001 Foundation” credential. A PECB Foundation Certificate shows that you have understood the fundamental methodologies, requirements, framework and management approach.
Who should attend?
- Individuals involved in Information Security Management
- Individuals seeking to gain knowledge about the main processes of Information Security Management Systems (ISMS)
- Individuals interested to pursue a career in Information Security Management
Educational approach
- Lecture sessions are illustrated with practical questions and examples
- Practical exercises include examples and discussions
- Practice tests are similar to the Certification Exam
PECB ISO/IEC 27001 Lead Auditor
35 HoursISO/IEC 27001 Lead Auditor
ISO/IEC 27001 Lead Auditor training enables you to develop the necessary expertise to perform an Information Security Management System (ISMS) audit by applying widely recognized audit principles, procedures and techniques.
Why should you attend?
During this training course, you will acquire the knowledge and skills to plan and carry out internal and external audits in compliance with ISO 19011 and ISO/IEC 17021-1 certification process.
Based on practical exercises, you will be able to master audit techniques and become competent to manage an audit program, audit team, communication with customers, and conflict resolution.
After acquiring the necessary expertise to perform this audit, you can sit for the exam and apply for a “PECB Certified ISO/IEC 27001 Lead Auditor” credential. By holding a PECB Lead Auditor Certificate, you will demonstrate that you have the capabilities and competencies to audit organizations based on best practices.
Who should attend?
- Auditors seeking to perform and lead Information Security Management System (ISMS) certification audits
- Managers or consultants seeking to master an Information Security Management System audit process
- Individuals responsible for maintaining conformance with Information Security Management System requirements
- Technical experts seeking to prepare for an Information Security Management System audit
- Expert advisors in Information Security Management
Learning objectives
- Understand the operations of an Information Security Management System based on ISO/IEC 27001
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002 and other standards and regulatory frameworks
- Understand an auditor’s role to: plan, lead and follow-up on a management system audit in accordance with ISO 19011
- Learn how to lead an audit and audit team
- Learn how to interpret the requirements of ISO/IEC 27001 in the context of an ISMS audit
- Acquire the competencies of an auditor to: plan an audit, lead an audit, draft reports, and follow-up on an audit in compliance with ISO 19011
Educational approach
- This training is based on both theory and best practices used in ISMS audits
- Lecture sessions are illustrated with examples based on case studies
- Practical exercises are based on a case study which includes role playing and discussions
- Practice tests are similar to the Certification Exam
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 are internationally recognized standards for quality and information security management systems, respectively.
This instructor-led, live training (online or onsite) is aimed at intermediate-level professionals who wish to interpret ISO 9001 and ISO 27001 standards and perform internal audits effectively.
By the end of this training, participants will be able to:
- Understand the principles and requirements of ISO 9001 and ISO 27001.
- Interpret the clauses and controls in real-world contexts.
- Plan and conduct internal audits aligned with ISO standards.
- Identify nonconformities and recommend corrective actions.
Format of the Course
- Interactive lecture and discussion.
- Simulated auditing exercises and case studies.
- Hands-on analysis of quality and security scenarios.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
PECB ISO/IEC 27001 Transition
14 HoursThe ISO/IEC 27001 Transition training course enables participants to thoroughly understand the differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022. In addition, participants will acquire knowledge on the new concepts presented by ISO/IEC 27001:2022.
ISO/IEC 27001 Lead Auditor (certification course)
35 HoursWho can attend?
- Auditors seeking to perform and lead information security management system (ISMS) audits
- Managers or consultants seeking to master the information security management system audit process
- Individuals responsible to maintain conformity with the ISMS requirements in an organization
- Technical experts seeking to prepare for the information security management system audit
- Expert advisors in information security management
Learning objectives
By the end of this training course, the participants will be able to:
- Explain the fundamental concepts and principles of an information security management system (ISMS) based on ISO/IEC 27001
- Interpret the ISO/IEC 27001 requirements for an ISMS from the perspective of an auditor
- Evaluate the ISMS conformity to ISO/IEC 27001 requirements, in accordance with the fundamental audit concepts and principles
- Plan, conduct, and close an ISO/IEC 27001 compliance audit, in accordance with ISO/IEC 17021-1 requirements, ISO 19011 guidelines, and other best practices of auditing
- Manage an ISO/IEC 27001 audit program
Educational approach
- This training is based on both theory and best practices used in ISMS audits
- Lecture sessions are illustrated with examples based on case studies
- Practical exercises are based on a case study which includes role playing and discussions
- Practice tests are similar to the Certification Exam
Problem Solving with Root Cause Analysis (RCA)
14 HoursThis instructor-led, live training in Croatia (online or onsite) is aimed at intermediate-level professionals who wish to develop a systematic approach to identifying, analyzing, and resolving problems using RCA methodologies.
By the end of this training, participants will be able to:
- Understand essential concepts of RCA and continuous improvement cycles.
- Apply different RCA tools to identify the root cause of problems.
- Develop and implement effective problem-solving strategies.
- Integrate RCA into organizational improvement and prevention efforts.
Root Cause Analysis (RCA) for Internal Auditors
14 HoursThis instructor-led, live training in Croatia (online or onsite) is aimed at intermediate-level internal auditors who wish to enhance their audit effectiveness by applying structured RCA techniques.
By the end of this training, participants will be able to:
- Understand RCA methodologies and their role in internal auditing.
- Identify and analyze the root causes of audit findings.
- Apply RCA tools such as the 5 Whys, Fishbone Diagram, and Failure Mode and Effects Analysis (FMEA).
- Develop corrective and preventive action plans based on RCA findings.
- Integrate RCA into the internal audit process to improve risk management.
Root Cause Analysis (RCA) with Operational Safety Focus
14 HoursThis instructor-led, live training (online or onsite) is aimed at intermediate-level safety professionals and operational managers who wish to enhance their ability to investigate incidents, identify systemic weaknesses, and design effective corrective and preventive actions.