ISO/IEC 27005
Run information security risk management that leadership can read and act on.
ISO/IEC 27005: what it is and why it matters
ISO/IEC 27005 gives guidance on managing information security risks, from establishing context through assessment, treatment, acceptance, communication and monitoring. It supports the risk requirements of ISO/IEC 27001 without prescribing one method.
The value of the subject is practical: a risk process that produces decisions, owners and treatment plans rather than a spreadsheet nobody reads.
Built for the people who carry the work
- Risk managers and information security officers
- ISMS implementers responsible for risk treatment
- Consultants running risk workshops
- Internal auditors reviewing risk processes
What you will be able to do
- Establish risk criteria, scope and context
- Identify assets, threats, vulnerabilities and consequences
- Estimate and evaluate risk with a repeatable method
- Choose treatment options and record residual risk and acceptance
- Communicate risk to management in business terms
- Monitor and review risk over time
Subject outline
- 01
Risk management process and its place in an ISMS
- 02
Context, criteria and scope
- 03
Risk identification: event-based and asset-based approaches
- 04
Risk analysis and evaluation
- 05
Risk treatment and residual risk
- 06
Communication, consultation, monitoring and review
- 07
Choosing and comparing risk methods
How it supports real work
Building a risk register tied to business services
Making treatment plans with named owners and dates
Showing an auditor how risk drove control selection
Training, examination and certification are different steps
ISO/IEC 27005 is guidance, so there is no organisational certificate for it. Personal credentials in risk management are offered by several bodies, each with its own prerequisites and exams.
- Attending training does not award a credential.
- Personal credentials depend on the issuing body and normally need an exam.
- We confirm the route and requirements with you before you enrol.
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Does ISO/IEC 27005 prescribe a single risk method?
No. It describes a process and allows several methods. EBIOS Risk Manager is one example of a method that can be used.
How does it relate to ISO 31000?
ISO 31000 is the general risk management guideline. ISO/IEC 27005 applies that thinking to information security.
Is it only for ISO/IEC 27001 projects?
No. Any organisation managing information risk can use it.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for ISO/IEC 27005.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


