華睿教育
返回課程列表

資訊安全

ISO/IEC 27005 — Information Security Risk Management

可報讀程度

課程類型、時長及學費

課程類型適合對象企業得益時長學費
Foundation希望學習管理系統及其流程實施基礎的人士透過理解 ISO 標準的核心要素,為機構建立以最佳實務為本的取向與文化2 HKD 4,400
Lead Manager相關領域的管理人員,希望掌握最佳實務所訂明的指引帶領機構依循 ISO 標準指引,提升員工技能並改善效率3 HKD 9,600

About the standard

ISO/IEC 27005 provides a risk management framework for information security, giving organizations guidelines for identifying, analyzing, evaluating, treating, and monitoring information security risks. It supports the guidelines of ISO 31000 and is especially useful for organizations working to meet ISO/IEC 27001's risk management requirements. Applying an ISO/IEC 27005-based process involves an iterative risk assessment approach, risk treatment, ongoing stakeholder communication, and documentation of the whole process.

Levels available

  • Foundation — Introduces the core concepts of information security risk management and ISO/IEC 27005's framework.
  • Risk Manager — Builds practical skills to identify, analyze, evaluate, and treat information security risks within an organization.
  • Lead Risk Manager — For those responsible for leading an information security risk management process, developing advanced skills to align it with an ISMS and drive continual improvement.

Who should attend

This track suits information security officers, risk managers, and ISMS implementation team members responsible for managing information security risk. It's also relevant to consultants and auditors who assess how well an organization identifies and treats risk to its information assets.

Learning objectives

  • Understand the risk management concepts and principles set out in ISO/IEC 27005
  • Learn to manage information security risks based on recognized best practices
  • Gain the competence to establish an information security risk management process aligned with an ISMS
  • Understand how to integrate risk management into an organization's broader activities and functions
  • Learn to support the continual improvement of information security risk management and the ISMS

Why attend

Properly protecting information assets starts with a rigorous, repeatable way to identify and treat the risks that threaten them. This training builds the competence to establish a risk management process appropriate to an organization's context, gives professionals a competitive edge in the information security field, and demonstrates globally recognized expertise in managing information security risk.

PECB link

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005

PECB 官方頁面