資訊安全
ISO/IEC 27005 — Information Security Risk Management
課程類型、時長及學費
| 課程類型 | 適合對象 | 企業得益 | 時長 | 學費 |
|---|---|---|---|---|
| Foundation | 希望學習管理系統及其流程實施基礎的人士 | 透過理解 ISO 標準的核心要素,為機構建立以最佳實務為本的取向與文化 | 2 天 | HKD 4,400 |
| Lead Manager | 相關領域的管理人員,希望掌握最佳實務所訂明的指引 | 帶領機構依循 ISO 標準指引,提升員工技能並改善效率 | 3 天 | HKD 9,600 |
About the standard
ISO/IEC 27005 provides a risk management framework for information security, giving organizations guidelines for identifying, analyzing, evaluating, treating, and monitoring information security risks. It supports the guidelines of ISO 31000 and is especially useful for organizations working to meet ISO/IEC 27001's risk management requirements. Applying an ISO/IEC 27005-based process involves an iterative risk assessment approach, risk treatment, ongoing stakeholder communication, and documentation of the whole process.
Levels available
- Foundation — Introduces the core concepts of information security risk management and ISO/IEC 27005's framework.
- Risk Manager — Builds practical skills to identify, analyze, evaluate, and treat information security risks within an organization.
- Lead Risk Manager — For those responsible for leading an information security risk management process, developing advanced skills to align it with an ISMS and drive continual improvement.
Who should attend
This track suits information security officers, risk managers, and ISMS implementation team members responsible for managing information security risk. It's also relevant to consultants and auditors who assess how well an organization identifies and treats risk to its information assets.
Learning objectives
- Understand the risk management concepts and principles set out in ISO/IEC 27005
- Learn to manage information security risks based on recognized best practices
- Gain the competence to establish an information security risk management process aligned with an ISMS
- Understand how to integrate risk management into an organization's broader activities and functions
- Learn to support the continual improvement of information security risk management and the ISMS
Why attend
Properly protecting information assets starts with a rigorous, repeatable way to identify and treat the risks that threaten them. This training builds the competence to establish a risk management process appropriate to an organization's context, gives professionals a competitive edge in the information security field, and demonstrates globally recognized expertise in managing information security risk.
PECB link
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005
