ISO 27005 Risk Manager Course - english



Kursarrangør: Glasspaper AS
Sted: Oslo, Helsfyr
Oslo
Kursadresse: Brynsveien 12, 0667 Oslo (kart)
Type:Åpent kurs / gruppeundervisning
Studie / yrkesutdanning (21 studiepoeng)
Undervisningstid: kl 09:00 - 16:00
Varighet: 3 days
Pris: 20.900
Neste kurs: 07.09.2026 | Vis alle kursdatoer

We provide course about ISO 27005 Risk Manager in english. ISO/IEC 27005 Risk Manager is a comprehensive course designed to give participants an in-depth understanding of information security risk management based on the ISO/IEC 27005 standard.

Course description:
The programme focuses on analysing, evaluating and managing risks through structured frameworks and methodologies, enabling organisations to make informed decisions about risk exposure and treatment. This course provides participants with practical skills to conduct effective risk assessments, develop risk treatments and embed risk management practices into organisational processes.

Through a combination of theory, case studies and practical exercises, participants learn how to identify threats and vulnerabilities, assess risk impact, and design appropriate control strategies that align with business goals and compliance requirements. The course also prepares delegates for the ISO/IEC 27005 Risk Manager certification exam.

Course objectives:
Upon completion of this course, participants will be able to:
• Understand advanced risk concepts and requirements of ISO/IEC 27005
• Conduct structured risk identification and analysis
• Evaluate, prioritise and develop risk treatment plans
• Select and justify appropriate security controls to mitigate risk
• Integrate risk management processes with wider governance frameworks
• Prepare for and take the ISO/IEC 27005 Risk Manager certification exam

Course content:
Module 1 - Advanced risk management principles:
• Participants start with a deeper exploration of risk theory, including key definitions, principles and the role of structured risk management within information security frameworks.

Module 2 - Conducting risk identification and analysis:
• This section covers approaches for identifying and analysing risks, helping participants understand how to categorise and document threats, vulnerabilities, impacts and risk scenarios.

Module 3 - Risk evaluation and prioritisation:
• Participants learn methods for risk evaluation and prioritisation, including qualitative and quantitative techniques, risk scoring and how to interpret results to support decision-making.

Module 4 - Developing risk treatment plans:
• This part of the course focuses on creating risk treatment strategies, selecting appropriate controls, and designing implementation plans that align with organisational objectives and compliance needs.

Module 5 - Integrating risk processes within governance:
• Participants explore how to integrate risk management practices across organisational governance models, including alignment with standards like ISO/IEC 27001 and other management systems.

Module 6 - Monitoring and continual improvement:
• This section covers how to monitor risk environments, evaluate effectiveness of treatments and embed mechanisms for continual improvement in risk practices.

Module 7 - Preparation for exam:
• The course concludes with guidance on the certification exam, covering exam structure, key topic review and exam-taking strategies.

Target audience:
This course is suitable for risk professionals, information security practitioners, compliance officers, governance specialists, IT and security staff, consultants and anyone responsible for managing or coordinating risk activities within an organisation.

Prerequisites:
• Participants should have foundational knowledge of information security risk concepts, preferably through ISO/IEC 27005 Foundation or equivalent experience.

Language:
• English course material, english speaking instructor

Certification:
The exam is will take place at the end of the course on onsite classroom courses