Develop the expertise to identify, assess, treat, and manage information security risks using the ISO/IEC 27005:2022 framework.
This course equips professionals with the practical knowledge to establish a structured Information Security Risk Management (ISRM) programme, perform comprehensive risk assessments, select appropriate treatment strategies, and continually improve risk management practices aligned with ISO/IEC 27005 and ISO 31000 guidelines.
- Why get trained: Learn how to establish an information security risk management programme, perform risk assessments, evaluate treatment options, communicate risk effectively, apply internationally recognized risk methodologies, and align risk management activities with ISO/IEC 27001 and organizational security objectives.
- Why it matters: Professionals who can systematically identify, evaluate, and mitigate information security risks enable stronger governance, improve organizational resilience, and support informed business decision-making.
- Who should attend: Information Security Managers, Risk Managers, ISMS Professionals, Governance, Risk and Compliance (GRC) Professionals, Information Security Consultants, IT Managers, and professionals responsible for maintaining ISO/IEC 27001 compliance or managing enterprise information security risks.
Build the practical expertise to establish, manage, and continually improve information security risk management across your organization. HRD Corp Claimable.
Bumiputera Malaysians: Level up your skills and stand out with a globally recognized PECB ISO/IEC 27005:2022 cybersecurity certification with Yayasan Peneraju Financing Scheme.

Overview
ISO/IEC 27005 Lead Risk Manager
The ISO/IEC 27005 Lead Risk Manager training course enables participants to acquire the necessary competencies to assist organizations in establishing, managing, and improving an information security risk management (ISRM) program based on the guidelines of ISO/IEC 27005.
Apart from introducing the activities required for establishing an information security risk management program, the training course also elaborates on the best methods and practices related to information security risk management.
Cybersecurity is not optional. It’s Operational. Don’t wait for a breach. Build the skills. Earn the badge. Lead the defense. Be the reason your organization survives the next cyberattack:
Skills Covered
ISO/IEC 27005 Lead Risk Manager
The ISO/IEC 27005 Lead Risk Manager training course enables participants to acquire the necessary competencies to assist organizations in establishing, managing, and improving an information security risk management (ISRM) program based on the guidelines of ISO/IEC 27005.
Apart from introducing the activities required for establishing an information security risk management program, the training course also elaborates on the best methods and practices related to information security risk management.
Cybersecurity is not optional. It’s Operational. Don’t wait for a breach. Build the skills. Earn the badge. Lead the defense. Be the reason your organization survives the next cyberattack:
Prerequisites
The main requirements for participating in this training course are having a fundamental understanding of ISO/IEC 27005 and comprehensive knowledge of risk management and information security.
Target Audience
This training course is intended for:
- Managers or consultants involved in or responsible for information security in an organization
- Individuals responsible for managing information security risks, such as ISMS professionals and risk owners
- Members of information security teams, IT professionals, and privacy officers
- Individuals responsible for maintaining conformity with the information security requirements of ISO/IEC 27001 in an organization
- Project managers, consultants, or expert advisers seeking to master the management of information security risks

Day 1: Introduction to ISO/IEC 27005:2022, Concepts and Implementation of a Risk Management Program
- Course objectives and structure
- Standard and regulatory framework
- Concepts and definitions of risk
- Implementing a risk management programme
- Context establishment
Day 2: Risk Identification, Evaluation, and Treatment as Specified in ISO/IEC 27005:2022
- Risk identification
- Risk analysis
- Risk evaluation
- Risk assessment with a quantitative method
- Risk treatment
Day 3: Information Security Risk Acceptance, Communication, Consultation, Monitoring, and Review
- Information security risk acceptance
- Information security risk communication and consultation
- Information security risk monitoring and review
Day 4: Risk Assessment Methodologies
- OCTAVE method
- MEHARI method
- EBIOS method
- Harmonized Threat and Risk Assessment (TRA) method
- Applying for certification and closing the training
Day 5: Certification Exam
- Certification exam
Dates & Locations
August 3, 2026 - August 7, 2026
August 3, 2026 - August 7, 2026
November 16, 2026 - November 20, 2026
November 16, 2026 - November 20, 2026

Exam & Certification
The “PECB Certified ISO/IEC 27005 Lead Risk Manager” exam meets all the requirements of the PECB Examination and Certification Program (ECP). It covers the following competency domains:
- Domain 1: Fundamental principles and concepts of information security risk management
- Domain 2: Implementation of an information security risk management program
- Domain 3: Information security risk assessment
- Domain 4: Information security risk treatment
- Domain 5: Information security risk communication, monitoring, and improvement
- Domain 6: Information security risk assessment methodologies
For specific information about exam type, languages available, and other details, please visit the List of PECB Exams and the Examination Rules and Policies.
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631
























