Risk Management in ISMS according to ISO/IEC 27005 (ISMS4)

Cybersecurity, ISMS and GDPR

Risk is the central concept of an information security management system, and risk management is a core organizational process. This course explains ISO/IEC 27005 as a practical guide for identifying and assessing risks in an ISMS aligned with ISO/IEC 27001.

Knowing the standard alone is not enough for effective risk management in real organisations. The training adds practical guidance, proven methods and insights from other frameworks and standards to help you treat, monitor and communicate security risks.

THIS TRAINING COURSE WILL HELP YOU:

  • Understand ISO/IEC 27005 and its role in ISMS
  • Identify and assess information security risks
  • Select and implement suitable risk treatments
  • Integrate risk activities with ISO/IEC 27001 processes

WHO SHOULD ATTEND?

  • ISMS or information security managers
  • IT risk managers and security analysts
  • Internal auditors and compliance staff
  • IT managers responsible for security

COURSE LOCATION AND AVAILABLE DATES



Choose whether to attend in person in our classroom or join online. You can select your preferred format during registration. Learn more about hybrid training.

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • Day 1: Context and objectives of ISMS, core terminology, overview of the ISO/IEC 27000 family - analysis of risk factors and drivers
  • Day 2: Risk assessment methods and risk treatment options - communication, monitoring and continual improvement
  • Note: Daily content is not fixed and will be adapted flexibly to participants' needs.
Prerequisites:
Basic knowledge of organizational processes and elementary IT security awareness.
Schedule:
2 days (9:00-17:00)
Price per person:
516.00 € ( 624.36 € incl. 21% VAT)

Training and learning environment