Introduction to ISO 27005 — Essentials of Information Security Risk Management
Learn to run the information security risk management process end to end under ISO/IEC 27005:2022 — from context and risk criteria through identification, analysis and treatment to a defensible Statement of Applicability and risk treatment plan.
23
Lessons
~10h
Study time
30
Exam questions
Earns a QR-verifiable Certificate of Training
Overview
About this course
ISO/IEC 27005:2022 is the guidance standard that tells you how to do what ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3 merely require: define risk criteria, assess information security risk repeatably, choose treatment options, determine the controls that are necessary, compare them with Annex A, produce a Statement of Applicability, and obtain risk owner approval of the risk treatment plan and acceptance of residual risk. This foundation course works through that process clause by clause, in the order a practitioner meets it.
The programme covers the relationship between ISO 31000, ISO/IEC 27005 and ISO/IEC 27001; context establishment and the two families of risk criteria; both routes to risk identification — the asset-based route through assets, threats and vulnerabilities, and the event-based route through risk sources and strategic scenarios — and how to judge which suits your organisation; consequence and likelihood assessment; qualitative, semi-quantitative and quantitative analysis with worked scoring; evaluation and prioritisation; the four treatment options and control selection against ISO/IEC 27002; and the documented information an auditor will ask to see. It closes with a practical first-ninety-days path and the pitfalls that most often derail a first risk assessment cycle.
It is written for information security officers, IT and GRC staff, risk and asset owners, ISMS implementers and consultants supporting certification. It is not an auditor course: audit technique, penetration testing and tool selection are deliberately out of scope.
Assessment is a 30-question online exam with a 70% pass mark. Successful learners receive a verifiable SKEDMIA certificate. Approximately 10 hours of self-paced study.
What you earn
A certificate anyone can verify in seconds
Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.
Verified at skedmia.com/verify
Syllabus
Course content
8 modules · 23 lessons · ~10h
01Module 1 — ISO/IEC 27005 in Context — What the Standard Is and Who It Serves3 lessons
- What ISO/IEC 27005 Is — Purpose, Scope and LineagePreview25 min
- Where 27005 Sits — ISO 31000, ISO/IEC 27001 Clauses 6.1.2 and 6.1.3, and the Wider 27000 Family30 min
- The Language and Shape of the Process — Terms, Clause Structure and Risk Management Cycles25 min
02Module 2 — Establishing Context — Organisation, Scope and Risk Criteria3 lessons
- Organisational Considerations, Interested Parties and the ISMS Boundary25 min
- Risk Criteria — Acceptance Criteria and Criteria for Performing Risk Assessment30 min
- Choosing an Appropriate Method — Applying Risk Assessment and Selecting the Approach25 min
03Module 3 — Risk Identification — The Event-Based and Asset-Based Routes3 lessons
- What Identification Must Produce — Risk Descriptions and Risk Owners25 min
- The Asset-Based Approach — Assets, Threats, Vulnerabilities and Existing Controls30 min
- The Event-Based Approach — Risk Sources, Strategic Scenarios and Choosing Between Routes30 min
04Module 4 — Risk Analysis — Consequence, Likelihood and Determining Levels of Risk3 lessons
- Assessing Potential Consequences25 min
- Assessing Likelihood25 min
- Determining the Level of Risk — Qualitative, Semi-Quantitative and Quantitative Techniques35 min
05Module 5 — Evaluation and Treatment — From Prioritised Risks to Selected Controls3 lessons
- Risk Evaluation — Comparing Results with Criteria and Prioritising for Treatment25 min
- The Treatment Options — Modify, Retain, Avoid, Share30 min
- Determining Necessary Controls and Comparing Them with Annex A30 min
06Module 6 — Documenting and Sustaining Risk Management — SoA, Treatment Plan, Acceptance and Review3 lessons
- Producing the Statement of Applicability30 min
- The Risk Treatment Plan, Risk Owner Approval and Acceptance of Residual Risk30 min
- Operating the Process — Communication, Monitoring, Review and Documented Information30 min
07Module 7 — Putting It Into Practice — First Cycle, Common Pitfalls and the First 90 Days3 lessons
- Designing and Running the First Cycle30 min
- Common Pitfalls and How to Correct Them25 min
- A First 90-Day Path and the Evidence Pack30 min
08Course materials & downloads2 lessons
- Asset-Based vs Event-Based Risk Identification — Decision and Comparison Chart (PDF)
- Risk Register, Risk Treatment Plan and Statement of Applicability Template Pack (PDF)
Keep browsing
More it, security & ai training

ISO 27001 (The International Information Security Standard)
ISO 27001 Lead Auditor Training

ISO 27001 (The International Information Security Standard)
ISO 27001 2013 VS 27001 2022

IT Courses
