Who is this course for?
Information Security Risk Manager
Build defensible information security risk assessments
ISMS Risk Analyst
Bring ISO 27005 rigor to your ISMS
Security Risk Consultant
Deliver 27005-aligned risk methodologies to clients
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.
Information Security Risk Manager
Build defensible information security risk assessments
ISMS Risk Analyst
Bring ISO 27005 rigor to your ISMS
Security Risk Consultant
Deliver 27005-aligned risk methodologies to clients
Upcoming dates you can join soon.
Can't attend these dates? Self-study is available year-round.
This course runs multiple times per year, onsite and online.
Learn at your own pace. Flexible access, trainer support.
No date works for you?
Request a private or flexible session
Train with practitioners. Pass with confidence.
Abilene Academy is the only PECB Titanium Partner in Switzerland — the highest accreditation tier in the industry — delivering certified training in information security, data protection, AI governance, and GRC compliance. 99% exam pass rate. 2,500+ professionals trained across 120+ countries and trusted by 600+ organizations. Multilingual programmes available.
Operational information security risk management under ISO 27005
This ISO 27005 Risk Manager course is available eLearning and can be started at any time. Available in EN/FR/ES/DE. Learn at your own pace with no fixed schedule.
Information security risk management has become a board level concern. In the 2024–2025 regulatory landscape, organizations are expected not only to identify risks but to demonstrate how those risks are evaluated, treated, monitored, and communicated. ISO/IEC 27005:2022 provides the reference framework, yet many organizations struggle to apply it consistently and pragmatically.
This training focuses on how risk management actually works inside organizations. Participants do not simply study the standard. They practice building a risk management framework that aligns with ISO/IEC 27001, supports certification audits, and produces decisions that management can accept or challenge with confidence.
Throughout the course, participants work with a realistic case study reflecting common operational constraints such as incomplete data, competing business priorities, and regulatory pressure. They define context, identify and analyze risks, evaluate acceptability, and select treatment options that are proportionate and documented. Particular attention is given to risk communication, ensuring that technical findings can be understood by non technical stakeholders.
Abilene Academy’s approach reflects consulting reality. Trainers are active practitioners who regularly design and review risk management processes for regulated organizations. The course also positions ISO 27005 in relation to other widely used methods such as EBIOS, OCTAVE, MEHARI, NIST, CRAMM, and harmonized threat and risk analysis, explaining when and why each is used.
Participants leave with a structured, repeatable approach that can be applied immediately within their organization or client environments.
ISO 22301 Lead Implementer · ISO 22301 Lead Auditor · ISO 27001 Lead Implementer · ISO 27005 Risk Manager · EBIOS Risk Manager
Expert in Business Continuity, Risk Management and Information Security Governance Consulting for large multinational corporations, government organization and internal organizations Certified international trainer and Lecturer at Sorbonne University Paris 1
PECB ISO 27001 Senior Lead Auditor · ISO 27001 Lead Implementer · CISM® Exam Bootcamp · ISO 27005 Risk Manager · CISA® Exam Bootcamp
Passionate Information Security and Business Continuity trainer with hands-on experience auditing, designing and implementing management systems. His journey spans finance, cloud services, software engineering, public sector, NGOs and beyond, so he understands your challenges.
Contact us for pricing
3 days
Exam Included · Certification Available