Skip to content
AfriScience GroupAfriScienceGroup
Cybersecurity and IT

Information Security Risk Management to ISO/IEC 27005

This course covers information security risk management following the ISO/IEC 27005 approach, within the wider ISO/IEC 27001 management system. Delegates work through establishing context and risk criteria, asset and threat identification, vulnerability assessment, risk analysis and evaluation, and treatment selection against a control set. Practical emphasis is on producing a risk assessment that supports decisions rather than one that fills a folder, including the treatment of residual risk acceptance and the documentation an auditor will expect. Delegates carry an assessment through the full cycle on a realistic scope.

Course objectives

  • Establish context, scope and risk criteria for an assessment
  • Identify assets, threats and vulnerabilities systematically
  • Analyse and evaluate risk consistently against defined criteria
  • Select and justify risk treatment against a control set
  • Document residual risk and obtain informed acceptance
  • Produce documentation that satisfies an auditor
  • Maintain the assessment as the environment changes

Who should attend

  • Information security managers and officers
  • IT risk and compliance professionals
  • Internal auditors covering information security
  • Management system practitioners
  • Technology managers implementing ISO/IEC 27001

Course outline

  1. 01The risk management process within a management system
  2. 02Context, scope and risk criteria
  3. 03Asset identification and valuation
  4. 04Threat and vulnerability identification
  5. 05Risk analysis and evaluation
  6. 06Treatment selection and control justification
  7. 07Residual risk and informed acceptance
  8. 08Documentation, audit evidence and maintenance

Scheduled sessions

Scheduled sessions for Information Security Risk Management to ISO/IEC 27005
DatesVenueFormatPriceRegister
13 to 17 September 2026Johannesburg, South AfricaClassroomR11,995 per delegateRegister Now
1 to 5 October 2026Lusaka, ZambiaClassroomR11,995 per delegateRegister Now
7 to 11 October 2026Lagos, NigeriaClassroomR11,995 per delegateRegister Now
15 to 19 October 2026Kigali, RwandaClassroomR11,995 per delegateRegister Now
5 to 9 December 2026Lagos, NigeriaClassroomR11,995 per delegateRegister Now

Information Security Risk Management to ISO/IEC 27005

From R11,995

AskRegister