Skip to content
Team Favour
ManagerRisk ManagementHigh demand

PECB Certified ISO/IEC 27005 Lead Risk Manager

Five days building the practitioner capability to establish, run and continually improve information security risk management as a managed programme.

5 days 31 CPD credits 3h exam English Certified by PECB

Total price, all inclusive

$1,495per seat

Exam, one retake and first-year certification included.

Choose your format
  • Official PECB participant materials and case studies
  • 3-hour PECB certification exam voucher included
  • One free exam retake if you do not pass first time
  • First-year certification application fee covered
  • 31 CPD credits on completion

No payment is taken online. We confirm your seat and dates by email, then invoice. Questions?

About this course

ISO/IEC 27005 provides the guidelines for information security risk management that ISO/IEC 27001 assumes but does not spell out. It is the course that turns a risk register from a spreadsheet of guesses into a defensible, repeatable process.

This is the official PECB Manager scheme for ISO/IEC 27005, delivered over 5 days and worth 31 CPD credits. On completion and after passing the examination you are awarded the PECB Certified ISO/IEC 27005 Lead Risk Manager credential.

Why this certification is worth holding

  • Fixes the weakest part of most ISMS implementations: the risk assessment
  • Directly examinable evidence of risk competence for auditors and regulators
  • Pairs with ISO 31000 for enterprise-wide risk alignment

What you will be able to do

  • 01Master the concepts and frameworks underpinning information security risk management
  • 02Establish, maintain and improve a information security risk management programme
  • 03Lead the risk identification, analysis and treatment decisions the discipline demands
  • 04Advise leadership using evidence, metrics and defensible judgement
  • 05Prepare the programme for assessment against recognised good practice

Day-by-day agenda

5 days of instruction and case-study work, following the official PECB curriculum.

  1. 1

    Introduction to information security risk management and ISO/IEC 27005

    • Training objectives and the certification path
    • Core concepts, terminology and the ISO/IEC 27005 framework
    • Governance, mandate and organisational context
    • Roles, responsibilities and programme structure
  2. 2

    Designing the programme

    • Planning: risk criteria, risk identification and analysis approach
    • Qualitative and quantitative risk analysis techniques, and scenario-based assessment
    • Objectives, appetite and decision criteria
    • Policy, procedure and documented information architecture
  3. 3

    Running the programme

    • Designing and deploying risk treatment options and controls
    • Operation: risk treatment, acceptance and residual risk communication
    • Risk monitoring, review and reassessment after change or incident
    • Awareness, competence and stakeholder communication
  4. 4

    Measurement, assurance and improvement

    • Monitoring, measurement and programme metrics
    • Assurance activities, internal audit and independent review
    • Reporting to leadership and demonstrating value
    • Continual improvement and closing the training
  5. 5

    Certification exam

    • Exam-technique clinic: how the essay-type domains are marked
    • Timed mock questions with model answers walked through
    • Sitting the official PECB examination (online-proctored or paper)
    • Submitting the certification application and evidencing experience

Exam and certification

Exam duration

3 hours

Exam format

Essay-type · open book

Delivery

Online-proctored or paper-based

CPD credits

31 credits

To be awarded PECB Certified ISO/IEC 27005 Lead Risk Manager

  • Pass the PECB examination for the scheme
  • Five years of professional experience, two of them in the relevant field
  • 300 hours of related project activities
  • Sign the PECB Code of Ethics

If you do not pass first time

One retake is included at no extra cost, and PECB does not require you to repeat the training. We run a focused review session with you first to work out where the marks went, then rebook the sitting.

Exam duration and format follow PECB’s published examination rules, which we confirm with you before you sit.

Who it is for

Built for

  • Risk managers and security analysts owning information security risk management in their organisation
  • Consultants advising on programme design and maturity
  • Team leads moving from delivery into programme ownership
  • Professionals seeking a recognised practitioner credential

Prerequisites

A working knowledge of information security risk management fundamentals. No formal prerequisite is enforced.

See the Foundation course

What is included

  • Official PECB participant materials and case studies
  • 3-hour PECB certification exam voucher included
  • One free exam retake if you do not pass first time
  • First-year certification application fee covered
  • 31 CPD credits on completion
  • Twelve months of access to the KATE learning app
  • A 1:1 pre-enrolment call to confirm the course is right for you

Common questions

PECB is a global certification body that provides training and certification against ISO standards. Its personnel certification schemes are accredited to ISO/IEC 17024, the international standard for bodies certifying people — which is what makes a PECB credential recognised by employers, auditors and certification bodies worldwide rather than being a private certificate of attendance.

No. Foundation is not a formal prerequisite for Lead Implementer or Lead Auditor. It exists for people who are new to the standard and want the vocabulary and clause structure before the deeper course. If you already work with the standard day to day, go straight to the Lead course — we will tell you plainly on the pre-enrolment call which is right for you.

The official PECB participant materials and case studies, the certification exam voucher, one free retake if you do not pass first time, your first-year certification application fee, the CPD credits, twelve months of KATE app access, and a 1:1 call before you enrol. There are no separate exam fees added later.

Lead Implementer is for building the management system: scope, risk assessment, control selection, documentation and getting the organisation ready for its certification audit. Lead Auditor is for assessing one: audit planning, evidence gathering, findings, nonconformity reports and audit programme management. Implementers build, auditors verify. Consultants often hold both.

Foundation exams are one hour and multiple choice. Lead-level exams are three hours, essay-type and open book — you may bring the standard and your own notes. Exams can be sat online with remote proctoring or on paper at the end of a classroom session. Results are typically issued within four to six weeks, and your certification is then issued once your application is approved.

One retake is included in every price on this site, at no additional cost. PECB allows retakes without repeating the training, and we will run a focused review session with you first to work out what went wrong.