Information Security Risk Management
ISO/IEC 27005 provides the guidelines for information security risk management that ISO/IEC 27001 assumes but does not spell out. It is the course that turns a risk register from a spreadsheet of guesses into a defensible, repeatable process.
Why ISO/IEC 27005 is worth holding
- Fixes the weakest part of most ISMS implementations: the risk assessment
- Directly examinable evidence of risk competence for auditors and regulators
- Pairs with ISO 31000 for enterprise-wide risk alignment
- Certification paths
- 2
- From
- $795
Certification path
You do not need all of these. Most people take one — the level that matches what they are actually being asked to do.
Foundation
A two-day grounding in ISO/IEC 27005 — the vocabulary, the structure of the standard and how information security risk management programmes actually work in practice.
Manager
Five days building the practitioner capability to establish, run and continually improve information security risk management as a managed programme.
Compare the levels
| Level | Length | CPD | Exam | Best for | From |
|---|---|---|---|---|---|
| Foundation | 2 days | 14 | 1h · Multiple choice | Professionals joining the risk programme implementation or audit team | $795 |
| Manager | 5 days | 31 | 3h · Essay-type | Risk managers and security analysts owning information security risk management in their organisation | $1,495 |
PECB is a global certification body that provides training and certification against ISO standards. Its personnel certification schemes are accredited to ISO/IEC 17024, the international standard for bodies certifying people — which is what makes a PECB credential recognised by employers, auditors and certification bodies worldwide rather than being a private certificate of attendance.
No. Foundation is not a formal prerequisite for Lead Implementer or Lead Auditor. It exists for people who are new to the standard and want the vocabulary and clause structure before the deeper course. If you already work with the standard day to day, go straight to the Lead course — we will tell you plainly on the pre-enrolment call which is right for you.
The official PECB participant materials and case studies, the certification exam voucher, one free retake if you do not pass first time, your first-year certification application fee, the CPD credits, twelve months of KATE app access, and a 1:1 call before you enrol. There are no separate exam fees added later.
Lead Implementer is for building the management system: scope, risk assessment, control selection, documentation and getting the organisation ready for its certification audit. Lead Auditor is for assessing one: audit planning, evidence gathering, findings, nonconformity reports and audit programme management. Implementers build, auditors verify. Consultants often hold both.
Foundation exams are one hour and multiple choice. Lead-level exams are three hours, essay-type and open book — you may bring the standard and your own notes. Exams can be sat online with remote proctoring or on paper at the end of a classroom session. Results are typically issued within four to six weeks, and your certification is then issued once your application is approved.
One retake is included in every price on this site, at no additional cost. PECB allows retakes without repeating the training, and we will run a focused review session with you first to work out what went wrong.