ISO/IEC 27005 LEAD RISK MANAGER
ISO/IEC 27005 LEAD RISK MANAGER
Obtain the necessary competencies to guide and support organizations establish their information security risk management process based on ISO/IEC 27005 and other best practices
*International Certification by Professional Evaluation and Certification Board (PECB)*
Background ISO/IEC 27005 LEAD RISK MANAGER
Risk management is an essential component of any information security program. An effective information security risk management program enables organizations to detect, address, mitigate, and even prevent information security risks.
The ISO/IEC 27005 Lead Risk Manager training course provides an information security risk management framework based on ISO/IEC 27005 guidelines, which also supports the general concepts of ISO/IEC 27001. The training course also provides participants with a thorough understanding of other best risk management frameworks and methodologies, such as OCTAVE, EBIOS, MEHARI, CRAMM, NIST, and Harmonized TRA.
The PECB ISO/IEC 27005 Lead Risk Manager certificate demonstrates the individual has acquired the necessary skills and knowledge to successfully perform the processes needed for effectively managing information security risks. It also proves that the individual is able to assist organizations in maintaining and continually improving their information security risk management program.
The training course is followed by an exam. If you pass, you can apply for a “PECB Certified ISO/IEC 27005 Lead Risk Manager” credential. For more information about the examination process, please refer to the Examination, Certification, and General Information section below.
Objectives ISO/IEC 27005 LEAD RISK MANAGER
By successfully completing this training course, you will be able to:
- Explain the risk management concepts and principles based on ISO/IEC 27005 and ISO 31000
- Establish, maintain, and continually improve an information security risk management framework based on the guidelines of ISO/IEC 27005 and best practices
- Apply information security risk management processes based on the guidelines of ISO/IEC 27005
- Plan and establish risk communication and consultation activities
- Record, report, monitor, and review the information security risk management process and framework
Contents
- Introduction to ISO/IEC 27005 and information security risk management
- Training course objectives and structure
- Standards and regulatory frameworks
- Fundamental concepts and principles of information security risk management
- Information security risk management program
- Context establishment
- Risk identification, analysis, evaluation, and treatment based on ISO/IEC 27005
- Risk identification
- Risk analysis
- Risk evaluation
- Risk treatment
- Information security risk communication and consultation, recording and reporting, and monitoring and review
- Information security risk communication and consultation
- Information security risk recording and reporting
- Information security risk monitoring and review
- Risk assessment methods
- OCTAVE and MEHARI methodologies
- EBIOS method
- NIST framework
- CRAMM and TRA methods
- Closing of the training course
- Certification Exam
Examination
- Domain 1: Fundamental principles and concepts of information security risk management
- Domain 2: Implementation of an information security risk management program
- Domain 3: Information security risk assessment
- Domain 4: Information security risk treatment
- Domain 5: Information security risk communication, monitoring, and improvement
- Domain 6: Information security risk assessment methodologies
Certification
Metode
Metode pelatihan dapat dilakukan dengan tiga metode dimana Peserta dapat memilih metode yang sesuai. Metode tersebut adalah :
- Metode Peserta Belajar Online Mandiri (Asinkron) yaitu:
- Peserta belajar secara mandiri melalui website yang disediakan setelah mendapatkan akun untuk mengakses materi.
- Apabila diperlukan peserta dapat diskusi atau konsultasi terkait dengan materi yang akan difasilitasi oleh konsultan/trainer dari PT Expertindo melalui berbagai media seperti Google Meet, Zoom, Microsoft Teams, Team link, atau WhatsApp sesuai dengan kesepakatan
- Metode Live Online Training(Sinkron) yaitu :
- Instruktur mengajar secara LIVE dengan durasi 4 jam perhari selama 3 hari secara terjadwal
- Media Live training dapat menggunakan Google Meet, Zoom, Microsoft Teams atau Team link.
- Metode Offline Training(Classroom) yaitu:
- Instruktur mengajar secara tatap muka dengan durasi 8 jam perhari selama 3 hari secara terjadwal
- Teknik yang digunakan: presentasi, diskusi, tanya jawab, studi kasus, brainstorming.
Ketentuan Online Training
Persiapan Peserta
- Dianjurkan menggunakan laptop, bukan smartphone.
- Koneksi internet yang stabil.
- Buku dan alat tulis.
- Peserta menginstall aplikasi sesuai yang akan digunakan, sebelum jadwal training berlangsung. Untuk yang mempunyai kesulitan, bisa menghubungi staff kami sebelum jadwal training berlangsung
Platform yang digunakan
- Beberapa alternative platform Zoom, Google Meet, Hang Out, Team link atau Webex untuk conference live training
- Google Classroom untuk memuat materi, tugas dan dokumen lain yang dapat diakses peserta dengan link dan kode kelas yang akan diberikan oleh penyelenggara sebelum pelaksanaan training.
Cara masuk ke video conference
- Penyelenggara akan memberikan undangan berupa link.
- Klik linktersebut, ikuti arahan selanjutnya.
- Anda akan dibawa masuk ke dalam video conference.
Investasi dan Fasilitas
Metode Pelaksanaan | Harga & Fasilitas |
Opsi 1 –
Pelatihan Online |
● Training Online Rp 6.900.000 per peserta
● Sertfikasi $600 ● Minimal kuota 1 peserta dan bisa request tanggal ● Pelaksanaan training selama 3 hari half day (08.00 – 12.00 WIB atau 13.00 – 17.00 WIB) ● Menggunakan aplikasi Zoom, Google Meet, atau Ms Teams ● Fasilitas : Sertifikat Training Softfile & Hardfile, Pengiriman Sertifikat ke Alamat Peserta, Softfile Materi ● Biaya belum termasuk PPN 11% |
Opsi 2 –
Pelatihan Offline di Yogyakarta |
● Training Offline Rp 9.900.000 per peserta
● Sertfikasi $600 ● Minimal kuota 1 peserta dan bisa request tanggal ● Pelaksanaan training selama 3 hari full day (08.00 – 16.00 WIB) ● Tempat pelaksanaan di Hotel Ibis Malioboro, Yogyakarta ● Fasilitas : Meeting Room, Modul Training, Sertifikat Training, Training Kits, Lunch, Coffee Break ● Biaya belum termasuk PPN 11% |
Opsi 3 –
Pelatihan Offline Luar Yogyakarta (Jakarta, Bandung, Surabaya, dll) |
● Training Offline Rp 10.900.000 per peserta
● Sertfikasi $600 ● Minimal kuota 2 peserta dan bisa request tanggal ● Pelaksanaan training selama 3 hari full day (08.00 – 16.00 WIB) ● Pilihan Tempat pelaksanaan : ● Hotel Grand Tebu, Bandung ● Hotel Santika Pandegiling, Surabaya ● Hotel Asyana Kemayoran, Jakarta ● Hotel Ibis Simpang Lima, Semarang ● Hotel Ibis, Solo ● dll ● Fasilitas : Meeting Room, Modul Training, Sertifikat Training, Training Kits, Lunch, Coffee Break ● Biaya belum termasuk PPN 11% |
Opsi 4 –
Pelatihan Offline Luar Pulau Jawa (Lombok, Bali, Balikpapan, dll) |
● Training Offline Rp 11.900.000 per peserta
● Sertifikasi $600 ● Minimal kuota 2 peserta dan bisa request tanggal ● Pelaksanaan training selama 3 hari full day (08.00 – 16.00 WIB) ● Pilihan Tempat pelaksanaan : ✔ Hotel Santika Kuta,Bali ✔ Hotel Nagoya Plaza, Batam ✔ Hotel Fave, Balikpapan ✔ Hotel Aston, Manado ✔ Hotel Lombok Raya, Mataram ✔ dll ● Fasilitas : Meeting Room, Modul Training, Sertifikat Training, Training Kits, Lunch, Coffee Break ● Biaya belum termasuk PPN 11% |
Lead Instructor
PECB Consultant Team |
In House Training lainnya yang beritanya dapat dilihat di link berikut => In House Training.
Untuk judul dan informasi online training, kunjungi juga website PT Expertindo lainnya di alamat www.e-trainingonline.com