Skip to main content
ISO 31000

ISO 27005 Foundation

ISO 27005 Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Risk management professionals seeking to formalise their knowledge of information security risk management guidelines
  • Professionals who want to become familiar with ISO/IEC 27005 and its application to information security risks
  • Personnel responsible for managing information security risks within their area of responsibility
  • Individuals interested in beginning or advancing a career in information security risk management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced information security risk practitioners who already apply ISO/IEC 27005 daily will likely find the content too introductory
  • Professionals seeking deep technical skills in penetration testing or vulnerability management will not find that focus in this course
  • Those looking for implementation or auditor-level credentials should explore higher-level PECB programmes aligned to ISO/IEC 27001 or ISO/IEC 27005

What you'll be able to do

  • 1Define the main risk management concepts, principles, and definitions relevant to information security
  • 2Interpret the guidelines of ISO/IEC 27005 for managing information security risks within an organisation
  • 3Identify the approaches, methods, and techniques used to implement and manage an information security risk management programme
  • 4Distinguish between different risk treatment options and explain when each is appropriate
  • 5Describe the iterative nature of information security risk management and its relationship to the broader information security management system
  • 6Apply ISO/IEC 27005 concepts to introductory risk identification and assessment scenarios

Day by day

Day 1Introduction to ISO/IEC 27005 and Fundamental Concepts of Information Security Risk Management
  • Core Risk Management Concepts and Definitions

    Participants examine the foundational terminology and principles of risk management as they apply to information security environments.

  • Overview of ISO/IEC 27005 and Its Guidelines

    This module introduces the structure and intent of ISO/IEC 27005, explaining how its guidelines support systematic information security risk management.

  • Relationship Between ISO/IEC 27005 and Information Security Management

    Participants explore how ISO/IEC 27005 connects to the broader information security management landscape, including its relevance to ISO/IEC 27001.

By end of day

  • Use correct ISO/IEC 27005 terminology when discussing information security risks with colleagues or stakeholders
  • Explain the purpose and scope of ISO/IEC 27005 and how it supports organisational risk decisions
  • Describe the relationship between risk management guidelines and an information security management system
Day 2Information Security Risk Management Processes and Exam Preparation
  • Information Security Risk Management Approaches and Processes

    Participants review the risk assessment, treatment, acceptance, communication, and monitoring processes outlined in ISO/IEC 27005.

  • Methods and Techniques for Risk Assessment

    This module introduces qualitative and quantitative methods and practical techniques that can be used to identify, analyse, and evaluate information security risks.

  • Domain Review: Exam Competency Domains 1 and 2

    Participants consolidate their understanding of both exam competency domains to prepare for the PECB ISO/IEC 27005 Foundation exam.

By end of day

  • Describe the end-to-end information security risk management process as structured by ISO/IEC 27005
  • Select appropriate risk assessment methods for a given organisational context
  • Assess readiness across both exam competency domains before sitting the PECB Foundation exam

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental concepts of information security risk management
  • Domain 2: Information security risk management approaches and processes

Certification Rules and Policies

The certificate requirements are:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational Approach

  • Contains lecture sessions illustrated with examples and discussions
  • Encourages interaction between participants by means of questions and suggestions
  • Includes quizzes with similar structure to the exam

Buyers always ask

What is the difference between completing the training and obtaining the PECB certificate?+

Completing the two-day training course provides participants with an attestation of completion and an understanding of ISO/IEC 27005 guidelines. It does not automatically result in a credential.

To obtain the PECB Certificate Holder in ISO/IEC 27005 Foundation credential, a participant must pass the PECB exam and submit a successful certificate application to PECB in accordance with their Certification Rules and Policies.

What competency domains does the PECB ISO/IEC 27005 Foundation exam assess?+

The exam covers two competency domains: Domain 1 addresses fundamental concepts of information security risk management, and Domain 2 covers information security risk management approaches and processes.

Candidates should consult the PECB List of Exams and Examination Rules and Policies for details on exam format, duration, and language availability.

Is any prior experience in risk management or information security required to attend?+

No prior experience is required. The course is designed to introduce participants to information security risk management concepts and ISO/IEC 27005 from a foundational level.

Professionals from a variety of backgrounds, including IT, compliance, and operations, can attend without needing specialist risk management qualifications.

How does ISO/IEC 27005 relate to ISO/IEC 27001?+

ISO/IEC 27005 provides detailed guidance on information security risk management processes, which directly support the risk assessment and treatment requirements found in ISO/IEC 27001.

Understanding ISO/IEC 27005 can therefore be valuable for individuals involved in implementing or maintaining an information security management system based on ISO/IEC 27001.

What credential can be pursued after passing the PECB ISO/IEC 27005 Foundation exam?+

After passing the exam, candidates can apply for the PECB Certificate Holder in ISO/IEC 27005 Foundation, which is an entry-level credential within the PECB certification programme.

This credential requires passing the exam and completing the certificate application process. There are no professional experience requirements for this particular certificate, as confirmed by PECB's published requirements.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.