ENTERPRISE & INFORMATION SECURITY RISK

RISK MANAGEMENT TRAINING

Develop practical skills to identify, assess, treat and monitor risk. ISO 31000 provides guidance for managing risk across an organisation, while ISO/IEC 27005 focuses on information security risk. Compare introductory and advanced ISO 31000 training with the specialist ISO/IEC 27005 Risk Manager option to choose the path that fits your responsibilities.

Identify Risks

Recognise threats and opportunities that could affect objectives.

Clear Ownership

Define who assesses, treats and monitors each risk.

Informed Decisions

Use risk assessment to guide priorities and actions.

Ongoing Review

Monitor changes and improve risk treatment over time.

ISO 31000 Foundation

Who it is forProfessionals who want an introduction to risk management principles and processes.

What you will learnUnderstand risk management concepts, the ISO 31000 framework and the main steps in managing risk.

PrerequisiteNone.

Duration2 days.

Typical next stepProgress to Risk Manager training.

ISO 31000 Risk Manager

Who it is forManagers, risk practitioners and consultants responsible for applying risk management across an organisation.

What you will learnEstablish a risk management framework and apply risk assessment, treatment, monitoring and communication processes.

PrerequisiteBasic knowledge of risk management is recommended.

Duration3–4 days; check the selected programme.

Typical next stepManage organisational risk activities or progress to Lead Risk Manager training.

ISO 31000 Lead Risk Manager

Who it is forExperienced professionals responsible for leading organisation-wide risk management.

What you will learnLead the design, implementation, review and improvement of a risk management framework and process.

PrerequisiteRisk management knowledge and relevant experience are recommended.

Duration5 days.

Typical next stepLead strategic risk management and improvement activities.

ISO/IEC 27005 Risk Manager

Who it is forInformation security, cybersecurity and risk professionals managing risks to information assets.

What you will learnIdentify, analyse, evaluate, treat and communicate information security risks using ISO/IEC 27005 guidance.

PrerequisiteBasic knowledge of information security and risk management is recommended.

Duration3 days.

Typical next stepApply information security risk management within your organisation.

READY TO CHOOSE YOUR TRAINING?

Individual learners can explore available courses and dates in the training catalogue.
Organisations can request a training solution for their team.

FREQUENTLY ASKED QUESTIONS

RISK MANAGEMENT TRAINING FAQS

Find the right training for organisational or information security risk.

What is the difference between ISO 31000 and ISO/IEC 27005?

ISO 31000 gives guidance for managing risk across an organisation. ISO/IEC 27005 applies risk management principles specifically to information security risk.

Which course should I choose first?

Choose ISO 31000 Foundation if you are new to risk management. Choose ISO 31000 Risk Manager for broader organisational risk responsibilities, or ISO/IEC 27005 Risk Manager if your focus is information security risk.

When should I choose Lead Risk Manager?

Choose it when you have relevant risk management knowledge and need to lead the design or improvement of organisation-wide risk management activities.

Why can the ISO 31000 Risk Manager duration vary?

Training formats and programme structures may differ. Review the duration shown for the specific course you select in the training catalogue.

Does ISO 31000 certify an organisation?

ISO 31000 provides risk management guidelines. These training courses develop individual knowledge and skills; completing one does not certify an organisation.

Can our team request private training?

Yes. Use the corporate training option to discuss your team's risk responsibilities and preferred learning arrangement.