Home / Training / ISO 27005: Certified Risk Manager with EBIOS Method

ISO 27005: Certified Risk Manager with EBIOS Method

Master risk management according to ISO/IEC 27005 and the EBIOS method (ANSSI).

Objective

This intensive five-day course allows you to master risk management for all relevant information security assets, using ISO/IEC 27005:2011 as a reference framework and the EBIOS method (developed by ANSSI). Through practical exercises and case studies, you will learn to perform optimal risk assessment and manage risk over time, being familiar with their life cycle.

Specific objectives:

  • Understand the concepts, approaches, methods, and techniques for effective risk management
  • Develop the necessary skills to conduct a risk analysis with the EBIOS method

Prerequisites

  • Basic knowledge of information systems security

General Information

  • Code: ISO27005+EBIOS
  • Duration: 5 days
  • Schedule: 8:30 AM - 5:30 PM
  • Location: 4-star hotel, Tunis

Target audience

  • Risk managers
  • Information technology consultants
  • Information security or compliance managers

Resources

  • Course materials
  • 40% demonstration
  • 40% theory
  • 20% practical exercises

Training Program

  • Days 1 to 4 : Introduction, risk management, identification and analysis according to ISO 27005
    • Concepts and definitions related to risk management
    • Standards, reference frameworks, and methodologies
    • Implementation of a risk management program
    • Risk analysis (identification and estimation)
    • Risk evaluation, treatment, acceptance, communication, and monitoring
    • Certified ISO/IEC 27005 Risk Manager Exam
  • EBIOS: Risk Analysis
    • EBIOS Presentation
    • Phase 1 – Context establishment
    • Phase 2 – Analysis of fear events
    • Phase 3 – Risk analysis
    • Phase 4 – Determination of security measures
    • Workshop with case studies
  • Day 5 : Exam session

Do not hesitate to contact our experts for any additional information, free study and calculation of an audit service.

Information security is essential for any company that needs to protect and improve its information assets.

Contact us