Day 1: Introduction, risk management program according to ISO 27005
Concepts and definitions related to risk management
Risk management standards, frameworks and methodologies
Implementation of an information security risk management program
Understanding an organization and its context
Day 2: Risk identification and assessment, risk evaluation, treatment, acceptance, communication and surveillance according to ISO 27005
Risk identification
Risk analysis and risk evaluation
Risk assessment with a quantitative method
Risk treatment
Risk acceptance and residual risk management
Information Security Risk Communication and Consultation
Risk monitoring and review
Day 3: Exam and risk assessment methodologies according to IEC/ISO 31010
Certified ISO/IEC 27005 Risk Manager Exam (2 hours)
Brainstorming
DELPHI technique
HAZOP – Hazard & Operability Analysis
SWIFT – The Structured ‘What If’ Technique
HACCP - Hazard Analysis Critical Control Point
Scenario analysis
FMEA & FMECA analysis
FTA analysis
"Taken from PECB <https://pecb.com