Day 1: Introduction, risk management program according to ISO 27005
Concepts and definitions related to risk management
Risk management standards, frameworks and methodologies
Implementation of an information security risk management program
Understanding an organization and its context
Day 2: Risk identification and assessment, risk evaluation, treatment, acceptance, communication and surveillance according to ISO 27005
Risk identification
Risk analysis and risk evaluation
Risk assessment with a quantitative method
Risk treatment
Risk acceptance and residual risk management
Information Security Risk Communication and Consultation
Risk monitoring and review
Day 3: Exam and Start of a risk assessment with MEHARI
Certified ISO/IEC 27005 Risk Manager Exam (2 hours)
Presentation of MEHARI
Assessment and classification issues
Overview of the process
The value chain for failures
Classification of resources
Day 4: Assessment of vulnerabilities and risk, according to MEHARI
Assessment of the vulnerabilities
Qualities of a security service
Measuring the quality of a security service
Evaluation process
Risk assessment
Day 5: Security planning according to MEHARI & Exam
Security plans and procedures
Tools to support the implementation of MEHARI
The “MEHARI advanced” exam (3 hours)
"Taken from PECB <https://pecb.com