Day 1 : Introduction, risk management program according to ISO/IEC 27005
Concepts and definitions related to risk management
Risk management standards, frameworks and methodologies
Implementation of information security risk management program
Understanding an organization and its context
DAY 2 : Risk identification and assessment, risk evaluation, treatment, acceptance, communication and surveillance according to ISO/IEC 27005
Risk identification
Risk analysis and risk evaluation
Risk assessment with a quantitative method
Risk treatment
Risk acceptance and residual risk management
Information Security Risk Communication and Consultation
Risk monitoring and review
DAY 3 : Exam and start of risk assessment with MEHARI
Certified ISO/IEC 27005 Risk Manager Exam (2 hours)
MEHARI Presentation
Assessment and classification issues
Overview of the process
The value chain for failures
Classification of resources
DAY 4 : Assessment of vulnerabilities and risk, according to MEHARI
Assessment of the vulnerabilities
Qualities of a security service
Measuring the quality of a security service
Evaluation process
Risk assessment
DAY 5 : Security planning according to MEHARI and Exam
Security plans and procedures
Tools to support the implementation of MEHARI
“MEHARI advanced” exam (2 hours)