«ISO/IEC 27005:2022 Управление рисками информационной безопасности — SynergyCom

«ISO/IEC 27005:2022 Управление рисками информационной безопасности

Код курса: BSI-006 Продолжительность: 2 дня (16 часов)

По завершению курса «ISO/IEC 27005:2022 Управление рисками информационной безопасности» вы сможете:

  • Объяснить концепции, характерные для управления информационными рисками, включая термины и определения
  • Распознать типичные риски информационной безопасности, с которыми сталкиваются организации
  • Распознать типичные проблемы управления рисками информационной безопасности
  • Разъяснять введение, предысторию, цель, область применения и структуру ISO/IEC 27005:2022
  • Описать как ISO/IEC 27005:2022 интегрируется и взаимодействует с другими стандартами, такими как ISO/IEC 27001:2022
  • Реализовать темы, охватываемые ISO/IEC 27005:2022, в своей организации
  • Определить ценность информационных активов, находящихся под вашим контролем
  • Оценить угрозы информационным активам
  • Определить, проанализировать и оценить риски информационной безопасности
  • Определить приоритеты и выбрать соответствующие методы обработки рисков.

Авторизованный семинар включает:

  • Официальное учебное пособие в электронном виде
  • Сертификат о прохождении обучения от British Standards Institution

Продолжительность: 2 дня, 16 академических часов
Формат: 80% лекции / 20% практика

With the increasing number of internal and external information security threats, organizations recognize the importance of adopting a formal risk management programme. Without a mechanism to identify, analyse and manage information security risks, it’s difficult for organizations to prioritize their security remediation efforts and resource allocation and associated costs. This leaves organizations more susceptible to security breaches, which can lead to financial and reputational damage.

Building on the concepts and framework specified in ISO/IEC 27001, ISO/IEC 27005 provides guidelines for adopting an information security risk management approach that is appropriate to all organizations.

This course aims to provide you with clear and practical guidance on the framework and steps involved to identify, analyse and manage information security risks. It will help you to review your existing risk treatments and controls, and ensure they are appropriate to manage and reduce the identified risks. This will give you the confidence to get the most effective allocation of resources in place to address information security issues for your organization.

How will you benefit?

This course will help you:

  • Identify key benefits associated with using ISO/IEC 27005:2022 for protecting information assets, as part of an effective information security management system (ISMS)
  • Understand the best practice risk management processes contained in ISO/IEC 27005:2022
  • Understand the rationale behind the processes, their usage and implementation
  • Establish an acceptable level of risk for your information assets based on a knowledge and understanding of the risks your organization faces
  • Develop processes for assessing and managing the many different risks related to your organization’s information assets

This course will help organizations investigate and score information security risks in a robust, quantifiable and repeatable way.

What will you learn?

By the end of this course delegates will be able to:

  • Explain concepts specific to information risk management including terms and definitions
  • Recognize typical information security risks faced by organizations
  • Recognize typical information security risk management concerns
  • Communicate ISO/IEC 27005:2022 introduction, background, purpose, scope and structure
  • Explain how ISO/IEC 27005:2022 integrates and interfaces with other standards such as ISO/IEC 27001:2022
  • Implement the topics covered in ISO/IEC 27005:2022 within your organization
  • Determine the value of the information assets under your control
  • Evaluate threats to information assets
  • Identify, analyse and evaluate information security risks
  • Prioritize and choose appropriate risk treatments

Who should attend?

Anyone who wants to learn about:

  • Identifying and analysing information security risks
  • How risks can be evaluated
  • What treatments, controls and measures can be implemented in order to mitigate risks
  • Ongoing governance and risk monitoring processes

The course is applicable to individuals from any size or type of organization who are currently involved in (or will be in the future) planning, implementing, maintaining, supervising or assessing information security, as part of an ISO/IEC 27001 ISMS or a standalone system.

What’s included?

  • Course notes
  • On completion, you will be awarded an internationally recognized BSI Training Academy certificate.

Время проведения курса пока не определено, отправьте нам заявку, пожалуйста.

Возможно, мы предложим пройти курс в дистанционном режиме или организуем выездной курс, если у Вас группа.

Направления обучения

Поиск по сайту