The 5 Questions Every Board Should Ask Their CISO
Most boards do not know what to ask their CISO. That is not their fault. Cybersecurity moves faster than quarterly...
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
PECB Authorized Boot Camp. Official courseware, expert instructors, exam, certification fee, free retake, and 31 CPD credits included. Four days to a defensible risk method.
Exam Protection Included
Authorized Training
For risk managers and security officers who own the risk register. Four days to run information security risk management to ISO/IEC 27005:2022, so every control decision traces to a documented method, with the PECB exam and one free retake included.
ISO/IEC 27005:2022 turns risk assessment from opinion into method. Four days on identifying and analyzing information security risk, choosing treatment, recording decisions that trace back to evidence, and picking an assessment approach that fits the organization rather than the template.
We deliver the official PECB courseware, taught live by PECB-certified instructors. Every module maps to the certification exam objectives.
We include your PECB certification exam in the course price. No surprise fees. You take the exam on the final day of your course.
Unlock iOS/Android app immediately upon enrollment.
The only curriculum 100% aligned to the 2026 exam.
We cover your Included ($500 value) exam fee. No hidden costs.
Practice with CAT-style questions. No surprises.
Unlimited class returns if you need a second shot.
Day, evening, online or in-person—your choice.
Take your exam on-site within 7 days of class.
180 days of unlimited 1-on-1 coaching after class.
If you do not pass on your first attempt, we include one free retake within 12 months, covered by your course fee. The exam is open-book: 80 multiple-choice questions in three hours.
Immersive classroom experience with direct instructor access and peer collaboration.
Same instructors, same curriculum - learn from anywhere using our award-winning virtual learning platform.
Tell us about your training needs and we'll create a personalized plan.
Official PECB courseware taught live by PECB-certified instructors. Four days that follow the official course structure through to the exam.
Risk management fundamentals, the risk program, assessment, treatment, communication and monitoring, and assessment methodologies.
The PECB exam is 80 multiple-choice questions, open-book, three hours, and both the exam and certification fees are in your course price.
ISO/IEC 27005:2022 gives your risk assessment a documented method, so every control choice and the Statement of Applicability trace back to it.
If you do not pass your first attempt, we include one free retake within 12 months of the exam, covered by your course fee.
PECB issues an attestation of course completion worth 31 CPD credits you can put toward other certifications’ continuing-education requirements.
A structured path designed for working professionals.
Each day builds on the last—momentum is everything.
Real questions from real professionals who passed.
Here's
how we answer them.
ISO/IEC 27005 is the international standard for managing information security risk: how to identify, analyze, evaluate, treat and monitor it. The PECB Certified ISO/IEC 27005 Lead Risk Manager credential shows you can run an information security risk management program that stands up to an ISO/IEC 27001 audit.
Risk managers, information security officers, ISMS team members, and consultants who run or advise on an information security risk program. Privacy officers who need a defensible risk method for personal data also attend.
PECB asks for a fundamental understanding of ISO/IEC 27005 and a working knowledge of risk management and information security. You do not need ISO/IEC 27001 Lead Implementer first.
Day 1 introduces ISO/IEC 27005:2022 and how it fits with ISO/IEC 27001 and ISO 31000. Day 2 is the core of the standard: risk identification, analysis, evaluation and treatment. Day 3 covers risk communication, recording, reporting, monitoring and review. Day 4 compares risk assessment methods and how to choose one for your organization. The four days follow PECB’s official course structure, with the exam at the end.
The exam covers 6 competency domains: fundamental principles of information security risk management; implementing a risk management program; information security risk assessment; information security risk treatment; risk communication, monitoring and improvement; risk assessment methodologies. Questions are weighted across the domains, and the course is organized so every domain is taught before you sit the exam.
The exam has 80 multiple-choice questions, a mix of standalone and scenario-based, and lasts 3 hours. It is open-book, and the passing score is 70%. Online exams are graded instantly.
Yes. Both the PECB certification exam and the certification fee are included in your course fee, and the exam is scheduled at the end of the course. There is nothing extra to buy to get certified.
Yes. We include one free exam retake within 12 months of your first attempt, and it is covered by your course fee.
ISO/IEC 27001 requires a risk assessment and a risk treatment plan but does not say how to perform them. ISO/IEC 27005 is the standard that does. Following it means the controls you select and the Statement of Applicability you sign trace back to a documented, repeatable method that an auditor can follow.
Lead Implementer covers the entire management system, with risk as one chapter. Lead Risk Manager spends all four days on risk: the framework, the assessment, the treatment decisions and the methods. Take it if risk is your job rather than one of your tasks.
As of 2026 the current edition is ISO/IEC 27005:2022, which aligned the standard with ISO/IEC 27001:2022 and ISO 31000 and dropped the older annex of prescribed methods in favor of guidance on choosing one. This course teaches the 2022 edition.
Yes. PECB issues an attestation of course completion worth 31 CPD (Continuing Professional Development) credits to everyone who attends the course.
Yes. PECB is accredited to ISO/IEC 17024, the international standard for bodies certifying people, and its credentials are recognized internationally. Training Camp delivers the official PECB courseware as an authorized training partner.
The risk questions boards actually ask, where risk credentials fit in GRC, and how the PECB exams and certification process work.
Most boards do not know what to ask their CISO. That is not their fault. Cybersecurity moves faster than quarterly...
GRC job postings have a certification problem. Pull up ten listings for governance, risk, and compliance roles right now and...
ISO/IEC 27001 Lead Implementer trains you to build an information security management system and get it through a certification audit....
PECB is a personnel certification body accredited under ISO/IEC 17024 that issues credentials tied to ISO management system standards, and...
Advance your career with these recommended certifications
Build and certify an ISO/IEC 27001:2022 ISMS in four days.
Select, implement and measure the 93 ISO/IEC 27002:2022 controls.
Plan, detect, respond and recover with the ISO/IEC 27035 series.
Plan, lead and report ISO/IEC 27001 audits to ISO 19011.