Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

PECB Authorized Training Partner

PECB Certified ISO/IEC 27005 Lead Risk Manager

PECB Authorized Boot Camp. Official courseware, expert instructors, exam, certification fee, free retake, and 31 CPD credits included. Four days to a defensible risk method.

Verified for 2026 ISO-27005-RM Exam
Student
Student
Student
Join 250,000+ certified alumni.
CISSP Professional

Free Retake

Exam Protection Included

Official PECB

Authorized Training

PECB Authorized Training Partner

Exam Ready in Four Days. Assess the Risk. Defend the Method.

For risk managers and security officers who own the risk register. Four days to run information security risk management to ISO/IEC 27005:2022, so every control decision traces to a documented method, with the PECB exam and one free retake included.

Program Abstract

REF: ISO-27005-RM 6
Curriculum aligned to the latest Exam Outline.
Format Live, Instructor-Led
Duration 4

A Risk Register an Auditor Can Follow.

ISO/IEC 27005:2022 turns risk assessment from opinion into method. Four days on identifying and analyzing information security risk, choosing treatment, recording decisions that trace back to evidence, and picking an assessment approach that fits the organization rather than the template.

Official PECB Training.

We deliver the official PECB courseware, taught live by PECB-certified instructors. Every module maps to the certification exam objectives.

System Integrity Check
Content Source PECB Official
Curriculum Ver. v2025.1
Instructor Auth. Verified
Exam Alignment 100% MATCH

Exam Fee Included.

We include your PECB certification exam in the course price. No surprise fees. You take the exam on the final day of your course.

Mobile Learning

Start Right Away

Unlock iOS/Android app immediately upon enrollment.

Authorized Material

Course from the Source

The only curriculum 100% aligned to the 2026 exam.

All-Inclusive

Exam Fee Included

We cover your Included ($500 value) exam fee. No hidden costs.

Sim Engine

Exam Deja Vu

Practice with CAT-style questions. No surprises.

Retake Policy

Exam Protection Included

Unlimited class returns if you need a second shot.

Flexible Schedule

Training Fits Your Life

Day, evening, online or in-person—your choice.

Test Center

Test While It's Fresh

Take your exam on-site within 7 days of class.

Expert Support

Never On Your Own

180 days of unlimited 1-on-1 coaching after class.

Free Retake Included.

If you do not pass on your first attempt, we include one free retake within 12 months, covered by your course fee. The exam is open-book: 80 multiple-choice questions in three hours.

Thursday 5PM
Bootcamp Concludes - You leave with a personalized attack plan.
Class Ends
Unlimited 1-on-1
AI Gap Analysis - We identify your weak domains using our simulation engine.
Gap Analysis
Exam Day
Exam Protection Active - If you don't pass, your next seat is free.
Certified
·
Training materials including official courseware and study guides
Practitioner Led
Instructors are working security professionals, not just trainers.

"I don't teach from a textbook. I teach what happens in the SOC when the alert fires."

Jeff Porch

VP Ed. Services • CISSP, CISM CISSP: Certified Information Systems Security Professional. CISM: Certified Information Security Manager.

Choose Your Delivery Mode.

Same Curriculum
In-person classroom training session
A

In-Person

Immersive classroom experience with direct instructor access and peer collaboration.

  • Face-to-face instruction
  • On-site exam option
Student attending live online training
B

Live Online

Same instructors, same curriculum - learn from anywhere using our award-winning virtual learning platform.

  • Zero travel required
  • Interactive breakout rooms
Get Started Today

Explore Your Training Options

Tell us about your training needs and we'll create a personalized plan.

PECB Authorized Training Partner

PECB Authorized Training Partner

Official PECB courseware taught live by PECB-certified instructors. Four days that follow the official course structure through to the exam.

6 exam domains

All 6 Exam Domains in Four Days

Risk management fundamentals, the risk program, assessment, treatment, communication and monitoring, and assessment methodologies.

Exam fee included

Exam and Certification Fee Included

The PECB exam is 80 multiple-choice questions, open-book, three hours, and both the exam and certification fees are in your course price.

ISO/IEC 27005:2022

Risk That Survives an Audit

ISO/IEC 27005:2022 gives your risk assessment a documented method, so every control choice and the Statement of Applicability trace back to it.

Free retake

Free Exam Retake

If you do not pass your first attempt, we include one free retake within 12 months of the exam, covered by your course fee.

CPD credits

31 CPD Credits

PECB issues an attestation of course completion worth 31 CPD credits you can put toward other certifications’ continuing-education requirements.

PECB Certified ISO/IEC 27005 Lead Risk Manager

Accepting Inquiries
+1

    Eligible for Special Pricing?

    We respect your privacy. No spam.

    COURSE STRUCTURE

    ISO 27005 Risk Manager
    Boot Camp Syllabus

    A structured path designed for working professionals.
    Each day builds on the last—momentum is everything.

    MODULE_ID: PECB-27005RM-01

    Live Training QS: ~5
    DAY 1
    Critical Path

    Risk Management Fundamentals and Context

    Introduction to ISO/IEC 27005:2022 and information security risk management
    L.01.1
    Relationship with ISO 31000 and ISO/IEC 27001
    L.01.2
    Risk management terminology and key concepts
    L.01.3
    Establishing context: organizational and risk criteria
    L.01.4
    Scope and boundaries of the risk management program
    L.01.5
    Risk management framework design and governance
    L.01.6

    MODULE_ID: PECB-27005RM-02

    Live Training QS: ~5
    DAY 2
    Critical Path

    Risk Assessment — Identification, Analysis, Evaluation

    Risk identification: assets, threats, vulnerabilities, controls
    L.02.1
    Qualitative risk analysis: likelihood and impact matrices
    L.02.2
    Quantitative risk analysis: ALE, SLE, ARO calculations
    L.02.3
    Risk evaluation: prioritization and acceptance criteria
    L.02.4
    Risk treatment options: modify, retain, avoid, share
    L.02.5
    Risk treatment plan development and SoA considerations
    L.02.6

    MODULE_ID: PECB-27005RM-03

    Live Training QS: ~6
    DAY 3
    Critical Path

    Communication, Monitoring, and Improvement

    Risk communication and stakeholder engagement
    L.03.1
    Risk reporting formats and dashboards
    L.03.2
    Recording and documentation requirements
    L.03.3
    Trigger-based and schedule-based risk reviews
    L.03.4
    Key Risk Indicators (KRIs) and integration with incident management
    L.03.5
    Continual improvement of the risk management process
    L.03.6

    MODULE_ID: PECB-27005RM-04

    Live Training QS: ~6
    DAY 4
    Critical Path

    Risk Assessment Methodologies and Exam

    OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)
    L.04.1
    EBIOS (Expression des Besoins et Identification des Objectifs de Securite)
    L.04.2
    MEHARI (Method for Harmonized Analysis of Risk)
    L.04.3
    NIST RMF (Risk Management Framework)
    L.04.4
    Selecting the right methodology for organizational context
    L.04.5
    Exam preparation and risk management best practices
    L.04.6
    COURSE PROGRESS Day 1 of 4
    FREQUENTLY ASKED QUESTIONS

    ISO/IEC 27005 Lead Risk Manager
    Boot Camp FAQ

    Real questions from real professionals who passed.
    Here's how we answer them.

    ISO/IEC 27005 is the international standard for managing information security risk: how to identify, analyze, evaluate, treat and monitor it. The PECB Certified ISO/IEC 27005 Lead Risk Manager credential shows you can run an information security risk management program that stands up to an ISO/IEC 27001 audit.

    Risk managers, information security officers, ISMS team members, and consultants who run or advise on an information security risk program. Privacy officers who need a defensible risk method for personal data also attend.

    PECB asks for a fundamental understanding of ISO/IEC 27005 and a working knowledge of risk management and information security. You do not need ISO/IEC 27001 Lead Implementer first.

    Day 1 introduces ISO/IEC 27005:2022 and how it fits with ISO/IEC 27001 and ISO 31000. Day 2 is the core of the standard: risk identification, analysis, evaluation and treatment. Day 3 covers risk communication, recording, reporting, monitoring and review. Day 4 compares risk assessment methods and how to choose one for your organization. The four days follow PECB’s official course structure, with the exam at the end.

    The exam covers 6 competency domains: fundamental principles of information security risk management; implementing a risk management program; information security risk assessment; information security risk treatment; risk communication, monitoring and improvement; risk assessment methodologies. Questions are weighted across the domains, and the course is organized so every domain is taught before you sit the exam.

    The exam has 80 multiple-choice questions, a mix of standalone and scenario-based, and lasts 3 hours. It is open-book, and the passing score is 70%. Online exams are graded instantly.

    Yes. Both the PECB certification exam and the certification fee are included in your course fee, and the exam is scheduled at the end of the course. There is nothing extra to buy to get certified.

    Yes. We include one free exam retake within 12 months of your first attempt, and it is covered by your course fee.

    ISO/IEC 27001 requires a risk assessment and a risk treatment plan but does not say how to perform them. ISO/IEC 27005 is the standard that does. Following it means the controls you select and the Statement of Applicability you sign trace back to a documented, repeatable method that an auditor can follow.

    Lead Implementer covers the entire management system, with risk as one chapter. Lead Risk Manager spends all four days on risk: the framework, the assessment, the treatment decisions and the methods. Take it if risk is your job rather than one of your tasks.

    As of 2026 the current edition is ISO/IEC 27005:2022, which aligned the standard with ISO/IEC 27001:2022 and ISO 31000 and dropped the older annex of prescribed methods in favor of guidance on choosing one. This course teaches the 2022 edition.

    Yes. PECB issues an attestation of course completion worth 31 CPD (Continuing Professional Development) credits to everyone who attends the course.

    Yes. PECB is accredited to ISO/IEC 17024, the international standard for bodies certifying people, and its credentials are recognized internationally. Training Camp delivers the official PECB courseware as an authorized training partner.

    Get the Free
    PECB-27005RM Exam Guide

    • Expert strategies to spot trick questions
    • Question patterns examiners actually use
    • Proven pacing + pressure management tactics
    Articles and Certification Resources

    ISO/IEC 27005 Lead Risk Manager
    Articles & Resources

    The risk questions boards actually ask, where risk credentials fit in GRC, and how the PECB exams and certification process work.

    Continue Your Journey

    ISO 27005 RM Related Courses

    Advance your career with these recommended certifications

    Featured on