Visão Geral
O curso ISO 27005 Risk Management tem como objetivo capacitar profissionais na identificação, análise, avaliação e tratamento de riscos relacionados à Segurança da Informação, com base na norma ISO/IEC 27005. O treinamento aborda metodologias e boas práticas para gestão de riscos em ambientes corporativos, integrando-se ao Sistema de Gestão de Segurança da Informação (SGSI) baseado na ISO/IEC 27001.
Conteúdo Programatico
Module 1 – Introduction to Information Security Risk Management
- Overview of ISO/IEC 27005 standard
- Relationship between ISO 27005 and ISO 27001
- Risk management concepts and terminology
- Principles of information security risk management
- Risk management frameworks and approaches
Module 2 – Context Establishment
- Defining the scope and boundaries
- Identifying assets and asset owners
- Business environment and organizational context
- Legal, regulatory, and contractual requirements
- Risk criteria definition
Module 3 – Risk Identification
- Asset-based risk identification
- Threat identification techniques
- Vulnerability identification
- Existing controls analysis
- Risk scenarios development
Module 4 – Risk Analysis
- Qualitative vs quantitative analysis
- Likelihood and impact assessment
- Risk level determination
- Risk matrices and scoring models
- Documentation of analysis results
Module 5 – Risk Evaluation
- Comparing risks against risk criteria
- Risk prioritization
- Decision-making for risk treatment
- Acceptable vs unacceptable risks
Module 6 – Risk Treatment
- Risk treatment options (avoid, reduce, transfer, accept)
- Selection of security controls
- Risk treatment plan development
- Residual risk evaluation
- Alignment with Annex A controls
Module 7 – Risk Communication and Consultation
- Stakeholder communication strategies
- Reporting risk information
- Supporting decision-making processes
- Risk awareness and culture
Module 8 – Risk Monitoring and Review
- Continuous monitoring techniques
- Risk review processes
- Key risk indicators (KRIs)
- Improvement of risk management process
- Integration with ISMS lifecycle