1. Introduction to ISO/IEC 27005 and information security risk management

By the end of this module, learners will be able to:

  • Differentiate Between General and Domain-Specific Standards: Contrast the high-level enterprise principles of ISO 31000 with the information-security-specific guidance of ISO 27005.

  • Identify Cognitive Biases in Risk: Explain how human psychology and risk perception influence decision-making, and how standardised frameworks help mitigate these subjective biases.

  • Analyse the ISO 31000 Architecture and outline the relationship among the three pillars of risk management: Principles, Framework, and Process.

  • Select Appropriate Assessment Tools: Evaluate various risk assessment methodologies (referencing IEC 31010) to determine which qualitative or quantitative tools best suit different organisational needs.

  • Map the Standards Ecosystem: Describe how different ISO/IEC frameworks interlock to create a comprehensive risk management environment