1. Introduction to ISO/IEC 27005 and information security risk management
By the end of this module, learners will be able to:
Differentiate Between General and Domain-Specific Standards: Contrast the high-level enterprise principles of ISO 31000 with the information-security-specific guidance of ISO 27005.
Identify Cognitive Biases in Risk: Explain how human psychology and risk perception influence decision-making, and how standardised frameworks help mitigate these subjective biases.
Analyse the ISO 31000 Architecture and outline the relationship among the three pillars of risk management: Principles, Framework, and Process.
Select Appropriate Assessment Tools: Evaluate various risk assessment methodologies (referencing IEC 31010) to determine which qualitative or quantitative tools best suit different organisational needs.
Map the Standards Ecosystem: Describe how different ISO/IEC frameworks interlock to create a comprehensive risk management environment