ISO/IEC 27005:2022 -
INFORMATION SECURITY RISK
MANAGEMENT

Overview
Organizations today recognize the importance of adopting a robust risk management programme.
ISO/IEC 27005 provides a risk management framework for organizations to manage information security risks. The standard supports the guidelines of ISO 31000 and is particularly helpful for organizations aiming to safeguard their information assets and achieve information security objectives.
By establishing a risk management process based on ISO/IEC 27005, organizations increase the effectiveness of their ISMS, address information security risks, and establish appropriate information security risk management practices.
Benefits of ISO 27005 Certification
Identify benefits associated with using ISO/IEC 27005:2018, as part of an information security management system (ISMS)
Understand the best practice risk management processes contained in ISO/IEC 27005:2018
Develop processes for assessing and managing the risks related to your organization’s information assets
ISO 27005 Foundation (FD):
The ISO 27005 Risk Management Foundation training course enables participants to gain fundamental knowledge needed to implement an information security risk management program by following widely recognized best practices.
After completing this course, participants can sit for the exam. Once participants meet the pass mark, he/she will be given an “SandBP Certified ISO 27005 Information Security Risk Management Foundation” credential. A Sand BP Foundation Certificate shows that the participants have understood the fundamental methodologies, requirements, framework and management approach.
- Introduction to information risk management according to ISO/IEC 27005:2022
- Organization-wide risk management
- Multitiered risk management
- Information security risk management based on ISO/IEC 27005:2022
- Certification Exam
- PREREQUISITE: Basic knowledge of ISO/IEC 27001 and ISO/IEC 27002, as well as an understanding of the key principles of ISMS.
ISO 27005 Risk Manager(MG)
Information Security Risk Manager training course enables participants to understand the process of developing, establishing, maintaining, and improving an information security risk management framework based on the guidelines of ISO/IEC 27005.
After mastering all the necessary concepts of ISO 27005, participants can sit for the exam. Once participants meet the pass mark, he/she will be given “S and BP Certified ISO 27005 Risk Manager” credential. By holding an SandBP Manager Certificate, the participant can be able to demonstrate that he/she has the practical knowledge and professional capabilities to implement ISO 27005 in an organization.
- Introduction To Information Risk Management According To ISO/IEC 27005:2022
- Organization-wide Risk Management
- Risk Management Framework Steps And Structure
- Information Security Risk Management Based on ISO/IEC 27005:2022
- Context Establishment
- Information Security Risk Assessment Process
- Information Security Risk Treatment Process
- Operation
- Leveraging Related ISMS Processes
- Certification Exam
- PREREQUISITE: Basic knowledge of ISO/IEC 27001 and ISO/IEC 27002, as well as an understanding of the key principles of ISMS.
Terms of Certification
Candidates who score 70% and above in the examination will be issued an SANDBP certificate.
In case you do not meet the pass mark, you can retake the exam for FREE after the first attempt while subsequent retakes would come at a cost.
Criteria for Suspending and Withdrawing the Scope of Certification
SANDBP reserves the right to suspend or revoke certifications for reasons including fraud, deceit, or submission of inaccurate data.
Process:
Certificate holders will be notified by certified mail if evidence of charges is found.
They may present their defense in writing to the certification board.
The board will review the case and decide to uphold or deny the suspension/revocation.
Causes for Suspension/Withdrawal:
Improper use of certificates/logos
Malpractices
Providing false information
Ineligibility for applied examinations
Voluntary suspension requests
Recertification Process
Recertification ensures that certified individuals maintain their knowledge and skills in line with the latest standards and practices. It is a critical process that reaffirms the competency of certified professionals, allowing them to stay current with evolving industry standards.
Criteria for Recertification:
Transition Exam:
- Individuals must take and pass a transition exam when there is a change in the current version of the certification standard.
- The transition exam focuses on the updates and changes in the new version of the standard, ensuring that certified individuals are knowledgeable about the latest requirements and practices.
Adherence to Code of Ethics:
Certified individuals must adhere to a code of ethics, demonstrating professionalism and integrity in their practice. Any violations of the code of ethics may result in the suspension or revocation of certification
Payment of Recertification Fees:
Payment of the required recertification fees is necessary to process and validate the renewal of certification.
Introduction
To maintain the integrity and fairness of our examinations, specific guidelines have been established for proctoring. These rules apply to all candidates and must be adhered to strictly. Failure to comply may result in disqualification or other disciplinary actions.
General Requirements
Technology Setup
- Device: Use a desktop or laptop with a working webcam and microphone. Mobile phones or tablets are not permitted unless explicitly allowed.
- Internet: Ensure a stable internet connection with sufficient bandwidth to stream video and audio continuously.
- Browser: Use the designated browser as specified by the exam platform.
- Power Backup: Ensure your device is fully charged and/or connected to a reliable power source.
Environmental Setup
- Location: Choose a quiet, well-lit room with minimal distractions.
- Background: Ensure the background is plain and free of any clutter or distractions.
- Privacy: No other person is allowed in the room during the examination.
Pre-Exam Procedures
Present a valid government-issued photo ID or institution-approved identification document. Ensure that no unauthorized materials (e.g., books, notes, or electronic devices) are present.
During the Exam
Behavior Guideline
- Focus on the Screen: Avoid looking away from the screen for extended periods.
- No Assistance: You are prohibited from receiving help from anyone or any external resource.
Prohibited Items
- Electronic devices such as mobile phones, tablets, smartwatches, and earphones.
- Books, notes, or any other study material unless explicitly permitted.
Proctor Interaction
- Follow all instructions given by the proctor.
- If contacted for clarification or rule enforcement, respond promptly and cooperatively.
- Inform the proctor immediately in case of technical issues.
Post-Exam Procedures
Submission
- Ensure your exam responses are submitted within the designated time.
- Do not close the exam window or disconnect until you receive confirmation that your submission is successful.
Feedback
- Report any technical issues or concerns to the designated support team immediately aƜer the exam.
Violations and Consequences
Examples of Violations
- Using unauthorized materials or devices.
- Attempting to impersonate another candidate.
- Engaging in suspicious behavior (e.g., frequent movement, talking).
- Disconnecting intentionally without justification.
Consequences
- Warnings for minor infractions.
- Disqualification of the exam attempt for major violations.
Support and Troubleshooting
Contact the technical support team in case of any issues with logging in, connectivity, or proctoring tools. (support@sandbp.net)

$33
- Level : Foundation
- Duration: 4-6 Days
- Exam Duration : 2 hours
- Retake Exam: Yes
- Passing Score: 70%

$170
- Level : Manager
- Duration: 4-6 Days
- Exam Duration : 2 hours
- Retake Exam: Yes
- Passing Score: 70%