The ISO/IEC 27005 Information Security Risk Management standard provides guidelines for information security risk management in an organization. The ISO/IEC 27005 Lead Risk Manager is a certification intended for individuals seeking to validate their advanced knowledge of Informtion Security Risk Management in accordance with the ISO/IEC 27005:2022 standard. The ISO/IEC 27005 Lead Risk Manager certification exam is based on the ISO/IEC 27005 Information Security Risk Management standard.
This exam includes topics such as terms and definitions commonly used in the ISO/IEC 27005 standard, Scope, Overview of the information security risk management process, Context establishment, Information security risk assessment (Risk identification, Risk analysis, and Risk evaluation), Information security risk treatment (Risk modification, Risk retention, Risk avoidance, and Risk sharing), Information security risk acceptance, Information security risk communication and consultation, Information security risk monitoring and review, Defining the scope and boundaries of the information security risk management process, Identification and valuation of assets and impact assessment, Examples of typical threats, Vulnerabilities and methods for vulnerability assessment, and Information security risk assessment approaches.
The ISO/IEC 27005 Lead Risk Manager certification exam is an online, closed-book, and remotely-proctored exam. This exam consists of 40 multiple-choice questions. The passing score is 70%. Candidates will have 60 minutes to complete the exam. The exam is available in English and Portuguese. Validate your advanced knowledge of the ISO/IEC 27005:2022 standard and advance your career in Information Security. Register for your online exam now!
Exam code |
ITC-127 |
Launch date |
September 22, 2024 |
Exam description |
The ISO/IEC 27005 Lead Risk Manager exam tests the candidate's advanced knowledge of the ISO/IEC 27005:2022. |
Current version |
v1 (September 22, 2024) |
Exam format |
Multiple choice; computer-based; closed book (online proctored exam) |
Number of questions |
40 questions |
Passing score |
70% (28 out of 40) |
Exam duration |
60 minutes |
Level |
Advanced |
Languages |
English and Portuguese (Brazilian) |
Exam description |
This exam includes topics such as Terms and definitions commonly used in the ISO/IEC 27005 standard, Scope, Overview of the information security risk management process, Context establishment, Information security risk assessment (Risk identification, Risk analysis, and Risk evaluation), Information security risk treatment (Risk modification, Risk retention, Risk avoidance, and Risk sharing), Information security risk acceptance, Information security risk communication and consultation, Information security risk monitoring and review, Defining the scope and boundaries of the information security risk management process, Identification and valuation of assets and impact assessment, Examples of typical threats, Vulnerabilities and methods for vulnerability assessment, and Information security risk assessment approaches. |
RECOMMENDED HOURS OF STUDY |
32 hours |
Bloom's Taxonomy |
Level 2 (Understanding), Level 3 (Applying), Level 4 (Analyzing), and Level 5 (Evaluating) |
Recommended reading |
• ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks |
Prerequisites |
There are no prerequisites for this certification. |
Recommended experience |
Six months of work experience in Information Security Risk Management |
Validity period |
Lifetime |
Browse our certification programs and choose your certification.
Discover the exam objectives and prepare for your exam.
Register for your online proctored exam.
Take your online proctored exam in the comfort of your home or office.
Congratulations! You are certified!
After purchasing an exam voucher, candidates will have 180 days to take the exam.
The exam voucher includes 2 retakes in case the candidate fails the first attempt.
There are no prerequisites to take the exams. ITCERTS recommends that candidates have at least six months of work experience in the area that the certification exam covers.
If a candidate does not achieve a passing score on the first attempt, there is no waiting period between the first and the second attempt. If a candidate does not achieve a passing score on the second attempt, the candidate must wait at least 7 days before retaking the exam for a third time. A candidate may not take a given exam any more than three times per year (12 months).
Visit the Online Proctored Exam registration page to find complete instructions.
Training is recommended as part of your certification preparation, but it is not mandatory.
Our exams are currently available in English and Portuguese.
Exams are delivered online (Online Proctored Exams) and can be taken from anywhere in the world.
ITCERTS certifications are considered good-for-life and do not expire.
Your employer can verify your certification on our certification verification page. Your certification number will be needed in order to process the verification.
Subscribe to our newsletter