GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.
Risk Management
ISO 31000 sets the organization-wide discipline of risk management; ISO/IEC 27005 applies that same discipline specifically to information security, in direct support of an ISO/IEC 27001 ISMS; EBIOS Risk Manager adds a scenario-based method, widely recognized across Europe, for building risk assessments regulators and partners can follow step by step. Together they answer a question no organization can dodge indefinitely: not just “what are our risks,” but “can you show us the method behind that answer.”
Why this matters for your organization
Board & executive leadership
Risk appetite and risk tolerance are board-level decisions. A documented, standards-based risk management framework is what lets a board make that decision deliberately, instead of inheriting it by default from whatever the organization happened to already be doing.
Risk, compliance & data protection functions
Risk managers and compliance officers are the ones who must translate risk appetite into a working process — ISO 31000 and ISO/IEC 27005 give that process a recognized structure, and EBIOS Risk Manager gives it a scenario-based method that stands up to external scrutiny.
Operational & technical specialists
For the specialists building risk registers and running assessments, a shared methodology means results that are comparable across projects and defensible when questioned — instead of judgment calls that vary by author.
Certifications offered
ISO 31000 — Risk Management
The reference framework for establishing and operating risk management at organizational level, independent of any specific domain.
- ISO 31000 Foundation (2 days) — fundamental concepts and principles of risk management.
- ISO 31000 Risk Manager (4 days incl. exam) — establish, implement and improve a risk management framework and process.
ISO/IEC 27005 — Information Security Risk Management
Risk management applied specifically to information security, complementary to ISO/IEC 27001.
- ISO/IEC 27005 Foundation (2 days) — fundamental concepts of information security risk management.
- ISO/IEC 27005 Risk Manager (3 days incl. exam) — establish and operate an information security risk management framework, including alternative methodologies.
EBIOS Risk Manager
A structured, scenario-based risk assessment method, recognized across Europe and complementary to ISO/IEC 27001.
- EBIOS Risk Manager (3 days incl. exam) — conduct a full EBIOS risk study, from scope and security baseline to strategic and operational risk scenarios.
