GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.

← Certifications & Training

Risk Management

ISO 31000 sets the organization-wide discipline of risk management; ISO/IEC 27005 applies that same discipline specifically to information security, in direct support of an ISO/IEC 27001 ISMS; EBIOS Risk Manager adds a scenario-based method, widely recognized across Europe, for building risk assessments regulators and partners can follow step by step. Together they answer a question no organization can dodge indefinitely: not just “what are our risks,” but “can you show us the method behind that answer.”

Why this matters for your organization

Board & executive leadership

Risk appetite and risk tolerance are board-level decisions. A documented, standards-based risk management framework is what lets a board make that decision deliberately, instead of inheriting it by default from whatever the organization happened to already be doing.

Risk, compliance & data protection functions

Risk managers and compliance officers are the ones who must translate risk appetite into a working process — ISO 31000 and ISO/IEC 27005 give that process a recognized structure, and EBIOS Risk Manager gives it a scenario-based method that stands up to external scrutiny.

Operational & technical specialists

For the specialists building risk registers and running assessments, a shared methodology means results that are comparable across projects and defensible when questioned — instead of judgment calls that vary by author.

Certifications offered

ISO 31000 — Risk Management

The reference framework for establishing and operating risk management at organizational level, independent of any specific domain.

  • ISO 31000 Foundation (2 days) — fundamental concepts and principles of risk management.
  • ISO 31000 Risk Manager (4 days incl. exam) — establish, implement and improve a risk management framework and process.

ISO/IEC 27005 — Information Security Risk Management

Risk management applied specifically to information security, complementary to ISO/IEC 27001.

  • ISO/IEC 27005 Foundation (2 days) — fundamental concepts of information security risk management.
  • ISO/IEC 27005 Risk Manager (3 days incl. exam) — establish and operate an information security risk management framework, including alternative methodologies.

EBIOS Risk Manager

A structured, scenario-based risk assessment method, recognized across Europe and complementary to ISO/IEC 27001.

  • EBIOS Risk Manager (3 days incl. exam) — conduct a full EBIOS risk study, from scope and security baseline to strategic and operational risk scenarios.

Contact us for upcoming session dates →

← Back to Certifications & Training