Enterprise Security Risk Management for Cybersecurity Managers: From Assessment to Governance with ISO/IEC 27005
1h 47mBeginner2025-09-25
Authors

Marc Menninger
Cybersecurity Director
Course details
In today’s threat landscape, cybersecurity risk management isn’t optional. It’s essential. In this course, cybersecurity director Marc Menninger equips security leaders and GRC professionals with the skills to build and maintain a risk management program based on the ISO 27005 framework. Learn how to identify, analyze, and treat cyber risks in alignment with business objectives, and how to communicate those risks effectively to executives. Explore practical examples and challenge-based exercises to gain hands-on experience applying the ISO 27005 lifecycle to real-world scenarios. Plus, dive into third-party risk management, software supply chain threats, and techniques for continual improvement. When you complete this course, you’ll be ready to lead with confidence and integrate cybersecurity risk into your organization’s enterprise risk strategy.
Learning objectives
Explain the purpose of enterprise risk management (ERM) and how cybersecurity fits into a broader risk management framework.
Apply the ISO 27005 risk management lifecycle to identify, analyze, evaluate, and treat cybersecurity risks.
Develop and maintain a cybersecurity risk register that aligns with business objectives and supports audit readiness.
Communicate cybersecurity risks effectively to stakeholders using risk matrices, dashboards, and executive reporting.
Integrate third-party and software supply chain risks into your risk management program and map them to enterprise-level concerns.
Learning objectives
Explain the purpose of enterprise risk management (ERM) and how cybersecurity fits into a broader risk management framework.
Apply the ISO 27005 risk management lifecycle to identify, analyze, evaluate, and treat cybersecurity risks.
Develop and maintain a cybersecurity risk register that aligns with business objectives and supports audit readiness.
Communicate cybersecurity risks effectively to stakeholders using risk matrices, dashboards, and executive reporting.
Integrate third-party and software supply chain risks into your risk management program and map them to enterprise-level concerns.
Concepts
Introduction
- Why enterprise risk management (ERM) matters for security leaders
Understanding Enterprise Risk Management (ERM)
- ERM vs. cybersecurity risk management
- Breaking down ERM risk types
- Connecting cyber risk to business risk
- Challenge - Match the cyber risk to the ERM risk type
- Solution - Match the cyber risk to the ERM risk type
ISO IEC 27005 Overview and Terminology
- Manage cybersecurity risk with ISO IEC 27005
- ISO IEC 27005 lifecycle overview
- Risk concepts and terms
- Challenge - Match the risk term to its meaning
- Solution - Match the risk term to its meaning
Establish the Context
- Understanding the organization and setting risk boundaries
- Identifying stakeholders and their risk requirements
- Defining risk criteria and acceptance levels
- Challenge - Determine risk appetite
- Solution - Determine risk appetite
Identify the Risk
- Event-based risk identification
- Asset-based risk identification
- Control-based risk identification
- Challenge - Find the risk from a missing control
- Solution - Find the risk from a missing control
- Assigning risk ownership
Analyze and Evaluate the Risk
- Qualitative vs. quantitative risk assessment
- Determining likelihood and impact
- Prioritizing risks and building a risk matrix
- Challenge - Estimate likelihood and impact
- Solution - Estimate likelihood and impact
Treat the Risk
- Reduce, accept, avoid, or transfer the risk
- Choosing controls to reduce risk
- Building a risk treatment plan
- Accepting residual risks
- Challenge - Identify controls to reduce this risk
- Solution - Identify controls to reduce this risk
Communicate and Report the Risk
- Tracking risks using a risk register
- Reporting risk to the board and executives
- Using visuals - Heat maps, graphs, and scorecards
- Challenge - Rephrase this risk for executives
- Solution - Rephrase this risk for executives
Third-Party Risk Management
- Why third parties are some of your biggest risks
- Reducing cyber risk in third-party relationships
- Understanding software supply chain risks
- Challenge - How would you handle this risky vendor
- Solution - How would you handle this risky vendor
Monitoring, Review, and Continual Improvement
- Keeping risk assessments up-to-date
- Conducting management reviews
- Corrective action and continual improvement
- Challenge - What would you cover in a risk management review
- Solution - What would you cover in a risk management review
Conclusion
- Turning risk awareness into action