Information Security skills are in high demand. The Information Security Risk Management Foundation (ISO/IEC 27005) is an entry-level certification intended for IT professionals seeking to validate their knowledge of Information Security Risk Management. The Information Security Risk Management Foundation (ISO/IEC 27005) certification exam is based on ISO/IEC 27005:2018 Information technology - Security techniques - Information security risk management standard.
This exam includes topics such as terms and definitions commonly used in the ISMS family of standards, the information security risk management process, information security risk assessment (risk identification (identification of assets, threats, existing controls, vulnerabilities and consequences), risk analysis, risk evaluation, information security risk treatment (risk modification, risk retention, risk avoidance and risk sharing), information security risk acceptance, information risk communication and consultation and information security risk monitoring and review.
The Information Security Risk Management Foundation (ISO/IEC 27005) certification exam is an online, closed-book, and remotely-proctored exam. It includes 40 multiple-choice questions and the passing score is 70%. You will have 60 minutes to complete the exam. Validate your knowledge of Information Security Risk Management and advance your career. Register for your online exam now!
Exam code |
ITC-012 |
Launch date |
January 20, 2017 |
Exam description |
The Information Security Risk Management Foudation (ISO/IEC 27005) exam tests the candidate knowledge in Information Security Risk Management. |
Current version |
v2 (July 24, 2020) |
Exam format |
Multiple choice; computer-based; closed book |
Number of questions |
40 questions |
Passing score |
70% (28 out of 40) |
Exam duration |
60 minutes |
Level |
Foundation |
Languages |
English and Portuguese (Brazilian) |
Exam description |
Terms and definitions, the information security risk management process, information security risk assessment (risk identification (identification of assets, threats, existing controls, vulnerabilities and consequences), risk analysis, risk evaluation, information security risk treatment (risk modification, risk retention, risk avoidance and risk sharing), information security risk acceptance, information risk communication and consultation and information security risk monitoring and review. |
RECOMMENDED HOURS OF STUDY |
16 hours |
Bloom's Taxonomy |
Level 1 (Remembering), Level 2 (Understanding) and Level 3 (Applying) |
Recommended reading |
• ISO/IEC 27005:2018 Information technology - Security techniques - Information security risk management |
Prerequisites |
There are no prerequisites for this certification |
Recommended experience |
Six months of work experience in Information Security Risk Management |
Validity period |
Lifetime |
Domains | Weight |
---|---|
1. The scope of ISO/IEC 27005 |
5% |
2. Terms and definitions |
15% |
3. Context establishment |
10% |
4. Information security risk assessment |
20% |
5. Information security risk treatment |
20% |
6. Information security risk acceptance |
10% |
7. Information Security risk communication and consultation |
10% |
8. Information Security Risk monitoring and review |
10% |
Total | 100% |
Browse our certification programs and choose your certification.
Discover the exam objectives and prepare for your exam.
Register for your online proctored exam.
Take your online proctored exam in the comfort of your home or office.
Congratulations! You are certified!
Earn 4 certifications and receive an integrator certification (designation).
All exams are available for $120 USD each. Prices may vary slightly by region and currency exchange rates.
There are no prerequisites to take the exams. Itcerts recommends that candidates have at least six months of work experience in the area that the certification covers.
If a candidate does not achieve a passing score on the first attempt, there is no waiting period between the first and the second attempt. If a candidate does not achieve a passing score on the second attempt, the candidate must wait at least 7 days before retaking the exam for a third time. A candidate may not take a given exam any more than three times per year (12 months).
Visit the Online Proctored Exam registration page to find complete instructions.
Training is recommended as part of your certification preparation, but it is not mandatory.
Our exams are currently available in English and Portuguese (Brazilian).
Exams are delivered online (Online Proctored Exams) and can be taken from anywhere in the world.
Itcerts certifications are considered good-for-life and do not expire.
Your employer can verify your certification on our certification verification page. Your certification number will be needed in order to process the verification.
Subscribe to our newsletter