How much does ISO 27005 Lead Risk Manager training cost in Australia?
$989 + GST, delivered self-paced. The official PECB examination voucher is included with one free retake within 12 months, so there is no separate ISO 27005 exam cost to budget for. Also included: 12 months of myPECB access and the full course materials. All ISO 27005 training through Aegentra Academy is official PECB certification training.
What is on the ISO 27005 Lead Risk Manager exam?
80 multiple-choice questions across 6 competency domains, open book, 3 hours, 70% to pass. The per-domain weighting from PECB’s certification scheme:
- Fundamental principles and concepts of information security risk management — 13 questions (16.25%)
- Implementation of an information security risk management program — 7 questions (8.75%)
- Information security risk assessment — 20 questions (25%)
- Information security risk treatment — 15 questions (18.75%)
- Risk communication, monitoring and improvement — 10 questions (12.5%)
- Information security risk assessment methodologies — 15 questions (18.75%)
Two of those six domains do not appear on the Risk Manager paper at all: risk communication, monitoring and improvement, and risk assessment methodologies. That is the real difference between the levels, and it is worth reading the next section before choosing.
Source note: these figures come from the current ISO/IEC 27005:2022 certification scheme. PECB’s older candidate handbooks still describe the 2008 edition and a 12-question essay paper — two editions stale, and a common source of wrong information about this exam.
Risk Manager or Lead Risk Manager — which should you take?
The deciding question is whether you run assessments or own the method.
Take Risk Manager if your job is to carry out information security risk assessments within a framework somebody else defined — identify the assets, score likelihood and consequence, propose treatment. Four domains, 60 questions, two hours, $849 + GST.
Take Lead Risk Manager if you own the programme: setting the risk criteria before anything is assessed, choosing between assessment methodologies and defending that choice, reporting risk to a board or an audit committee, and running the monitoring and improvement cycle. Six domains, 80 questions, three hours, $989 + GST.
The credential ladders differ too. This exam awards Provisional Risk Manager with no experience required, then Lead Risk Manager at five years with two in information security management and 300 hours of activity, then Senior Lead Risk Manager at ten years with seven and 1,000 hours.
ISO 27005 vs ISO 27001 at lead level — who owns the risk method?
ISO 27001 is the certifiable management system; ISO 27005 is the risk methodology inside it. Clause 6.1.2 of ISO 27001 requires a defined information security risk assessment process without prescribing one, and ISO/IEC 27005:2022 is the standard that fills the gap.
At lead level the distinction matters commercially. An ISO 27001 certification auditor will test whether your risk criteria were defined before assessment, whether the method was applied consistently, and whether residual risk was accepted by someone with the authority to accept it. Those are Lead Risk Manager responsibilities, and they are where ISO 27001 audits most often produce findings.
ISO 27005 itself is not certifiable for an organisation — no Stage 1 / Stage 2 audit, no company certificate. Only individuals hold the credential. Alongside it, ISO 31000 is the generic enterprise framework; most organisations run ISO 31000 as the umbrella and ISO 27005 for information security specifically.
What are the ISO 27005 risk assessment methodologies?
An entire exam domain — 15 of the 80 questions — covers this, and it is the part Risk Manager does not touch. The 2022 edition is deliberate about there being more than one defensible approach.
The choice runs along two axes. Event-based versus asset-based: an asset-based assessment starts from what you hold and works outward to threats and vulnerabilities; an event-based one starts from scenarios that would hurt and works back. Asset-based is thorough and slow; event-based is faster and better at catching risks that cross system boundaries. Qualitative versus quantitative: scales and judgement, or modelled loss values. Most Australian organisations run qualitative with calibrated scales, because the data for genuine quantification rarely exists.
What a lead is expected to do is choose deliberately, document why, and apply it consistently — not to pick the most sophisticated option. An auditor tests consistency, not sophistication.
Free information security risk documents
The two artefacts a lead actually owns, published in full and free — no email required.
If your organisation needs the ISMS built rather than a person trained, that is our governance and risk practice.