How much does ISO 27005 training cost in Australia?
The ISO 27005 Risk Manager course is $849 + GST self-paced, or $949 + GST with guided eLearning. There is no separate ISO 27005 exam cost — the official PECB examination voucher is included, along with one free retake within 12 months and 12 months of myPECB access. Aegentra Academy is an official PECB authorised training partner, and prices are quoted in Australian dollars ex-GST.
ISO 27005 vs ISO 27001 — what is the difference?
This is the question most people arrive with, and the answer is simpler than the internet makes it. ISO/IEC 27001 is the certifiable management system. ISO/IEC 27005 is the risk methodology you run inside it. They are not alternatives and you do not choose between them.
ISO 27001 Clause 6.1.2 requires you to define and apply an information security risk assessment process — but it deliberately does not say which one. ISO/IEC 27005:2022 is the guidance that fills that gap: how to identify assets, threats and vulnerabilities, how to analyse likelihood and consequence, how to evaluate against criteria you set in advance, and how to choose between modifying, retaining, avoiding or sharing a risk.
ISO 27005 is not certifiable for an organisation. There is no Stage 1 / Stage 2 audit and no certificate saying a company is “ISO 27005 certified” — it is guidance, not an auditable management system. Individuals are certified, through PECB. Where it does get audited is inside an ISO 27001 assessment: your risk method is evidence for Clause 6.1.2, and an auditor will test whether you actually followed it.
The third standard people ask about is ISO 31000, which is generic enterprise risk management. Most Australian organisations use ISO 31000 as the umbrella framework, ISO 27005 for information security risk specifically, and hold ISO 27001 as the certificate. See the ISO 27005 certification guide for Australia for the full comparison.
What is on the ISO 27005 Risk Manager exam?
60 multiple-choice questions across 4 competency domains, open book, 2 hours, 70% to pass. PECB publishes the per-domain weighting in its certification scheme, which is worth knowing before you study:
- Fundamental principles and concepts of information security risk management — 13 questions (21.7%)
- Implementation of an information security risk management program — 7 questions (11.7%)
- Risk management framework and processes based on ISO/IEC 27005 — 31 questions (51.7%)
- Other information security risk assessment methods — 9 questions (15%)
More than half the paper sits in one domain. If you are short on study time, the framework and process is where it should go.
A caution on sources: PECB’s older candidate handbooks for this standard still describe ISO/IEC 27005:2008 and a 12-question essay exam. That is two editions out of date. The figures above come from the current ISO/IEC 27005:2022 certification scheme. If a provider quotes you an essay exam for ISO 27005, they are republishing the old handbook.
What does the Risk Manager credential qualify you for?
Passing awards PECB Certified ISO/IEC 27005:2022 Risk Manager, or Senior Risk Manager depending on the experience you can attest to. Risk Manager requires two years of professional experience with one year in risk management, plus 200 hours of risk management activity. Note the edition year is part of the credential name — it is 27005:2022, not a generic “ISO 27005” certificate.
Certification runs three years and is maintained through 60 CPD hours per cycle plus the annual maintenance fee. If you will lead the programme rather than run assessments within it, the Lead Risk Manager course covers six domains rather than four and carries the Lead ladder.
Where ISO 27005 fits Australian security obligations
APRA CPS 234 requires regulated entities to classify information assets by criticality and sensitivity and to size controls to the threat — which is an information security risk assessment by another name. The ASD Essential Eight maturity model assumes you know which systems matter most, and that judgement comes from a risk assessment rather than from the model itself.
Neither names ISO 27005. Both assume what it produces: a documented, repeatable method for deciding which information security risks matter and what to do about them. That is why Australian GRC and information security auditor roles ask for risk credentials alongside ISO 27001.
Free ISO 27005 risk assessment templates
The two documents this method actually produces, published in full and free — no email required.