Skip to main content

ISO 27005 Certification Australia: A Complete Guide (2026)

Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026

A practical guide to ISO/IEC 27005 — the international standard for information security risk management and the risk engine inside every ISO 27001 ISMS. Covers the two PECB pathways (Risk Manager from $849 + GST, Lead Risk Manager $989 + GST), the open-book exams, real costs, and where the standard sits against APRA CPS 234, the Essential Eight, and SOCI Act risk management programs.

ISO/IEC 27005 is the international standard for information security risk management — the method behind every ISO 27001 risk assessment. In Australia, certification means individual PECB credentials: ISO/IEC 27005 Risk Manager from $849 + GST and Lead Risk Manager at $989 + GST through Aegentra, each with the official exam voucher and one free resit included.

What is ISO/IEC 27005?

ISO/IEC 27005:2022 provides guidance on managing information security risks: establishing context and risk criteria, identifying risks to confidentiality, integrity, and availability, analysing consequence and likelihood, evaluating against the criteria, treating through modification, retention, avoidance, or sharing, and then recording, reporting, monitoring, and reviewing the cycle. The 2022 edition aligns step for step with ISO 27001 clause 6 — the risk assessment and treatment obligations every certified ISMS must satisfy. It is the standard behind the two artefacts auditors examine hardest: the risk register and the Statement of Applicability. See the full ISO 27001 certification guide for the management-system side.

Practitioners are certified, not companies

Like ISO 31000, ISO 27005 is guidance — there is no Stage 1/Stage 2 audit and no organisational certificate. “ISO 27005 certification” in Australia means PECB practitioner credentials: Risk Manager and Lead Risk Manager. The organisational certificate in this domain is ISO 27001, where the ISO 27005-based risk assessment is examined during the Stage 2 audit. For enterprise-wide risk outside information security, the parallel scheme is ISO 31000 — principle-based, cross-domain, and the umbrella framework boards speak; ISO 27005 adds the asset-threat-vulnerability machinery information security requires.

Why ISO 27005 matters in Australia

Australian regulators rarely name ISO 27005, but they consistently require what it produces: a documented, defensible, repeatable information security risk assessment. APRA CPS 234 requires capability commensurate with the size and extent of threats — which presumes a current risk assessment underneath the board attestation. ASD Essential Eight maturity targets and uplift sequencing are risk-prioritisation exercises. SOCI Act Risk Management Programs require captured critical-infrastructure entities to identify and mitigate cyber hazards with a documented method. The Privacy Act's APP 11 “reasonable steps” and the PSPF's authorisation decisions rest on the same foundation.

Who needs it

ISMS implementers and coordinators (the natural companion credential to ISO 27001 Lead Implementer — most Stage 2 findings trace to risk work, not controls), GRC and security risk analysts at APRA-regulated and ASX-listed organisations, ISO 27001 auditors judging whether a methodology is sound and traceable, consultants and vCISOs who inherit a different risk method at every client, and SOCI-captured critical-infrastructure teams.

The two courses and cost

ISO/IEC 27005 Risk Manager — from $849 + GST (Self-Study; eLearning $949 + GST). The practitioner tier: 21–30 hours self-paced (3-day equivalent), 350+ pages of official materials, 21 CPD credits. ISO/IEC 27005 Lead Risk Manager — $989 + GST (Self-Study). The senior tier: 35–45 hours (5-day equivalent), 450+ pages, 31 CPD credits, with the certification application fee and first year of the PECB Annual Maintenance Fee included. Both include 12 months myPECB access, the official exam voucher, and one free resit within 12 months.

The exams

Both exams are open-book, remotely proctored, with a 70% pass mark — sit them from anywhere in Australia. Risk Manager is 2 hours of mixed multiple-choice and scenario-based questions across 4 competency domains. Lead Risk Manager is 3 hours with 80 multiple-choice questions across 6 competency domains; the standard, course materials, and personal notes are permitted. Both course tiers also survey the six established assessment methods — OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA — so you can choose a method rather than inherit one.

Credential tiers and pathway

Credentials issue through PECB's experience-based ladder: Provisional Risk Manager immediately on passing (no experience required), upgrading to Risk Manager, Lead Risk Manager, and Senior grades as attested professional hours accrue. All require signing the PECB Code of Ethics and are maintained through CPD. PECB is accredited by UKAS, IAS and COFRAC under ISO/IEC 17024 and recognised across Australia and internationally. Browse all Aegentra Academy courses.