Curriculum traceability
ISO/IEC 27005 (Information Security Risk Management)
This matrix shows how each curriculum area maps to ISO/IEC 27005 (Information Security Risk Management)requirements — the clause or control it supports, how it's taught, and the evidence the learner and organisation receive. It's a sample, illustrative mapping; your live records (completions, assessment scores, version history) form the per-organisation evidence pack.
What this supports — and what it doesn't
These programs support preparation for ISO/IEC 27005 (Information Security Risk Management) certification: they deliver the awareness and competence training the standard requires (notably Clause 7.2 Competence, 7.3 Awareness, and Annex A 6.3) and produce the documented completion and assessment records auditors look for. They do notby themselves certify your organisation or any individual, and they don't guarantee certification — your organisation still implements the management system and is audited by an accredited certification body. Training is the supporting evidence, not the certificate.
Information Security Risk & Incident Management (ISO 27005 + 27035)
| Curriculum area | ISO/IEC clauses / controls | Method | Evidence produced |
|---|---|---|---|
| 27005 Foundations & Methodology | 27005:2022 | Lesson + KC | Completion + score |
| 27005 Process | 27005 cl. 7-8 | Lesson + KC | Completion + score |
Hover a clause code for its title. Clause references follow ISO/IEC 27005 (Information Security Risk Management). For a per-organisation, audit-ready evidence pack, get in touch.