Develop information-security risk assessment and treatment skills, including how to compare assessment approaches. Aegentra offers this PECB course online from NZ$1,050.00 for Self-Study, with official materials, an exam attempt and one included retake under PECB’s rules.
Enrolment for this course is arranged by email. Confirm the package and total before payment; this page does not provide instant checkout.
Self-Study
Official slide-based learning for independent study. Read, work through the exercises and revisit the material at your own pace.
NZ$1,050.00per learner · NZD
Official PECB materials
First exam attempt and one free retake
Certificate/certification application fee
Prices are per learner in NZD. Australian billing addresses attract 10% GST; no GST is added for other billing countries. Confirm the total and package before paying.
Recorded PECB learning alongside official course materials. Choose video-led explanation without committing to a scheduled live class.
NZ$1,177.99per learner · NZD
Official PECB materials
First exam attempt and one free retake
Certificate/certification application fee
Prices are per learner in NZD. Australian billing addresses attract 10% GST; no GST is added for other billing countries. Confirm the total and package before paying.
Confirm the course-material access period, exam language, applicable edition and booking terms before payment. The exam deadline is not the same as material access. Mandatory consumer rights are not excluded. PECB’s current general policy includes the first exam attempt, one free retake and the certification application in partner training fees. For Self-Study and eLearning, it states that the bundled cycle must be completed within 12 months of purchase; a first retake requires a minimum 15-day wait after a failed attempt. Check your voucher dates before scheduling. This is not a promise of 12 months of course-material or lab access.
Who this course suits best
Choose for the responsibility.
Information-security risk owners
Develop information-security risk assessment and treatment skills, including how to compare assessment approaches.
GRC and ISMS practitioners
Use the scenario to explain a reasoned approach. Identify what you know, what you would check next and the limits of your authority before taking action.
Security advisers
Use this pathway to connect your existing work with the course’s concepts. Review the prerequisites and credential requirements before selecting a professional level.
Before you enrol
Discuss your information-security and risk-management background with us before enrolment; the reviewed course page does not state a separate prerequisite.
Use the scenario to explain a reasoned approach. Identify what you know, what you would check next and the limits of your authority before taking action.
Learning focus
Develop information-security risk assessment and treatment skills, including how to compare assessment approaches.
Learning area 1
Security risk concepts
Learning area 2
Risk assessment and treatment
Learning area 3
Communication and review
Learning area 4
Comparing assessment methods
Delivery
English · online · self-paced
Starting knowledge
Discuss your information-security and risk-management background with us before enrolment; the reviewed course page does not state a separate prerequisite.
CPD
21 credits on PECB course completion; not a guaranteed study duration
Examination
2 hours; multiple choice; open book; 60 questions
These areas summarise the official PECB course outline. Classroom-day headings describe a syllabus, not a fixed completion time for self-paced study.
Examination and certification
Know the assessment before booking.
PECB English exam register — checked 11 October 2026
Duration
2 hours
Assessment type
Multiple Choice
Questions or tasks
60
Book rules
Open Book
Online availability
Listed by PECB; scheduling and technical requirements apply
Passing the examination does not automatically award the full professional credential named by the course. PECB assesses the applicable application, experience and activity requirements, including any available Provisional tier. Review the course-specific credential table before enrolling; the title is not a promise that you already meet its requirements.
Read the applicable PECB maintenance rules as well as the entry requirements. Professional experience, activity evidence, CPD and maintenance fees are course- and tier-dependent; do not assume another course’s conditions apply.
Original fictional learning example. Not a client case study, official exam question, legal advice or a completed implementation.
Information-security risk in practice
A critical service relies on a small supplier with privileged access. A questionnaire gives the supplier a reassuring score, but the service team cannot explain the consequences of an account compromise.
Identify the service objective and a concrete loss scenario.
Distinguish evidence about likelihood from assumptions about impact.
Compare treatments, residual risk and the authority to accept it.
How should I use this exercise?
Use the scenario to explain a reasoned approach. Identify what you know, what you would check next and the limits of your authority before taking action. Write down your assumptions and the evidence you would need before reaching a conclusion. Nothing is submitted, stored or graded.
For New Zealand organisations
Apply the learning in context.
The NCSC’s critical controls are a useful New Zealand security reference when considering treatments. A control checklist and a risk assessment serve different purposes: use the organisation’s context and consequences to explain priorities.
Context reference: NCSC — critical controls. This source does not endorse Aegentra or this course.
Lead an information security risk programme: establish the framework, apply risk assessment and treatment, and organise communication and consultation.
Self-Study NZ$1,230.00
Foundation builds familiarity; implementation and audit pathways develop different responsibilities. Review the prerequisites of each course rather than assuming one is required before another. Browse every Academy course.
Before you decide
Your questions, answered.
How much is ISO/IEC 27005 Risk Manager in New Zealand?+
Self-Study is NZ$1,050.00; PECB eLearning is NZ$1,177.99 per learner. Prices are per learner in NZD. Australian billing addresses attract 10% GST; no GST is added for other billing countries. Confirm the total and package before paying. Enrolment for this course is arranged with Aegentra by email; the page does not provide an instant online checkout. Your enquiry should identify the format and any edition or access requirements.
What is included in the course package?+
The advertised package includes official PECB learning materials, the first exam attempt, one free retake and the certificate or certification application fee. Recorded eLearning is included only when that format is selected. Confirm access periods and the applicable issuer terms before payment; Aegentra Labs and consulting services are not included.
Who should choose ISO/IEC 27005 Risk Manager?+
Develop information-security risk assessment and treatment skills, including how to compare assessment approaches. Use the scenario to explain a reasoned approach. Identify what you know, what you would check next and the limits of your authority before taking action. Check the starting knowledge listed on this page and choose according to your responsibilities, not an assumption that a longer title automatically provides a higher credential.
What knowledge do I need before starting?+
Discuss your information-security and risk-management background with us before enrolment; the reviewed course page does not state a separate prerequisite.
What is the English exam format?+
PECB’s English exam register lists 2 hours; multiple choice; open book; 60 questions. Online availability is listed. Check the current handbook and exam instructions for permitted resources, identity checks, technical requirements and scheduling. We do not infer a pass mark from another course or promise an exam result.
Is this a live online class?+
No. This page offers Self-Study and PECB eLearning for self-paced online learning. Recorded eLearning is not a scheduled class or a personal instructor session. No live-class or consultancy package is included for this course.
Does passing the exam automatically award the credential?+
Passing the examination does not automatically award the full professional credential named by the course. PECB assesses the applicable application, experience and activity requirements, including any available Provisional tier. Review the course-specific credential table before enrolling; the title is not a promise that you already meet its requirements.
How does the included exam retake work?+
PECB’s current general policy includes the first exam attempt, one free retake and the certification application in partner training fees. For Self-Study and eLearning, it states that the bundled cycle must be completed within 12 months of purchase; a first retake requires a minimum 15-day wait after a failed attempt. Check your voucher dates before scheduling. This is not a promise of 12 months of course-material or lab access.
How is ISO 27005 different from ISO 31000?+
ISO/IEC 27005 focuses on information-security risk. ISO 31000 provides general risk-management guidance across organisational objectives. Choose the security-specific pathway if your work centres on information assets, threat scenarios and security treatments; choose the broader pathway when you manage several categories of enterprise risk.
Check the details
Issuer sources and enrolment support.
Course and exam facts checked . These links let you check the current issuer position; this is not a claim that an individual trainer reviewed this page.