Information Security
ISO/IEC 27001 Training: understanding and applying the standard
A practical course on the requirements of ISO/IEC 27001 and what they mean for setting up, maintaining and improving an information security management system.
Request this courseAt a glance
- Subject
- ISO/IEC 27001:2022 and the ISMS
- Suited to
- Anyone who sets up, manages or supports an ISMS
- Completion
- With or without an exam, depending on the variant
- Format
- Online, classroom or in-company
About this course
ISO/IEC 27001 is the international standard for information security management systems (ISMS). This course covers the requirements of the standard and translates them into the choices an organisation makes in practice: from scope and risk assessment to controls, internal audit and improvement.
The emphasis is on understanding and application. You learn not only what the standard asks, but also how to meet those requirements in a way that fits the size and way of working of your organisation.
Courses are delivered by experienced professionals with relevant subject expertise and, where applicable, through specialised training partners.
Who it is for
Information security professionals, security officers and CISOs
Compliance, risk and quality managers
IT managers and project leaders preparing an ISO/IEC 27001 programme
Staff taking on a role in the ISMS or in internal audits
Consultants guiding organisations towards certification
What you will learn
Explain the structure of ISO/IEC 27001 and how clauses 4 to 10 fit together
Determine the context, scope and interested parties of an ISMS
Set up a risk assessment and risk treatment in line with the standard
Select Annex A controls and justify them in a Statement of Applicability
Organise roles, documentation and documented information
Organise monitoring, internal audit, management review and continual improvement
Programme
Information security and the ISMS
- Why an information security management system
- How it relates to ISO/IEC 27002 and other standards
- The certification process in outline
The requirements of ISO/IEC 27001
- Context of the organisation and scope
- Leadership, policy and roles
- Planning: objectives, risks and opportunities
Risk assessment and risk treatment
- Choosing a method and criteria
- Identifying, analysing and evaluating risks
- Drawing up a risk treatment plan
Annex A and the Statement of Applicability
- The 93 controls in four themes
- Selecting and justifying controls
- Connecting to existing processes
Operating, measuring and improving
- Documentation and documented information
- Monitoring and measurement
- Internal audit and management review
- Nonconformities, corrective action and improvement
Format
Online
Live remote sessions, with room for questions and exercises.
Classroom
Together in a training room, with the trainer and other participants.
In-company
A closed course for your team, at your premises or online.
Depending on the course, schedule and group size, training can be organised online, in a classroom or as a closed in-company course.
The content can be matched to the level of the group: as an introduction for those starting with ISO/IEC 27001, or in more depth for those already working with an ISMS.
Exam and certification
This course can be offered with or without a final exam.
Whether an exam is included, which organisation issues the certificate and what conditions apply depends on the chosen variant and training partner. This is stated in the offer.
On completion you receive a certificate of attendance. In a variant with an exam, you receive a certificate from the examining or certifying organisation once you pass.
In-company training
For teams, this course can be organised as a closed in-company course. The content can then be tailored to your organisation, for example with examples from your own risk assessment or policies.
A closed course is also a good start to an ISO/IEC 27001 programme: the whole team begins with the same knowledge.
Frequently asked questions
Do I need prior knowledge?
Usually no specific prior knowledge is required. Experience with information security, IT or quality management does help to apply the material to your own practice. We agree the exact entry requirements with you per variant.
Is there an exam?
That depends on the variant. The course can be offered with or without an exam; the offer states which examining or certifying organisation is involved.
Can the course take place at our premises?
Yes. For groups, the course can be organised as a closed in-company course: at your premises, at an external venue or online.
How does it differ from the Lead Auditor course?
This course focuses on understanding and applying the standard. The ISO/IEC 27001 Lead Auditor course focuses on planning, conducting and leading audits of an ISMS.
Discuss your training needs
Tell us which course you are looking for, for whom and in what period. You will receive a tailored proposal.
Request a proposal