Skip to content

Information Security

ISO/IEC 27001 Training: understanding and applying the standard

A practical course on the requirements of ISO/IEC 27001 and what they mean for setting up, maintaining and improving an information security management system.

Request this course

At a glance

Subject
ISO/IEC 27001:2022 and the ISMS
Suited to
Anyone who sets up, manages or supports an ISMS
Completion
With or without an exam, depending on the variant
Format
Online, classroom or in-company

About this course

ISO/IEC 27001 is the international standard for information security management systems (ISMS). This course covers the requirements of the standard and translates them into the choices an organisation makes in practice: from scope and risk assessment to controls, internal audit and improvement.

The emphasis is on understanding and application. You learn not only what the standard asks, but also how to meet those requirements in a way that fits the size and way of working of your organisation.

Courses are delivered by experienced professionals with relevant subject expertise and, where applicable, through specialised training partners.

Who it is for

  • Information security professionals, security officers and CISOs

  • Compliance, risk and quality managers

  • IT managers and project leaders preparing an ISO/IEC 27001 programme

  • Staff taking on a role in the ISMS or in internal audits

  • Consultants guiding organisations towards certification

What you will learn

  • Explain the structure of ISO/IEC 27001 and how clauses 4 to 10 fit together

  • Determine the context, scope and interested parties of an ISMS

  • Set up a risk assessment and risk treatment in line with the standard

  • Select Annex A controls and justify them in a Statement of Applicability

  • Organise roles, documentation and documented information

  • Organise monitoring, internal audit, management review and continual improvement

Programme

  1. Information security and the ISMS

    • Why an information security management system
    • How it relates to ISO/IEC 27002 and other standards
    • The certification process in outline
  2. The requirements of ISO/IEC 27001

    • Context of the organisation and scope
    • Leadership, policy and roles
    • Planning: objectives, risks and opportunities
  3. Risk assessment and risk treatment

    • Choosing a method and criteria
    • Identifying, analysing and evaluating risks
    • Drawing up a risk treatment plan
  4. Annex A and the Statement of Applicability

    • The 93 controls in four themes
    • Selecting and justifying controls
    • Connecting to existing processes
  5. Operating, measuring and improving

    • Documentation and documented information
    • Monitoring and measurement
    • Internal audit and management review
    • Nonconformities, corrective action and improvement

Format

  • Online

    Live remote sessions, with room for questions and exercises.

  • Classroom

    Together in a training room, with the trainer and other participants.

  • In-company

    A closed course for your team, at your premises or online.

Depending on the course, schedule and group size, training can be organised online, in a classroom or as a closed in-company course.

The content can be matched to the level of the group: as an introduction for those starting with ISO/IEC 27001, or in more depth for those already working with an ISMS.

Exam and certification

This course can be offered with or without a final exam.

Whether an exam is included, which organisation issues the certificate and what conditions apply depends on the chosen variant and training partner. This is stated in the offer.

On completion you receive a certificate of attendance. In a variant with an exam, you receive a certificate from the examining or certifying organisation once you pass.

In-company training

For teams, this course can be organised as a closed in-company course. The content can then be tailored to your organisation, for example with examples from your own risk assessment or policies.

A closed course is also a good start to an ISO/IEC 27001 programme: the whole team begins with the same knowledge.

Discuss your training needs →

Frequently asked questions

Do I need prior knowledge?

Usually no specific prior knowledge is required. Experience with information security, IT or quality management does help to apply the material to your own practice. We agree the exact entry requirements with you per variant.

Is there an exam?

That depends on the variant. The course can be offered with or without an exam; the offer states which examining or certifying organisation is involved.

Can the course take place at our premises?

Yes. For groups, the course can be organised as a closed in-company course: at your premises, at an external venue or online.

How does it differ from the Lead Auditor course?

This course focuses on understanding and applying the standard. The ISO/IEC 27001 Lead Auditor course focuses on planning, conducting and leading audits of an ISMS.

Discuss your training needs

Tell us which course you are looking for, for whom and in what period. You will receive a tailored proposal.

Request a proposal