Learning objectives
- Explain the structure and requirements of ISO/IEC 27001:2022
- Define the ISMS context, scope and governance
- Connect risk analysis, treatment and controls
- Prepare an implementation and improvement plan
Who should attend
Security, quality, compliance, risk and IT managers, and ISMS project managers.
Prerequisites
No formal prerequisites. General knowledge of information security is useful.
Course outline
- Management system principles and ISMS terminology
- Context, interested parties, scope and leadership
- Planning, objectives, risks and opportunities
- Support, competence, documentation and communication
- Operations, risk analysis and treatment
- Performance evaluation, internal audit and improvement
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: ISO, ISO/IEC 27001:2022 ↗
Introductory programme aligned with the standard. It includes neither a copy of the standard nor a third-party certification exam.
Introductory programme aligned with the standard. It includes neither a copy of the standard nor a third-party certification exam.
