COURSE OBJECTIVE:
After completing this course you should be able to:
• Explain the fundamental concepts and principles of an information security management system (ISMS) based on ISO/IEC 27001
• Interpret the ISO/IEC 27001 requirements for an ISMS from the perspective of an implementer
• Initiate and plan the implementation of an ISMS based on ISO/IEC 27001, by utilizing PECB's IMS2 Methodology and other best practices
• Support an organization in operating, maintaining, and continually improving an ISMS based on ISO/IEC 27001
• Prepare an organization to undergo a third-party certification audit
TARGET AUDIENCE:
Managers or consultants involved in and/or concerned with the implementation of an information security management system in an organization. Project managers, consultants, or expert advisers seeking to master the implementation of an information security management system; or individuals responsible to maintain conformity with the ISMS requirements within an organization. Members of the ISMS team
COURSE PREREQUISITES:
Attendees should have:
• A fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of implementation principles.
COURSE CONTENT:
Day 1: Introduction to ISO/IEC 27001 and initiation of an ISMS implementation
• Training course objectives and structure
• Standards and regulatory frameworks
• Information security management system based on ISO/IEC 27001
• Fundamental concepts and principles of information security
• Initiation of the ISMS implementation
• Understanding the organization and its context
• ISMS scope
Day 2: Implementation plan of an ISMS
• Leadership and project approval
• Organizational structure
• Analysis of the existing system
• Information security policy
• Risk management
• Statement of Applicability
Day 3: Implementation of an ISMS
• Selection and design of controls
• Implementation of controls
• Management of documented information
• Trends and technologies
Day 4: ISMS monitoring, continual improvement, and preparation for the certification audit
• Monitoring, measurement, analysis, and evaluation
• Internal audit
• Management review
• Treatment of nonconformities
• Continual improvement
• Preparation for the certification audit
• Closing of the training course
FOLLOW ON COURSES:
Not available. Please contact.