ISO 27001:2022 - Foundation: Information Security Management System
Business Organisation & TransformationDescription
Introduction
This training enables managers, information security coordinators and process owners to understand the fundamentals of ISO/IEC 27001:2022 and the management system approach to information security. The course focuses on the key principles, requirements and practical steps needed to establish, implement, maintain and continually improve an Information Security Management System (ISMS).
Objectives
By the end of the training, participants will be able to:
Understand the purpose and benefits of an Information Security Management System (ISMS)
Explain the main concepts, principles and requirements of ISO/IEC 27001:2022
Identify the role of risk assessment, risk treatment and Annex A controls
Plan the first steps for implementing and improving an ISMS
Programme
Key concepts: information security, confidentiality, integrity, availability, ISMS, risk, threat, vulnerability, control, documented information and continual improvement
Scope and context of the organisation
Interested parties and information security requirements
Information security policy, objectives and roles
Documented information and records
Implementation of ISO/IEC 27001:2022 – Information Security Management System
Planning
Information security objectives and priorities
Analysis of internal and external issues
Risk assessment and risk treatment plan
Asset identification and information classification
Selection and implementation of Annex A controls
Statement of Applicability
Incident management and business continuity considerations
Awareness, communication and competence
Control of internal and external documented information
Monitoring, evaluation and improvement of the ISMS
Performance indicators and monitoring
Internal audit
Management review
Continual improvement
Nonconformity and corrective actions
Improvement action plan
Preparation for certification pathway
Target audience
ISMS managers; information security coordinators; IT managers; risk, compliance or process managers; designated workers involved in information security activities.
Conditions
Support de cours
-
Des supports de cours seront disponibles après les modules respectifs
-
Die Kursunterlagen werden nach den jeweiligen Modulen zur Verfügung gestellt
-
Course materials will be made available after the respective modules
Certificate
At the end of the training course, participants will be able to download a certificate of attendance issued by the House of Training from the Learner Portal.
Location
L-1615 Luxembourg
Luxembourg