ISO 27001 Foundation
Course Overview:
ISO/IEC 27001:2022 international standard specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. Information being a valuable asset and building block is important to the growth, success and maintaining credibility of any organization. Information needs to be suitably protected like any other important business asset. If this asset is compromised, then the organization may be exposed to various threats including cybersecurity threats, identity theft and risks which may lead to brand image erosion, business disruption, financial and productivity loss etc.
The course will be conducted by our experienced Foundations, who have audited numerous organizations. This intensive course is a pre-requisite in becoming a registered auditor / Foundation. The course is structured to provide the knowledge and skills required to assess the Information Security Management System of an organization in accordance with the requirements of the ISO/IEC 27001:2022 international standard.
This comprehensive five-day course is structured to provide an understanding of ISO/IEC 27001:2022 requirements blended with presentations, case studies, exercises, workshops and role-plays to ensure that the participant thoroughly understands the role of an auditor / Foundation and acquires the expertise needed to perform effective audits.
Why should you attend?
ISO/IEC 27001 Foundation training allows you to learn the basic elements to implement and manage an Information Security Management System as specified in ISO/IEC 27001. During this training course, you will be able to understand the different modules of ISMS, including ISMS policy, procedures, performance measurements, management commitment, internal audit, management review and continual improvement.
After completing this course, you can sit for the exam and apply for the Certificate Holder in ISO/IEC 27001 Foundation” credential. A Foundation Certificate shows that you have understood the fundamental methodologies, requirements, framework and management approach.
Who should attend?
Learning objectives:
Duration:
Full 2 Days (16 Hours)
Course Content:
Domain 1:
Fundamental principles and concepts of an information security management system (ISMS).
Main objective:
Ensure that the candidate understands and is able to interpret the main ISO/IEC 27001 principles and concepts based on ISO/IEC 27001.
Competencies:
- Ability to explain the relation between ISO/IEC 27001 and other ISO standards, such as ISO/IEC 27002 and ISO/IEC 27003
- Ability to distinguish between other ISO management system standards
- Ability to interpret the definition of a management system
- Ability to explain the structure of ISO/IEC 27001
- Ability to identify the main requirements of ISO/IEC 27001 for an ISMS
- Ability to explain the main concepts of information security
- Ability to explain the relationship between information and assets
- Ability to interpret the concept of confidentiality, integrity, and availability of information
- Ability to explain the definition of threat, vulnerability, and information security risk
- Ability to interpret the relationship between information security concepts, such as vulnerability, threat, risk, and impact
- Ability to describe the main characteristics of artificial intelligence and cloud computing
Knowledge statements:
- Knowledge of the main standards of the ISO/IEC 27000 family
- Knowledge of other information security regulations, industry standards, and best practices
- Knowledge of the advantages of implementing an ISMS based on ISO/IEC 27001
- Knowledge of the definition of management system and management system standards
- Knowledge of the structure of ISO/IEC 27001
- Knowledge of the main requirements of ISO/IEC 27001, clauses 4 to 10
- Knowledge of the “Plan-Do-Check-Act” (PDCA) cycle
- Knowledge of the main concepts of information security related to ISO/IEC 27001
- Knowledge of the relationship between information security elements
- Knowledge of the concept of information confidentiality, integrity, and availability
- Knowledge of information security vulnerabilities, threats, and risks
- Knowledge of the main characteristics of artificial intelligence and cloud computing
Domain 2:
Information security management system (ISMS)
Main objective:
Ensure that the candidate is able to identify and interpret the requirements of ISO/IEC 27001 for an ISMS.
Competencies:
- Ability to analyze how ISMS objectives are set
- Ability to analyze the internal and external context of an organization
- Ability to identify the key roles and responsibilities of interested parties regarding the ISMS
- Ability to explain the requirements of ISO/IEC 27001 regarding leadership and commitment of the top management
- Ability to identify different types of policies
- Ability to interpret the development life cycle of an information security policy
- Ability to explain the different activities of the risk management process
- Ability to identify the criteria that should be considered when selecting a risk assessment methodology
- Ability to explain how risks are identified, analyzed, and evaluated
- Ability to interpret the requirements of ISO/IEC 27001 regarding information security risk treatment
- Ability to interpret the requirements of ISO/IEC 27001 regarding competence and awareness
- Ability to identify the resources required for the ISMS implementation
- Ability to interpret the concepts of training, awareness, and communication
- Ability to explain the requirements of ISO/IEC 27001 regarding documented information
- Ability to identify the main processes necessary for the operation of an ISMS
- Ability to interpret the requirements of ISO/IEC 27001 regarding performance evaluation
- Ability to distinguish between different types of audits
- Ability to explain the concept of nonconformity and the corrective action process
- Ability to interpret the requirements of ISO/IEC 27001 regarding management review
- Ability to interpret the requirements of ISO/IEC 27001 regarding continual improvement
Knowledge statements:
- Knowledge of typical ISMS objectives
- Knowledge of what typically constitutes an organization’s internal and external context
- Knowledge of the roles and responsibilities of interested parties relevant to ISMS
- Knowledge of the role of the top management in regards to the ISMS implementation
- Knowledge of different policies, such as high-level general, high-level specific, and topic-specific
- Knowledge of information security policy and its development life cycle
- Knowledge of the processes required to manage information security risks
- Knowledge of the selection of the risk assessment methodology
- Knowledge of risk identification, analysis, and evaluation
- Knowledge of risk treatment options
- Knowledge of the main competence and awareness activities
- Knowledge of resource management during the ISMS implementation process
- Knowledge of training and awareness activities and communication principles
- Knowledge of the types of documented information relevant to the ISMS
- Knowledge of operational planning requirements of ISO/IEC 27001
- Knowledge of the concepts of monitoring, measurement, analysis, and performance evaluation and their differences
- Knowledge of internal and external audits
- Knowledge of nonconformities, action plans, and corrective actions
- Knowledge of management review activities
- Knowledge of the definition and benefits of continual improvement
- Knowledge of the type and function of security controls
- Knowledge of Annex A controls of ISO/IEC 27001