ORYS Group
Home
Expertise
About Case studies Blog Careers
Cybersecurity & Digital Trust

Information systems security & ISO/IEC 27001

Understand the structure and requirements of the ISO/IEC 27001 standard. An intermediate-level course, 3 days (21h).

Learning objectives

  • Understand the structure and requirements of the ISO/IEC 27001 standard.
  • Design and run an Information Security Management System (ISMS).
  • Conduct a risk analysis (EBIOS Risk Manager method).
  • Prepare a certification process.

Programme

  • Regulatory framework: ISO 27001, 27002 and the 2700x family.
  • ISMS scope, context and stakeholders.
  • Risk assessment and treatment (EBIOS RM).
  • Statement of Applicability and security controls (Annex A).
  • Indicators, internal audits and management review.
  • Continuous improvement and preparing for the certification audit.

Who it's for

CISOs, IT managers, security project managers, internal auditors.

Prerequisites

General knowledge of IT and information systems.

Format

Case studies, building a running ISMS example, feedback from experience.

Cybersecurity & Digital Trust

Other courses in this track

See the full catalogue

Interested in this course?

Let's talk about your goals: our teams reply within 48 hours to help build your training plan.