Learning objectives
- Understand the structure and requirements of the ISO/IEC 27001 standard.
- Design and run an Information Security Management System (ISMS).
- Conduct a risk analysis (EBIOS Risk Manager method).
- Prepare a certification process.
Programme
- Regulatory framework: ISO 27001, 27002 and the 2700x family.
- ISMS scope, context and stakeholders.
- Risk assessment and treatment (EBIOS RM).
- Statement of Applicability and security controls (Annex A).
- Indicators, internal audits and management review.
- Continuous improvement and preparing for the certification audit.