Quality & Management Systems
ISO 27001 Information Security Foundations
Understand the information security management system and its controls, and build a realistic implementation plan.
Foundation2 days12 training hours6-20 participants
All training programmes are accredited by the Sharjah Private Education Authority.
Programme objectives
- Explain the ISMS structure and its requirements
- Run an information risk assessment and identify assets
- Select appropriate Annex A controls
- Prepare the statement of applicability
Detailed agenda
1
Day 1
The system and the risk
- The CIA triad: confidentiality, integrity, availability
- The standard's structure and requirements
- Identifying and classifying information assets
- The risk assessment methodology
2
Day 2
Controls and implementation
- Annex A controls and their domains
- Selecting controls and justifying exclusions
- The statement of applicability
- An implementation roadmap through to audit
Competencies developed
- Information risk management
- Compliance
- Asset classification
- Documentation
What participants take away
- An information asset register
- A risk assessment instrument
- A statement of applicability template
- A company-issued certificate of attendance
Prerequisites
General familiarity with the organisation's information systems.
How it is assessed
An information risk assessment exercise on a real asset, selecting the appropriate controls.
Related programmes
Advanced
ISO 9001 Internal Auditor
Qualify internal auditors who run effective audits and write reports that stand up to challenge.
3 days999 AEDPractitionerEnterprise Risk Management (ISO 31000)
Build a living risk register that gets reviewed and used in decisions — not a table filled in once a year.
3 days699 AEDAdvancedBusiness Continuity (ISO 22301)
Business impact analysis and continuity plans that are actually exercised, not merely filed.
3 days999 AED