Information Security 27001 Foundation – ISO 27001 training

information security ISO 27001 foundation course, information security training, information security certification, iso 27001 training, iso 27001 certification, live online training

Acquire the fundamental knowledge to establish and operate an Information Security Management System (ISMS) based on ISO/IEC 27001:2022

The Information Security 27001 Foundation course is a course based on ISO/IEC 27001. The course follows a real-world adapted case-study approach so students can be better prepared to apply the concepts of this ISO information security standard in a real-world scenario. This course prepares the students to support the establishment and operation of an ISMS based on ISO/IEC 27001 and provides them the fundamental knowledge on the audit concepts, principles and best practices based on ISO 19011.

Training materials updated with the last released editions of all the related best practices, including any related draft published.

 

This Training Plan and all associated documents are protected by Copyright and registered as a literary work at IGAC – Portugal.


Next GUARANTEED DATES (*)

29-Apr-2024,   Price | Register       05-Jul-2024,   Price | Register       27-Sep-2024,   Price | Register       

 

course evaluation     4.6 in 5

 

Introduction

This course is available to be delivered in a classroom and > Live Online Training <
Live Training brings you the dynamic environment of the classroom, to your desk. Using your computer, you interact with the trainer and the trainees as if you were with them in the classroom. Information Security 27001 Foundation Path
On this course, the students will acquire the fundamental knowledge to establish and operate an Information Security Management System (ISMS) based on the ISO/IEC 27001 standard.

The course covers the fundamental concepts related with information security, an overview clause-by-clause of the ISO/IEC 27001 standard with high-level implementation guidance and discussion-based practical examples to implement the requirements of the standard, and best practices for the implementation of the ISO/IEC 27001 Annex A controls, and/or others applicable according with the ISO/IEC 27002 control catalogue guidance.

As the students advance through the subjects of course, they will be presented with the main supporting standards of the ISO/IEC 27000 family, this includes, but not only, the guidance for information security controls implementation (ISO/IEC 27002), the guidance for implementation of the standard requirements (ISO/IEC 27003), the guidance for performance evaluation (ISO/IEC 27004), and the guidance for information security risk assessment (ISO/IEC 27005). These standards provide guidance to establish, implement, maintain, and continually improve an ISO/IEC 27001 Information Security Management System.

This course also provides an overview of other non-family and Information Security related best practices, legislation, and regulation and, on the last module, it covers an overview of the main concepts, principles, and best practices for auditing an ISMS based on the guidance of ISO 19011.

Training Methodology
This course is based on theorical, and practical sessions supported by a real-world adapted case-study. The course includes hands-on practical and theorical exercises to:
  • better prepare the students for the real-world challenges, and
  • to prepare and increase the likelihood of success on the certification exam, and
  • train and prepare professionals for participating in an ISMS implementation program or ISMS audit based on ISO/IEC 27001
This course is available to be delivered in a > Live Online Training < model and classroom.
Live Training brings you the dynamic environment of the classroom, to your desk. Using your computer, you interact with the trainer and the trainees as if you were with them in the classroom.

Audience
This course is intended to:
  • Information Security and/or IT Consultants, Auditors, Managers or Risk Professionals
  • CISO, CIO, CSO or any Executive or Senior Manager responsible to ensure the alignment and delivery of value from Information Security to the organization
  • Professionals responsible for the Information Security/IT Governance on the organization
  • Any professional, either, IT, information security, business or any other, involved on the establishment, implementation, operations and/or continual improvement of an Information Security Management System (ISMS) based on ISO/IEC 27001
  • Anyone who wants to learn the fundamentals of ISO/IEC 27001

Prerequisites
Students should understand English as the course documentation is in this language.
Also, other requisites may apply, please check the quotation or the proposal received.

Duration (days)
2 days

Learning Objectives
At the end of this course students will be able to:
  • Understand the fundamental information security concepts, and the main requirements and controls of ISO/IEC 27001
  • Get to know and understand the correlation of the ISO/IEC 27000 family standards, including ISO/IEC 27001, ISO/IEC 27002, and related ISO and other best practices, legislation and regulation
  • Support an organization on the implementation and operation of an ISMS based on ISO/IEC 27001, as part of an ISMS implementation team and/or during an implementation project
  • Understand the fundamental audit concepts and principles based on the ISO 19011 standard
  • Understand the several information security related source of requirements to discuss with the peers about relevant subjects to the maintenance and improvement of information security on the organization
  • Support the organization on the achievement and maintenance of the ISO/IEC 27001 certification
  • Acquire the required knowledge to succeed in the “BEHAVIOUR Certified Information Security 27001 Foundation” exam and achieve a personnel certification

Program
  1. Introduction to Information Security, the ISO/IEC 27001 standard and, related best practices
    • Course introduction
    • Information security standards and compliance requirements
    • Advancing for ISO/IEC 27001 Certification
    • Information security fundamentals
    • Presentation and overview of the ISMS requirements (Part 1- Clauses 4 to 6.1)
      • Information security context
      • Leadership and commitment
      • Planning (actions to address risks and opportunities, objectives, and ISMS changes)

  2. ISMS and Audit concepts and principles
    • Presentation and overview of the ISMS requirements (Part 2 - Clauses 6.2 to 10; and Annex A)
      • Planning (objectives and plans to achieve them)
      • Support
      • Operation
      • Performance evaluation
      • Improvement
      • Annex A controls: overview and high-level implementation guidance
    • Introduction to audit concepts and principles based on ISO 19011

Exam
The “Certified Information Security 27001 Foundation” exam covers the following competence domains:
  • Domain 1: Information security fundamentals
  • Domain 2: Information Security Management System ISO/IEC 27001 requirements
  • Domain 3: Fundamental audit concepts and principles based on ISO 19011

Language(s): English and Portuguese (please consult BEHAVIOUR for availability on additional languages).
Duration: 1 hour
Exam type: Multiple-choice questions.
Number of questions: 40 questions
Passing score: 260/400 marks.
Results: “Pass or Fail” quantitative score.
If the candidate fails the exam, he is entitled to one free retake within a 2 month period from the released date of the exam result.

Certification
After successfully completing the certification exam, and signing the agreement/code of ethics, participants will achieve the credentials of Certified Information Security 27001 Foundation.

A certificate will be issued to participants who successfully pass the exam and comply with all the other requirements related to the selected credential. Candidates also receive the digital badge of the certification achieved.

The “Certified Information Security 27001 Foundation” personnel certification program is drafted and maintained according to the ISO/IEC 17024 standard.

The certification programs are only valid to persons (not companies) and the achievement and maintenance depends on the exam result, on the professional experience and the commitment and comply to the agreement/code of ethics. If a professional does not comply with the agreement/code of ethics, the certification is not assigned or is revoked.

(Note: This program does not provide the competencies for a specific function or role, thus, it does not have any personnel certification maintenance requirements).

Trainer
Our specialists are renowned consultants and auditors, with several years of experience in the areas of implementation, auditing and training in family ISO 27000, with particular focus on standards ISO27001, ISO27005 and their associated standards.

General Information
  • Training in English language.
  • Online training material resources in English, with online access, and in accordance with the commercial conditions.
  • Behaviour Digital Participation Certificate of 16 CPD/CPE credits.
  • Online Certification Exam in Portuguese or English language. The exam can be taken up to 2 months from the start date of the course.
  • If the candidate fails the exam, he is entitled to one free retake within a 2 month period from the date of the exam result.
  • Certification Diploma and certification badge after successful examination and formal process registration. This process has no associated cost.

Benefits
  • ISO/IEC 27001 is an auditable Information Security Management System (ISMS).

  • ISO/IEC 27001 allows certification and international recognition of an organization; access to new markets and optimization of operations; and improves quality, increases productivity, competitive advantage, customer satisfaction and sales revenues.

  • Information Security 27001 Foundation course bases its pedagogical model in a certification program based on the ISO/IEC 17024 standard, which defines the requirements for certification of people, fulfilling the recommendations of ISO. (Note: Attention that this program does not provide the competences for a specific function, but it provides the knowledge required to be used by several functions and roles during the implementation and management of an ISMS. Due to this reason, the certification achieved does not have maintenance requirements).

  • Information Security 27001 Foundation course geared towards to the knowledge needed to support an organization in the implementation and operation of an ISMS based on ISO/IEC 27001 and provides guidance on the related best practices that can be used to support this process, including an overview of ISO/IEC 27002, ISO/IEC 27003, ISO/IEC 27004, ISO/IEC 27005, among others.

  • Certification exam is monitored by an official Behaviour administrator.

  • The Certified Information Security 27001 Foundation certification exam is conducted at the end of the course, on the last day of training, through a multiple questions-based exam.

  • Upon success in the exam, the professional will achieve one the Information Security 27001 Foundation certification. If the professional fails the exam, he is entitled to one free retake within a 2 month period from the released date of the exam result.

  • Behaviour Pedagogical Model aims to provide a learning environment conducive to acquisition of competences, in accordance with objectives of each training program. Promoting interaction, participation and appreciation of experiences, we contribute to meaningful learning, certification and international recognition but, above all to the development of critical thinking and autonomy.

  • Behaviour is an organization accredited by DGERT (Portuguese Government Entity). Behaviour has its Quality Management System (QMS) implemented in accordance with the requirements of ISO 9001, the requirements of DGERT, the requirements of the European standard NP 4512 and the standard ISO 10015.

Dates and Price

 

Guaranteed Dates Program
(*) All dates of this course are guaranteed only for the events that take place in Lisbon. In other physical locations or in Live Online training, all events are subject to a minimum number of participants.

On Behaviour all classroom courses at Lisbon occur regardless of the number of trainees in room. The concept of setting up classes does not exist in our classroom educational model, which is why all classroom public dates, presented on the website, are guaranteed. So if you're in Portugal or anywhere else in the world, you can prepare your week and your trip, as long as you ensure your registration in the a classroom course.

Volume Discounts
For companies, Behaviour offer discounts, starting from the registration of the 2nd participant, in the same course and on the same date.
Simulate the prices for the number of participants you want to register to training@behaviour-group.com or contact us via chat.

Hotels and Useful Information
Know where you can stay in Lisbon. For more information please check online Booking.com