Course Description
ISO/IEC 27001 is the management system standard that boards, customers and procurement teams already trust — and it has become the entry requirement for selling into enterprise. It is also the foundation for AI governance: because ISO 42001 shares the same high-level structure, organisations with a working ISMS find AI management dramatically easier to implement.
This course develops the capability to implement an ISMS and take it to certification. Participants learn the standard's structure, context and scope definition, leadership and policy, information security risk assessment and treatment, the Annex A control set, the Statement of Applicability, documented information, internal audit and management review, and the certification process.
What you will achieve
By the end of this training course, participants will be able to:
- Explain ISO/IEC 27001 and the ISMS concept
- Establish context, scope and interested parties
- Define leadership commitment, policy and roles
- Conduct information security risk assessment and treatment
- Apply the Annex A control set
- Produce and maintain the Statement of Applicability
- Manage documented information and operational control
- Prepare for and pass certification audit
How the course is delivered
The course works through the standard clause by clause with practical exercises in scoping, risk assessment, control selection and Statement of Applicability development on realistic organisational scenarios.
The programme also positions ISO 27001 as the foundation for ISO 42001, reflecting the common implementation path organisations follow when adding AI governance.
Designed for
This training course is ideal for:
- Information security and IT managers
- GRC, compliance and risk professionals
- CISOs and security leads
- Consultants implementing ISMS
- Anyone preparing for ISO 27001 certification
Daily programme
- ISO/IEC 27001 and the ISMS concept
- Management system standards and certification
- Structure and the high-level structure
- Context, scope and interested parties
- Leadership, policy and roles
- Information security objectives
- Information security risk assessment
- Risk treatment and acceptance
- The Annex A control set
- Organisational and people controls
- Physical and technological controls
- The Statement of Applicability
- Operational planning and control
- Documented information
- Awareness, competence and communication
- Supplier and third-party security
- Monitoring, measurement and evaluation
- Internal audit and management review
- Continual improvement
- Certification process, path to ISO 42001, workshop
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.