Module 1: Introduction to ISO 27001
Introduction
Compatibility with Other Management System Standards
ISO 27001:2022 and Its Clauses
Module 2: Information Security
What is Business?
Industries
Risk
SWOT Analysis
Constructs and Characteristics of Assets
Security and Privacy
Triad of Information Security
Cyber Security is Everyone’s Responsibility
Cybersecurity Landscape
What is Information Security?
Information Security Management
Need of Information Security
Threats to Information Security
Active and Passive Attacks
Module 3: Context of the Organisation
Understanding the Organisation and Its Context
Understanding the Needs and Expectations of Interested Parties
Determining the Scope of the Information Security Management System
Information Security Management System
Module 4: Leadership
Leadership and Commitment
Policy
Organisational Roles, Responsibilities, and Authorities
Module 5: Planning
Organisational Roles, Responsibilities, and Authorities
Information Security Objectives and Planning to Achieve Them
Planning of Changes
Module 6: Support
Resources
Competence
Awareness
Communication
Documented Information
Module 7: Operation
Operational Planning and Control
Information Security Risk Assessment
Information Security Risk Treatment
Module 8: Performance Evaluation
Monitoring, Measurement, Analysis, and Evaluation
Internal Audit
Management Review
Module 9: Improvement
Nonconformity and Corrective Action
Continual Improvement
Module 10: Introduction to Auditing
Internal Audit Charter
Communicate with Organisation and Audit Committee
Auditing Reflects
General and Internal Auditing Standards and Guidance
Auditing Types
Auditing Techniques
Auditing Principles
Phases of Audit
Module 11: Performing ISO 27001 Audits
Preparing an Audit Report
Assessment of Audit Reports and Documents
Report Preparation, Findings, Reconciliation, and Conclusions
Auditing Procedures
Reviewing Documents and Reports
Classifying Findings
Reliability of Audit Findings
Module 12: Internal Auditor
Roles and Responsibilities
Audit Plan
Opening Meeting
Record Review Activities
Internal Auditor Checklist
Communication Between Departments
Drafting Reports and Test Plans
Module 13: ISMS and the ISO 27001 Standards Family
What is an ISMS?
Project Plan
Management and Governance Frameworks
ISMS Benefits
Scope of ISMS in an Organisation
Introduction to Management Systems
Process Approach
Fundamentals
PDCA Cycle
Module 14: Interaction with ISO 27005
What is ISO 27005?
ISO 27001 VS ISO 27005
Quantifying the Business Impact
Impact Severity
Module 15: Roles and Responsibilities of a Lead Implementer
Roles and Responsibilities
Case Study: ABC’s ISO 27001
Module 16: Launch and Implement an ISMS in an Organisation
Apply the Frameworks
Procedures and Controls
Implementing the Controls
Training and Awareness Programme
Management’s Role
Responsibilities of Employees