ISO 27001 Information Security Management Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-010
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more than a policy library. They need a defensible management system that connects business context, asset and process risks, security objectives, control selection, evidence, internal audit and management review. This course helps security, risk and compliance professionals turn ISO 27001 requirements into an operating ISMS rather than a documentation exercise.

Participants work through ISO/IEC 27001:2022 clauses 4–10 and the Annex A control framework, using ISO/IEC 27002:2022 guidance to interpret controls in context. They learn to define ISMS scope and interested parties, establish risk criteria, perform risk assessment and treatment, create a Statement of Applicability (SoA), write measurable security objectives, assign control ownership, collect implementation evidence, and prepare an internal audit and corrective-action process. The course also addresses certification-readiness decisions, including how to deal with exclusions, outsourced services, cloud environments and supplier dependencies.

Instructor-led sessions combine clause-by-clause teaching with a realistic implementation case study. Teams build key ISMS artefacts in practical workshops: a scope statement, risk register, risk treatment plan, SoA, control implementation plan, audit checklist and management-review agenda. Participants leave with an ISMS implementation workbook and a 90-day action plan tailored to their own organisation or a supplied case organisation, plus a certificate on completion. The course is available as a five-day classroom programme or live online delivery.

It is designed for professionals who already work with information security, operational risk, compliance, IT governance or audit and now need to lead, support or scrutinise an ISO 27001 implementation.

Course objectives

By the end of this course, participants will be able to:

  • Define an ISO/IEC 27001 ISMS scope, context statement and interested-party requirements register
  • Interpret clauses 4–10 of ISO/IEC 27001:2022 against operational security activities
  • Conduct a risk assessment using defined assets, threats, vulnerabilities, likelihood, impact and risk criteria
  • Produce a risk treatment plan linking selected treatments to accountable owners and target dates
  • Create a Statement of Applicability that justifies Annex A control inclusion, exclusion and implementation status
  • Design measurable information security objectives, KPIs and evidence sources for ISMS performance evaluation
  • Plan an ISO 27001 internal audit using process-based audit trails, sampling questions and nonconformity criteria
  • Build a certification-readiness roadmap with corrective actions, management-review inputs and implementation priorities

Benefits of attending

For you

  • Gain practical confidence in converting ISO 27001 clauses into owned activities, records and evidence
  • Build a portfolio of ISMS artefacts, including a risk register, risk treatment plan and Statement of Applicability
  • Strengthen credibility when advising senior leaders on certification scope, control priorities and residual risk
  • Prepare to contribute effectively to ISO 27001 implementation, surveillance or recertification programmes
  • Develop a repeatable method for evaluating security controls across cloud, supplier and internal service environments

For your organisation

  • Establish a more consistent ISMS approach linking business risks to security controls and accountable owners
  • Reduce certification rework by improving scope definition, SoA rationale, evidence collection and audit preparation
  • Create clearer risk treatment decisions for material assets, services, suppliers and information-processing activities
  • Improve management visibility through security objectives, KPIs, internal audit findings and review inputs
  • Build internal capability to maintain ISO 27001 controls between external audits rather than relying solely on consultants

Target competencies

ISMS scope definitionSecurity risk assessmentControl applicability analysisRisk treatment planningInternal audit planningManagement review reporting

Who should attend

  • Information Security Managers — who are accountable for establishing or improving an ISMS
  • ISO 27001 Implementation Leads — who need a structured method for taking an organisation through certification readiness
  • IT Risk and GRC Managers — who translate technology and business risks into governed security treatments
  • Internal Auditors — who need to audit ISO 27001 clauses, Annex A controls and objective evidence
  • Compliance and Data Protection Managers — who must align security governance with regulatory and customer obligations
  • IT Managers and Service Owners — who own systems, suppliers or operational controls within ISMS scope

Requirements and prerequisites

Participants should have working familiarity with information security concepts such as confidentiality, integrity, availability, access control, incident management, asset ownership and third-party risk. Experience in IT operations, cyber security, audit, risk, compliance, privacy or governance is expected, along with the ability to read policies, process maps and risk registers. Participants should understand how their organisation delivers technology services and who owns key business processes. No previous ISO 27001 certification, lead auditor qualification, legal training or specialist penetration-testing skill is required. A laptop with spreadsheet and document-editing software is strongly recommended for workshops.

Training methodology

The programme uses short instructor-led clause briefings followed by facilitated application to a realistic multi-service organisation. Participants analyse scope boundaries, map interested parties, score risks in a spreadsheet-based register, select Annex A controls, and challenge each other’s SoA justifications. Case-study evidence packs are used to practise audit interviews, sampling and nonconformity writing. Daily workshops produce working ISMS documents, while the final session converts those outputs into a prioritised 90-day implementation plan for each participant’s organisation or case scenario.

Course outline

Day 1: ISMS foundations, context and scope

  • ISO/IEC 27001:2022 structure and the Plan-Do-Check-Act management system model
  • Clauses 4 and 5: organisational context, leadership and policy requirements
  • Interested-party analysis for customers, regulators, suppliers and internal functions
  • Defining ISMS boundaries across sites, cloud platforms, business units and outsourced services
  • Information security roles, authorities and the three-lines governance model
  • Documented information requirements and practical document-control conventions
  • Certification lifecycle, Stage 1 and Stage 2 audit expectations

Workshop: Participants draft an ISMS scope statement, interested-party register and governance map for the case organisation.

Day 2: Risk assessment and treatment

  • Clause 6 planning requirements and the relationship between risk, opportunity and security objectives
  • Risk assessment methodology design: assets, scenarios, likelihood, impact and risk acceptance criteria
  • Asset and information classification approaches for business processes and technology services
  • Threat, vulnerability and consequence analysis using risk scenarios
  • Risk register construction and inherent-versus-residual risk scoring
  • Risk treatment options: modify, retain, avoid and share risk
  • Risk treatment plan ownership, approval, due dates and residual-risk acceptance

Workshop: Teams assess five information-security risk scenarios and produce a scored risk register with treatment decisions.

Day 3: Annex A controls and the Statement of Applicability

  • Annex A:2022 control themes and the relationship to ISO/IEC 27002:2022 guidance
  • Control selection from risk treatment requirements and applicable obligations
  • Statement of Applicability structure, mandatory rationale and implementation-status fields
  • Organisational controls including policy, acceptable use, supplier security and incident readiness
  • People controls including screening, awareness, remote working and disciplinary processes
  • Physical and technological controls including access management, logging, backup and secure configuration
  • Control evidence design for policies, tickets, logs, approvals, training records and review minutes

Workshop: Participants create a Statement of Applicability extract, including control rationale, owner, evidence and implementation status.

Day 4: Operating, measuring and auditing the ISMS

  • Clause 7 support requirements for competence, awareness, communication and resources
  • Clause 8 operational planning and control for recurring security activities
  • Security objectives, KPIs, KRIs and performance-evaluation evidence
  • Monitoring control effectiveness using metrics, exceptions and trend analysis
  • Internal audit programme design, auditor independence and risk-based audit scheduling
  • Audit interviewing, evidence sampling and process-trail testing
  • Nonconformity grading, root-cause analysis and corrective-action management

Workshop: Participants conduct a simulated internal audit from an evidence pack and write findings, evidence references and corrective actions.

Day 5: Management review and certification readiness

  • Clause 9.3 management-review inputs, decisions and meeting records
  • Clause 10 continual improvement, correction and corrective-action verification
  • Readiness assessment against clauses 4–10, Annex A and the organisation’s SoA
  • Common certification audit findings: weak scope, generic risks, unsupported controls and incomplete evidence
  • Preparing process owners for certification-audit interviews and evidence requests
  • Implementation roadmap sequencing, dependencies, resources and executive decision points
  • Maintaining the ISMS through surveillance audits, change management and annual review cycles

Workshop: Participants complete a certification-readiness gap assessment and present a prioritised 90-day ISMS action plan.

Tools & standards covered

ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27005:2022, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You do not need a prior ISO 27001 qualification, but this is not a beginner cyber security course. Participants should already understand core security and risk concepts and be comfortable reading policies, risk registers or operational procedures.

Bring a laptop with a spreadsheet application and document editor, such as Microsoft Excel and Word. Workshop templates are provided, and participants use them to build risk, SoA, audit and action-planning artefacts.

Yes. The primary focus is building and operating an ISMS, from scope and risk treatment through control evidence and management review. Internal audit is covered because implementation teams need to test readiness and correct weaknesses before an external audit.

This course focuses on implementation decisions and working ISMS deliverables: scope, risk methodology, treatment plan, SoA, evidence and improvement roadmap. A Lead Auditor course concentrates more deeply on audit principles, audit-team leadership and conducting formal certification-style audits.

Yes. The case work addresses shared-responsibility boundaries, supplier dependencies, outsourced processes and evidence from cloud-based services. Participants learn how to reflect these arrangements in ISMS scope, risk treatment and control ownership.

You leave with completed templates and examples for an ISMS scope statement, risk register, risk treatment plan, Statement of Applicability, internal audit checklist and management-review agenda. You also create a prioritised 90-day implementation plan that can be adapted for your organisation.

Upcoming sessions

  • 21 – 25 Sep 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Nairobi · USD 3,000
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 02 – 06 Nov 2026
    Live Online · USD 1,500
    Book
  • 09 – 13 Nov 2026
    Nairobi · USD 3,000
    Book
  • 09 – 13 Nov 2026
    Dar es Salaam · USD 3,500
    Book
  • 23 – 27 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

CyberArk Privileged Access Management Administration Training Course

Privileged accounts sit at the centre of infrastructure administration, application support and incident response, yet unmanaged passwords, …

5 Days Certificate

PCI DSS v4.0 Payment Card Security Compliance Training Course

Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centr…

5 Days Certificate

Splunk Enterprise Security SIEM Operations Training Course

Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…

5 Days Certificate

CIS Controls v8 Implementation and Assessment Training Course

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…