ISO 27001 Information Security Management Training Course
| Course code | SD-CS-010 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more than a policy library. They need a defensible management system that connects business context, asset and process risks, security objectives, control selection, evidence, internal audit and management review. This course helps security, risk and compliance professionals turn ISO 27001 requirements into an operating ISMS rather than a documentation exercise.
Participants work through ISO/IEC 27001:2022 clauses 4–10 and the Annex A control framework, using ISO/IEC 27002:2022 guidance to interpret controls in context. They learn to define ISMS scope and interested parties, establish risk criteria, perform risk assessment and treatment, create a Statement of Applicability (SoA), write measurable security objectives, assign control ownership, collect implementation evidence, and prepare an internal audit and corrective-action process. The course also addresses certification-readiness decisions, including how to deal with exclusions, outsourced services, cloud environments and supplier dependencies.
Instructor-led sessions combine clause-by-clause teaching with a realistic implementation case study. Teams build key ISMS artefacts in practical workshops: a scope statement, risk register, risk treatment plan, SoA, control implementation plan, audit checklist and management-review agenda. Participants leave with an ISMS implementation workbook and a 90-day action plan tailored to their own organisation or a supplied case organisation, plus a certificate on completion. The course is available as a five-day classroom programme or live online delivery.
It is designed for professionals who already work with information security, operational risk, compliance, IT governance or audit and now need to lead, support or scrutinise an ISO 27001 implementation.
Course objectives
By the end of this course, participants will be able to:
- Define an ISO/IEC 27001 ISMS scope, context statement and interested-party requirements register
- Interpret clauses 4–10 of ISO/IEC 27001:2022 against operational security activities
- Conduct a risk assessment using defined assets, threats, vulnerabilities, likelihood, impact and risk criteria
- Produce a risk treatment plan linking selected treatments to accountable owners and target dates
- Create a Statement of Applicability that justifies Annex A control inclusion, exclusion and implementation status
- Design measurable information security objectives, KPIs and evidence sources for ISMS performance evaluation
- Plan an ISO 27001 internal audit using process-based audit trails, sampling questions and nonconformity criteria
- Build a certification-readiness roadmap with corrective actions, management-review inputs and implementation priorities
Benefits of attending
For you
- Gain practical confidence in converting ISO 27001 clauses into owned activities, records and evidence
- Build a portfolio of ISMS artefacts, including a risk register, risk treatment plan and Statement of Applicability
- Strengthen credibility when advising senior leaders on certification scope, control priorities and residual risk
- Prepare to contribute effectively to ISO 27001 implementation, surveillance or recertification programmes
- Develop a repeatable method for evaluating security controls across cloud, supplier and internal service environments
For your organisation
- Establish a more consistent ISMS approach linking business risks to security controls and accountable owners
- Reduce certification rework by improving scope definition, SoA rationale, evidence collection and audit preparation
- Create clearer risk treatment decisions for material assets, services, suppliers and information-processing activities
- Improve management visibility through security objectives, KPIs, internal audit findings and review inputs
- Build internal capability to maintain ISO 27001 controls between external audits rather than relying solely on consultants
Target competencies
Who should attend
- Information Security Managers — who are accountable for establishing or improving an ISMS
- ISO 27001 Implementation Leads — who need a structured method for taking an organisation through certification readiness
- IT Risk and GRC Managers — who translate technology and business risks into governed security treatments
- Internal Auditors — who need to audit ISO 27001 clauses, Annex A controls and objective evidence
- Compliance and Data Protection Managers — who must align security governance with regulatory and customer obligations
- IT Managers and Service Owners — who own systems, suppliers or operational controls within ISMS scope
Requirements and prerequisites
Participants should have working familiarity with information security concepts such as confidentiality, integrity, availability, access control, incident management, asset ownership and third-party risk. Experience in IT operations, cyber security, audit, risk, compliance, privacy or governance is expected, along with the ability to read policies, process maps and risk registers. Participants should understand how their organisation delivers technology services and who owns key business processes. No previous ISO 27001 certification, lead auditor qualification, legal training or specialist penetration-testing skill is required. A laptop with spreadsheet and document-editing software is strongly recommended for workshops.
Training methodology
The programme uses short instructor-led clause briefings followed by facilitated application to a realistic multi-service organisation. Participants analyse scope boundaries, map interested parties, score risks in a spreadsheet-based register, select Annex A controls, and challenge each other’s SoA justifications. Case-study evidence packs are used to practise audit interviews, sampling and nonconformity writing. Daily workshops produce working ISMS documents, while the final session converts those outputs into a prioritised 90-day implementation plan for each participant’s organisation or case scenario.
Course outline
Day 1: ISMS foundations, context and scope
- ISO/IEC 27001:2022 structure and the Plan-Do-Check-Act management system model
- Clauses 4 and 5: organisational context, leadership and policy requirements
- Interested-party analysis for customers, regulators, suppliers and internal functions
- Defining ISMS boundaries across sites, cloud platforms, business units and outsourced services
- Information security roles, authorities and the three-lines governance model
- Documented information requirements and practical document-control conventions
- Certification lifecycle, Stage 1 and Stage 2 audit expectations
Workshop: Participants draft an ISMS scope statement, interested-party register and governance map for the case organisation.
Day 2: Risk assessment and treatment
- Clause 6 planning requirements and the relationship between risk, opportunity and security objectives
- Risk assessment methodology design: assets, scenarios, likelihood, impact and risk acceptance criteria
- Asset and information classification approaches for business processes and technology services
- Threat, vulnerability and consequence analysis using risk scenarios
- Risk register construction and inherent-versus-residual risk scoring
- Risk treatment options: modify, retain, avoid and share risk
- Risk treatment plan ownership, approval, due dates and residual-risk acceptance
Workshop: Teams assess five information-security risk scenarios and produce a scored risk register with treatment decisions.
Day 3: Annex A controls and the Statement of Applicability
- Annex A:2022 control themes and the relationship to ISO/IEC 27002:2022 guidance
- Control selection from risk treatment requirements and applicable obligations
- Statement of Applicability structure, mandatory rationale and implementation-status fields
- Organisational controls including policy, acceptable use, supplier security and incident readiness
- People controls including screening, awareness, remote working and disciplinary processes
- Physical and technological controls including access management, logging, backup and secure configuration
- Control evidence design for policies, tickets, logs, approvals, training records and review minutes
Workshop: Participants create a Statement of Applicability extract, including control rationale, owner, evidence and implementation status.
Day 4: Operating, measuring and auditing the ISMS
- Clause 7 support requirements for competence, awareness, communication and resources
- Clause 8 operational planning and control for recurring security activities
- Security objectives, KPIs, KRIs and performance-evaluation evidence
- Monitoring control effectiveness using metrics, exceptions and trend analysis
- Internal audit programme design, auditor independence and risk-based audit scheduling
- Audit interviewing, evidence sampling and process-trail testing
- Nonconformity grading, root-cause analysis and corrective-action management
Workshop: Participants conduct a simulated internal audit from an evidence pack and write findings, evidence references and corrective actions.
Day 5: Management review and certification readiness
- Clause 9.3 management-review inputs, decisions and meeting records
- Clause 10 continual improvement, correction and corrective-action verification
- Readiness assessment against clauses 4–10, Annex A and the organisation’s SoA
- Common certification audit findings: weak scope, generic risks, unsupported controls and incomplete evidence
- Preparing process owners for certification-audit interviews and evidence requests
- Implementation roadmap sequencing, dependencies, resources and executive decision points
- Maintaining the ISMS through surveillance audits, change management and annual review cycles
Workshop: Participants complete a certification-readiness gap assessment and present a prioritised 90-day ISMS action plan.
Tools & standards covered
ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27005:2022, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
02 – 06 Nov 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Nairobi · USD 3,000 -
09 – 13 Nov 2026Book
Dar es Salaam · USD 3,500 -
23 – 27 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
CyberArk Privileged Access Management Administration Training Course
Privileged accounts sit at the centre of infrastructure administration, application support and incident response, yet unmanaged passwords, …
PCI DSS v4.0 Payment Card Security Compliance Training Course
Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centr…
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…
CIS Controls v8 Implementation and Assessment Training Course
Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…