Get in Touch

Course Outline

ISMS Foundations & ISO/IEC 27002 Framework (90 minutes)

  • Structure of the ISO/IEC 27000 family and its relationship to ISO/IEC 27001 certification.
  • Core principles underpinning a dynamic Information Security Management System.
  • The four control themes: Organizational, People, Physical, and Technological.
  • The benefits ISO/IEC 27002 offers to organizations, regulators, and the general public.
  • Activity: Self-assessment of security maturity and gap identification exercise.

In-depth Review of the 93 ISO/IEC 27002 Controls (120 minutes)

  • Structure of the 2022 revision: themes, categories, and control objectives.
  • Key controls including access management, cryptography, operations security, supplier relationships, compliance, and incident response.
  • Differences between mandatory and guideline controls, along with implementation flexibility.
  • Activity: Control categorization workshop and real-world scenario mapping.

Risk Linkage, Implementation & Evidence Mapping (120 minutes)

  • Linking controls to risk assessment and treatment plans.
  • Implementation strategies involving policy drafting, technical deployment, and process integration.
  • Compliance evidence, audit readiness, and continuous monitoring practices.
  • Activity: Developing a mini risk-treatment matrix and a control evidence checklist.

Operationalization, Framework Alignment & Next Steps (60 minutes)

  • Common pitfalls and best practices for adopting controls at scale.
  • Aligning ISO/IEC 27002 with regulatory frameworks such as GDPR, NIST CSF, HIPAA, etc.
  • Pathways to certification, advanced training opportunities, and organizational rollout planning.
  • Capstone Exercise: Group scenario mapping and drafting a 90-day control implementation roadmap.
  • Q&A session, resource distribution, and course closure.
 7 Hours

Testimonials (2)

Related Categories