ISO/IEC 27001 (ISO 27001) is the international standard for Information Security management. It provides a model to establish, implement, maintain and continually improve a risk-managed Information Security Management System (ISMS).
The standard forms the basis for effective management of sensitive, confidential information and for the application of information security controls.
An organization that conforms to the ISO/IEC 27001 standard possesses clear, objective proof of its commitment to continued improvement of control over its sensitive and confidential information.
ISO/IEC 27001, therefore, provides reassurance to sponsors, shareholders and customers that the organization has expert control over its risk management and data security.
Due to the diversity of different organizations’ information assets – the ISO/IEC 27001 standard is adaptable according to an organization’s requirements.
The design and implementation of the ISMS is tailored to the organization’s objectives, information assets, operational processes, governing legal requirements and regulatory security requirements.
The ISO/IEC 27001 Practitioner course will teach you how to apply the standard to enable the management of information security.
A minimum requirement for attendance is one of the following:
- APMG ISO/IEC 27001 Foundation certificate.
- TÜV SÜD ISO27001 Foundation certificate.
- ICO-CERT ISMS 27001 Foundation certificate.
The ISO/IEC 27001 Practitioner qualification is aimed at those who are:
- Internal managers and personnel working to implement, maintain and operate an Information Security Management System (ISMS) within an organization.
- External consultants supporting an organization’s implementation, maintenance and operation of an Information Security Management System (ISMS).
- Internal auditors who are required to have an applied knowledge of the standard.
In the ISO/IEC 27001 Practitioner course you will learn how to:
- Apply the principles of ISMS policy and its information security scope, objectives, and processes within an organizational context.
- Apply the principles of risk management including risk identification, analysis and evaluation and propose appropriate treatments and controls to reduce information security risk, support business objectives and improve information security.
- Analyze and evaluate deployed risk treatments and controls to assess their effectiveness and opportunities for continual improvement.
- Analyze and evaluate the effectiveness of the ISMS through the use of internal audit and management review to continually improve the suitability, adequacy and effectiveness of the ISMS.
- Create, apply and evaluate the suitability, adequacy and effectiveness of documented information and records required by ISO/IEC 27001.
- Identify and apply appropriate corrective actions to maintain ISMS conformity with ISO/IEC 27001.
About the ISO/27001 Practitioner Exam:
The exam is an open book, objective testing multiple-choice exam. Each paper comprises 4 questions with 20 marks available per question. A pass mark is 50% (ie 40 out the total 80 marks available). The exam duration is 2½ hours. The open book exam can be taken with the aid of ISO/IEC 27000, ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27003 and ISO/IEC 27005. You may use your own, or include them in your purchase here.