Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of ISMS & ISO/IEC 27002 Framework (90 min)
- Structure of the ISO/IEC 27000 family & its relationship to ISO/IEC 27001 certification
- Core principles of a dynamic Information Security Management System
- The four control themes: Organizational, People, Physical, and Technological
- Benefits of ISO/IEC 27002 for organizations, regulators, and public trust
- Activity: Security maturity self-assessment & gap identification exercise
In-Depth Analysis of the 93 ISO/IEC 27002 Controls (120 min)
- Structure of the 2022 revision: themes, categories, and control objectives
- Key controls: Access management, cryptography, operations security, supplier relationships, compliance, and incident response
- Mandatory vs. guideline controls & implementation flexibility
- Activity: Control categorization workshop & real-world scenario mapping
Linking Controls to Risk, Implementation & Evidence Mapping (120 min)
- Connecting controls to risk assessment & treatment plans
- Implementation strategies: policy drafting, technical deployment, and process integration
- Compliance evidence, audit readiness, and continuous monitoring practices
- Activity: Build a mini risk-treatment matrix & control evidence checklist
Operationalization, Framework Alignment & Next Steps (60 min)
- Common pitfalls & best practices for control adoption at scale
- Aligning ISO/IEC 27002 with regulatory frameworks (GDPR, NIST CSF, HIPAA, etc.)
- Pathways to certification, advanced training, and organizational rollout planning
- Capstone Exercise: Group scenario mapping & drafting a 90-day control implementation roadmap
- Q&A, resource distribution, and course close
7 Hours
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Risk optimization is more clear than the other subjects
Munirah Alsahli - GOSI
Course - CGEIT – Certified in the Governance of Enterprise IT
The knowledge and understanding of the trainer on the training material was exceptional. The trainer was well aware of the subject, provided practical examples in relevance. I would highly recommend him as a trainer for this training.