GRSee Training

PECB Certified ISO/IEC 27001 Lead Implementer

Master the implementation and management of information security management systems (ISMS) based on ISO/IEC 27001:2022

Why should you attend?

Information security threats and attacks grow and improve constantly. As such, organizations are increasingly concerned about
how their valuable information is handled and protected. The best form of defense against them is the proper implementation
and management of information security controls and best practices. Information security is the globally accepted benchmark
and also a key expectation and requirement of customers, legislators, and other interested parties.

This training course is designed to prepare you to implement an information security management system (ISMS) based on
the requirements of ISO/IEC 27001. It aims to provide a comprehensive understanding of the best practices of an ISMS and a framework for its continual management and improvement.

The training content is packed with practical exercises and case studies which will help you get equipped with real-world
expertise that you can apply to your day-to-day operations and activities. Our training courses are all-inclusive, meaning that
they cover everything you need to get the certificate.

Who should attend

  • Managers or consultants involved in and/or concerned with the implementation of an information security management system in an organization
  • Project managers, consultants, or expert advisers seeking to master the implementation of an information security
    management system; or individuals responsible to maintain conformity with the ISMS requirements within an organization
  • Members of the ISMS team

Learning objectives

  • Explain the fundamental concepts and principles of an information security management system (ISMS) based on ISO/IEC
    27001
  • Interpret the ISO/IEC 27001 requirements for an ISMS from the perspective of an implementer
  • Initiate and plan the implementation of an ISMS based on ISO/IEC 27001, by utilizing PECB’s IMS2 Methodology and other best
    practices
  • Support an organization in operating, maintaining, and continually improving an ISMS based on ISO/IEC 27001
  • Prepare an organization to undergo a third-party certification audit

Course agenda

Day 01

Introduction to ISO/IEC 27001 and initiation of an ISMS implementation

  • Training course objectives and structure
  • Standards and regulatory frameworks
  • Information security management system based on
    ISO/IEC 27001
  • Fundamental concepts and principles of information
    security
  • Initiation of the ISMS implementation
  • Understanding the organization and its context
  • ISMS scope

Day 02

Implementation plan of an ISMS

  • Leadership and project approval
  • Organizational structure
  • Analysis of the existing system
  • Information security policy
  • Risk management
  • Statement of Applicability

Day 03

Implementation of an ISMS

  • Selection and design of controls
  • Implementation of controls
  • Management of documented information
  • Trends and technologies
  • Communication
  • Competence and awareness
  • Management of security operations

Day 04

ISMS monitoring, continual improvement, and preparation for the certification audit

  • Monitoring, measurement, analysis, and evaluation
  • Internal audit
  • Management review
  • Treatment of nonconformities
  • Continual improvement
  • Preparation for the certification audit
  • Closing of the training course

Day 05

Certification exam