
Explore the ISO 27,001 foundation by examining the standard, its requirements, and guidance from ISO 27,002, to prepare for audits and demonstrate foundation-level IT security knowledge.
Explore the ISO/IEC 27001 foundation exam, a 40-question, 1-hour, not open-book test, and learn how 27002 guidance, accreditation, and downloading the standard shape preparation.
Explore the iso/iec 27000 family and how iso 27001 and its guidance documents, including 27002 and 27003, shape information security management, audits, and industry-specific implementations.
Explore data versus information in ISO 27001 foundation, showing how relationships in a CMDB turn data into information. Address archives, retention, classification, and vocabulary for secure information management.
Explore how the value of data varies by industry, and apply CIA (confidentiality, integrity, availability) through privacy, access controls, and data governance under ISO/IEC 27001.
Explore the fundamental principles of security through the CIA triad—confidentiality, integrity, and availability—applied to data, equipment, people, and content within the ISO 27001 framework.
apply confidentiality by enforcing access limits and protecting data across the entire data stream. ensure integrity through change management, and guarantee availability with backups and separate environments.
Explore the differences between threats, vulnerabilities, risks, and exposure within ISO 27001 foundation, and see how human and non-human threats, threat agents, and exposure shape audits.
Explore how ISO 27001 risk management analyzes threats, incidents, vulnerabilities, and exposures to distinguish direct vs indirect damage and prioritize controls using a simple risk matrix.
Explore countermeasures: preventive, reductive, detective, repressive, corrective, and acceptance, driven by risk analysis and management to reduce threats and minimize consequences in ISO/IEC 27,001 foundation.
Explore the security organization, detailing the information security management system and its PDCA cycle. Learn how security policy, document control, and incident and event management enable continual improvement.
Examine the information security management system built on domain architecture across locations. Learn about domain policies, byox policy, IoT, media handling, and access controls.
Explore how ISO 27,001 Foundation defines a security organization, outlining roles and responsibilities from the chief security officer to data protection officer, and stressing awareness, training, and audit readiness.
Learn about access control and access management, from new starter procedures to revoking access for leavers. See how HR, the help desk, and security grant appropriate physical and logical access.
Learn how cryptography protects data confidentiality, integrity, and authenticity, and compare symmetric, asymmetric, public key infrastructure, and one-way encryption with practical examples.
Explore incident management within ISO 27,001 foundation, distinguishing events from incidents, and learn how the service desk logs and manages disruptions and security incidents—often automatically via exceptional events.
Explore incident management in ISO 27001 Foundation, tracing the threat to disruption, damage, and recovery while examining reductive, preventive, detective, repressive, and corrective countermeasures.
Explore how ISO 27001 foundations define measures as technical or administrative safeguards, categorized as preventative, detective, reductive, repressive, or corrective, guided by risk analysis.
Explore physical security measures across outer rings, the building, and the working space. Apply risk-based access, sensors, barriers, and disposal policies to safeguard assets and information in iso 27001 foundation.
Explore technical security measures, including antivirus, firewalls, vulnerability management, backups, and cryptography, to protect confidentiality, integrity, and availability.
Explore organizational measures for information security, focusing on policies, disaster planning, segregation of duties and security roles, and secure remote working with mobile devices.
Explore access management and IAA (identification, authentication, and authorization) within ISO/IEC 27001 foundation, and align policies, roles, disaster recovery with business continuity, testing, and redundancy options.
Explore how legislation and regulation shape data protection and compliance across education, covering FERPA, GDPR, NDAs, and policy frameworks such as acceptable usage, retention, and shredding.
Explore the differences between legislation and regulation, and how organizations choose to comply with standards like ISO 27001, NIST, PCI, and SOX, using plan-do-check-act.
Preview ISO 27001 foundation exam techniques and tips through a sample paper walkthrough, teaching careful reading, strategic answering, and note-taking to improve accuracy and confidence.
Explore the governance framework of ISO 27001 foundation, its ISMS, incident handling, information classification, physical and logical security, and GDPR.
The ISO 27,001 Foundation Course is a training program designed to provide participants with a basic understanding of the ISO 27,001 standard, which is focused on information security management systems (ISMS). ISO 27,001 is an internationally recognized standard that outlines the requirements for establishing, implementing, maintaining, and continually improving an ISMS within the context of the organization's overall business risks.
It's important to note that while the ISO 27001 Foundation Course provides a solid understanding of the standard's fundamentals, it might not make participants experts in ISO 27001 implementation. It's often a stepping stone for individuals who wish to further their knowledge and become involved in implementing or managing information security management systems within their organizations.
The aim to provide participants with a comprehensive understanding of the key concepts, principles, and requirements of the ISO 27001 standard and its implications for information security management.
By the end of an accredited ISO 27,001 Foundation Course, participants should have a strong foundational understanding of ISO 27001, enabling them to contribute effectively to information security initiatives within their organizations and potentially pursue more advanced ISO 27001 training or certification tracks.
In short, in this course, we explore the concepts of the ISO / IEC 27,000 standard and prepare for the ISO / IEC 27,000 Information Security Management examination accredited by EXIN.