Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Accredited ISO/IEC 27,001 Foundation
Rating: 4.2 out of 5(24 ratings)
80 students

Accredited ISO/IEC 27,001 Foundation

Information Security Management Systems (ISMS)
Last updated 8/2023
English
English

What you'll learn

  • Understand the purpose and significance of an ISMS in protecting sensitive information and managing security risks.
  • Gain an overview of the ISO 27001 standard, including its structure, main clauses, and annexes.
  • Comprehend fundamental information security concepts such as confidentiality, integrity, availability, and the CIA triad.
  • Learn the process of identifying information security risks, assessing their impact and likelihood, and determining appropriate risk treatment options.
  • Explore various categories of information security controls, including technical, physical, and organizational controls.
  • Gain insights into the steps involved in implementing ISO 27001 within an organization, including scoping the ISMS, defining policies, and creating the Stateme

Course content

1 section26 lectures10h 42m total length
  • Overview3:00

    Explore the ISO 27,001 foundation by examining the standard, its requirements, and guidance from ISO 27,002, to prepare for audits and demonstrate foundation-level IT security knowledge.

  • The ISO/IEC 27,001 Foundation Exam28:49

    Explore the ISO/IEC 27001 foundation exam, a 40-question, 1-hour, not open-book test, and learn how 27002 guidance, accreditation, and downloading the standard shape preparation.

  • The ISO/IEC 27,000 Family29:11

    Explore the iso/iec 27000 family and how iso 27001 and its guidance documents, including 27002 and 27003, shape information security management, audits, and industry-specific implementations.

  • Data vs Information28:24

    Explore data versus information in ISO 27001 foundation, showing how relationships in a CMDB turn data into information. Address archives, retention, classification, and vocabulary for secure information management.

  • Value of Information27:23

    Explore how the value of data varies by industry, and apply CIA (confidentiality, integrity, availability) through privacy, access controls, and data governance under ISO/IEC 27001.

  • Fundamental Principles of Security20:58

    Explore the fundamental principles of security through the CIA triad—confidentiality, integrity, and availability—applied to data, equipment, people, and content within the ISO 27001 framework.

  • Fundamental Principles of Security Part 232:27

    apply confidentiality by enforcing access limits and protecting data across the entire data stream. ensure integrity through change management, and guarantee availability with backups and separate environments.

  • Threats, Risks, Vulnerabilities and Exposure27:31

    Explore the differences between threats, vulnerabilities, risks, and exposure within ISO 27001 foundation, and see how human and non-human threats, threat agents, and exposure shape audits.

  • Types of Damage and Risk Management25:04

    Explore how ISO 27001 risk management analyzes threats, incidents, vulnerabilities, and exposures to distinguish direct vs indirect damage and prioritize controls using a simple risk matrix.

  • Countermeasures24:50

    Explore countermeasures: preventive, reductive, detective, repressive, corrective, and acceptance, driven by risk analysis and management to reduce threats and minimize consequences in ISO/IEC 27,001 foundation.

  • The Security Organisation22:55

    Explore the security organization, detailing the information security management system and its PDCA cycle. Learn how security policy, document control, and incident and event management enable continual improvement.

  • The Security Organisation Part 223:05

    Examine the information security management system built on domain architecture across locations. Learn about domain policies, byox policy, IoT, media handling, and access controls.

  • The Security Organisation Part 317:50

    Explore how ISO 27,001 Foundation defines a security organization, outlining roles and responsibilities from the chief security officer to data protection officer, and stressing awareness, training, and audit readiness.

  • Access Control27:02

    Learn about access control and access management, from new starter procedures to revoking access for leavers. See how HR, the help desk, and security grant appropriate physical and logical access.

  • Cryptography17:48

    Learn how cryptography protects data confidentiality, integrity, and authenticity, and compare symmetric, asymmetric, public key infrastructure, and one-way encryption with practical examples.

  • Incident Management23:22

    Explore incident management within ISO 27,001 foundation, distinguishing events from incidents, and learn how the service desk logs and manages disruptions and security incidents—often automatically via exceptional events.

  • Incident Management Part 216:25

    Explore incident management in ISO 27001 Foundation, tracing the threat to disruption, damage, and recovery while examining reductive, preventive, detective, repressive, and corrective countermeasures.

  • Importance of Measures31:38

    Explore how ISO 27001 foundations define measures as technical or administrative safeguards, categorized as preventative, detective, reductive, repressive, or corrective, guided by risk analysis.

  • Physical Security Measures28:41

    Explore physical security measures across outer rings, the building, and the working space. Apply risk-based access, sensors, barriers, and disposal policies to safeguard assets and information in iso 27001 foundation.

  • Technical Security Measures28:50

    Explore technical security measures, including antivirus, firewalls, vulnerability management, backups, and cryptography, to protect confidentiality, integrity, and availability.

  • Organisational Measures32:06

    Explore organizational measures for information security, focusing on policies, disaster planning, segregation of duties and security roles, and secure remote working with mobile devices.

  • Organisational Measures Part 225:20

    Explore access management and IAA (identification, authentication, and authorization) within ISO/IEC 27001 foundation, and align policies, roles, disaster recovery with business continuity, testing, and redundancy options.

  • Legislation and Regulation28:52

    Explore how legislation and regulation shape data protection and compliance across education, covering FERPA, GDPR, NDAs, and policy frameworks such as acceptable usage, retention, and shredding.

  • Legislation and Regulation Part 221:49

    Explore the differences between legislation and regulation, and how organizations choose to comply with standards like ISO 27001, NIST, PCI, and SOX, using plan-do-check-act.

  • Sample Paper29:22

    Preview ISO 27001 foundation exam techniques and tips through a sample paper walkthrough, teaching careful reading, strategic answering, and note-taking to improve accuracy and confidence.

  • Sample Paper Part 220:03

    Explore the governance framework of ISO 27001 foundation, its ISMS, incident handling, information classification, physical and logical security, and GDPR.

Requirements

  • The prerequisites for an accredited ISO 27001 Foundation Course are usually minimal, given that the course is designed to provide an introductory understanding of the ISO 27001 standard and information security concepts. Since this course is targeted at individuals with limited or no prior knowledge of ISO 27001, the prerequisites are often straightforward.
  • Participants should have basic computer skills, as the course materials and assessments might be delivered through digital platforms.
  • While not a strict prerequisite, having an interest in information security and a desire to learn about protecting sensitive data will greatly enhance the learning experience.

Description

The ISO 27,001 Foundation Course is a training program designed to provide participants with a basic understanding of the ISO 27,001 standard, which is focused on information security management systems (ISMS). ISO 27,001 is an internationally recognized standard that outlines the requirements for establishing, implementing, maintaining, and continually improving an ISMS within the context of the organization's overall business risks.

It's important to note that while the ISO 27001 Foundation Course provides a solid understanding of the standard's fundamentals, it might not make participants experts in ISO 27001 implementation. It's often a stepping stone for individuals who wish to further their knowledge and become involved in implementing or managing information security management systems within their organizations.

The aim to provide participants with a comprehensive understanding of the key concepts, principles, and requirements of the ISO 27001 standard and its implications for information security management.

By the end of an accredited ISO 27,001 Foundation Course, participants should have a strong foundational understanding of ISO 27001, enabling them to contribute effectively to information security initiatives within their organizations and potentially pursue more advanced ISO 27001 training or certification tracks. 

In short, in this course, we explore the concepts of the ISO / IEC 27,000 standard and prepare for the ISO / IEC 27,000 Information Security Management examination accredited by EXIN.

Who this course is for:

  • Information Security Beginners
  • Managers and Supervisors
  • IT Professionals
  • Quality and Process Managers
  • Anyone Interested in Information Security