
Develop a practical approach to implementing ISO 27001 and building an information security management system. Learn the certification process, audits by accredited bodies, and step-by-step hands-on activities.
This lecture outlines the ISO 27001 implementation process, emphasizing management support, fixed scope, asset-based risk assessment, selecting controls, a risk treatment plan, and audits leading to certification.
Craft a structured business case for ISO 27001 implementation, detailing costs and benefits, governance, and a risk assessment and treatment plan to maximize return on secure investments.
Learn to build asset inventory with an asset register for digital assets, databases, and people assets. Assign ownership, assess risk, define classification and disposal, and safeguard confidentiality, integrity, and availability.
Apply ISO 27001 risk assessment to identify assets, threats, and vulnerabilities, calculate risk with probability, impact, and detectability, and develop a risk treatment plan toward certification.
Define asset risk levels, select treatment options—transfer, reduction, or acceptance—and craft a risk treatment plan using the statement of applicability to justify controls and prepare for audits.
The course is a fast track to explaining the basics concepts of ISO27001 with hands-on experience in setting up the processes. Course discusses the standard ISO 27001 process drilled down with an explanation of the practical components. The course first gives a high-level overview of ISO 27001 and discusses the process, Business case, Asset Inventory, Risk Assessment, and Treatment Options.