
This video provides a very high level overview of the content of the course
Understand what is ISO27001, the Global Standard for Information Security. In this video we talk about the CIA of Information Security and the PDCA Cycle (Plan, Do, Check, Act)
Understand what we mean by scope and how it applies within ISO 27001
What do we mean by Risk, and how does it apply to ISO 27001. Understand the basics of Risk Analysis.
What is a Control? And how are controls used within ISO 27001? Controls address risks. Understand the basics of ISO 27001 Mandatory and Optional Controls. How is the response to Control requirements shown? In the Statement of Applicability - what is this document?
What documentation is required for ISO 27001? There are mandatory and optional documents. This section will give an understanding of some of the documentation required.
ISO 27001 requires that you keep a record of all assets - physical and digital. What are information assets? What do we mean by the Classification of those assets?
ISO 27001 requires that you measure how effective your controls are. What does this mean? After watching this short video you will have a basic understanding of measurement.
This section provides guidance in terms of implementing the standard in your organization. There are a number of steps which are described here.
It is possible to implement ISO 27001 but not officially certify - which requires an audit by an external party. So why certify? There are a number of benefits to certifying to the ISO 27001 standard, and some are discussed here.
This final lecture discusses the steps to certification, and how the process works.
This is a short quiz to test your understanding of the basics of ISO 27001.
ISO 27001 is the Global Standard for Information Security. If you're interested in protecting your assets and information against attacks, this is for you!
ISO 27001 is a framework for efficient and comprehensive protection of what is vitally important to your business.
If you know little about the standard, and want to know more, then this series of short video lectures will help you to understand what is ISO 27001 and what is required to implement it.
In these short lectures we talk briefly about the following topics:
Scope - What do we mean by Scope in the context of ISO 27001?
Risk - You need to measure and control the Risks to your business. We talk about the basics of Risk Analysis.
Controls - What controls to you need to put in place to address the risks you have identified. What is meant by Controls? We discuss Mandatory and Optional Controls.
Documentation - A very important document in ISO 27001 is the Statement of Applicability. What is it and what does it contain?
Documentation - What other documentation is required for ISO 27001? Some are mandatory and some optional.
Assets - There are two types of Assets, Digital and Physical. How do you record these in ISO 27001?
Measurement - ISO 27001 requires you to measure how effective your controls are. How do you do that?
Implementation - We provide information on how best to implement the standard in your organization. What steps are required.
Certification - It is not compulsory, but should you choose to certify to the standard, what is involved and how best should you do it?
At the end of the course is a short test, and after completing the course you should have a good basic understanding of the Global Standard, the main features and requirements, and some guidance on how to implement it.