Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Bereik wereldwijd miljoenen mensen door optimaal gebruik te maken van je kennis.
Meer informatie
Je winkelwagentje is leeg.
Verder winkelen
ISO/IEC 27002. Information security controls
Score 4,5 van de 5(1,565 scores)
7.359 studenten
Laatst bijgewerkt: 10-2025
Engels

Wat je leert

  • Implement an effective information security programme
  • Determine and apply appropriate security controls
  • Achieve compliance with ISO/IEC 27001
  • Understand information security best practices
  • Manage information security risks

Cursusinhoud

6 secties105 collegesTotale lengte van 6u 51m
  • Introduction3:17
  • Information security, cybersecurity and privacy4:12

    About the three concepts: information security, cybersecurity and privacy. The CIA triad (Confidentiality, Integrity, Availability).

  • The ISO/IEC 27000 series of standards4:35

    About the standards in the ISO/IEC 27000 series of standards. Which are the most popular standards in this family and what is their purpose.

    Standards on information security you can find here: https://www.iso.org/committee/45306/x/catalogue/p/1/u/0/w/0/d/0

  • An ISMS according to ISO/IEC 270013:53

    What is a management system and what is an ISMS (Information Security Management System). What does an ISMS consist of. What is the purpose of ISO/IEC 27001 and ISO/IEC 27002.

  • About ISO/IEC 270027:21

    A short history of ISO/IEC 27002. The structure of the standard. The four categories of controls (or themes): Organizational controls, People controls, Physical controls and Technological controls. About the attributes associated to each control in the standard.

Vereisten

  • Familiarity with the ISO/IEC 27000 framework is useful, but not mandatory
  • An understanding of information security management principles

Beschrijving

This course details the information security controls in ISO/IEC 27002:2022.

It is intended to provide an overview of the 93 controls required for an ISMS (Information Security Management System).

The structure of the course includes an introductory section with a presentation of the ISO/IEC 27000 family of international standards, the position and the purpose of ISO/IEC 27002. The introductory section provides definitions for concepts like information security, cybersecurity and privacy and explains what is an ISMS and what it should consist of.

The second section of the course details the 37 Organizational controls in ISO/IEC 27002 including: roles and responsibilities, duties segregation, threat intelligence, information security in project management, information classification and labelling, access control, information transfer, supplier relationships from an information security perspective, ICT continuity, privacy and protection of PII or documented operating procedures as part of an ISMS.

Section three is about security controls that refer to the individuals working for or on behalf of the organization (People controls). It covers aspects like screening, terms and conditions of employment, training and awareness, disciplinary process or remote working.

The next section includes controls that address physical security (Physical controls) including: secure areas, entry controls, clear desk and clear screen, storage media, supporting utilities or the secure re-use and disposal of equipment.

Section number four covers Technological controls that refer to aspects like: the use of endpoint devices, data masking, information deletion, backup, cryptography, logging, networks security, secure development, secure coding, the protection of test information, web filtering, secure authentication, access to source code or the use of privileged utility programs.

The final section of the course provides information on the certification to ISO/IEC 27001 and ISO/IEC 27002 for both organizations and individuals.

This course includes a promotion

Voor wie is deze cursus bedoeld:

  • Information security managers
  • ISMS auditors and consultants
  • Information security management practitioners and enthusiasts
  • Cybersecurity and privacy practitioners
  • Those interested in the ISO 27k framework