ISO27001 Boot Camp

Course Description

The object of this course is to provide you with the skills and tools necessary in implementing your own Information Security Management System (ISMS). On this course, you will be taken through the processes, policies and procedures involved in implementation. You will develop a skeleton ISMS which will be ready to use as soon as you go back to the office.

Who should attend?

  • Information Security Consultants;
  • Delegates who have a good understanding of ISO 27001 :2005 and ISO 17799:2005 Information Security Management Systems;
  • Staff tasked with the implementation and management of an ISO 27001:2005 Information Security Management System.

 

What are the benefits of attending this course?

This course will teach you how to develop a skeleton ISMS to an ISO 27001:2005 certificate standard. The skills, tools and procedures that you learn here will enable you to construct and maintain an effective ISMS to protect your business and your customers.

Course Delivery

The course is delivered through a mix of presentations and instructor-led workshops. Participants will work through hands-on exercises to practice all the major phases of the implementation of an ISO27001 and BS25999 compliant Information Security Management System (ISMS). The hands-on exercises are based on a case study and by the end of the course delegates will have developed a skeleton ISO27001 ISMS manual that can be easily applied to their own organization. As part of the course, delegates will also receive useful template documents to help them develop a customized ISMS manual they can use back in the office.

Course Breakdown

Day 1

1. The value of Information Security
2. ISO27001 standard
3. Define the ISMS Scope
4. Writing effective information security policies
5. ISO27001 compliant Risk Management
6. Managing Risks with ISO27005

Day 2

1. Identification of information assets
2. Determination of risk
3. Risk treatment and selection of controls
4. Interpreting Annex A Controls according to ISO27002
5. Producing the Statement of Applicability

Day 3

1. Risk treatment plan and implementation of controls
2. Security awareness training
3. ISO 27001 documentation requirements
4. Developing Internal Audit Plans
5. Selection of Internal Auditors

Day 4

1. ISMS Implementation plan
2. Information security metrics
3. BS25999 and Business Continuity Planning
4. Preparing for ISO27001 Certification
5. The ISO27001 Certification Process according ISO27006
6. Choosing the Certification Body
7. Selecting the right staff and personnel
8. Exam Preparation

Day 5

Examination

 
top