BSI’s “Implementing ISO/IEC 27001:2005” course provides an overview of the latest techniques and examines issues surrounding Information Security Management Systems (ISMS). This course details the requirements for implementing a formal management system as specified in ISO/IEC 27001:2005 and outlines information security issues including methods of control and countermeasures for threats. Experienced instructors lead students to help them understand the processes required to implement and manage information security. Exercises and discussions teach students how to implement controls and how to integrate ISMS activities with business and other security objectives.
Learning objectives
- Understand the specific requirements for an ISMS
- Identify uses of ISMS controls
- Determine and assess risk to information security
- Understand the design and implementation of an ISMS
- Understand definitions of policies, standards, and procedures
- Recognize the importance of auditing and reviewing an ISMS
- Understand ISMS documentation
- Understand the implementation process
Course materials
Students receive comprehensive course manuals with reference materials.
Who should attend
- IT Security Officers
- IT Managers
- Management Systems Managers
- Professionals involved in introducing ISO/IEC 27001:2005 and ISO/IEC 27002:2005 into an organization
- Chief Security Officers
- Information Security Consultants
Prerequisite
A prior review of ISO/IEC 27001:2005 and knowledge of information security practices is strongly suggested.