Get in Touch

Course Outline

ISMS Foundations & The ISO/IEC 27002 Framework (90 minutes)

  • The structure of the ISO/IEC 27000 family and its connection to ISO/IEC 27001 certification
  • Key principles underpinning a dynamic Information Security Management System
  • The four primary control themes: Organizational, People, Physical, and Technological
  • The value ISO/IEC 27002 delivers to organizations, regulators, and public trust
  • Activity: Conduct a security maturity self-assessment and identify gaps

Comprehensive Review of the 93 ISO/IEC 27002 Controls (120 minutes)

  • Overview of the 2022 revision: themes, categories, and control objectives
  • Essential controls covering access management, cryptography, operational security, supplier relationships, compliance, and incident response
  • Distinguishing between mandatory and guideline controls, along with implementation flexibility
  • Activity: Participate in a control categorization workshop and map real-world scenarios

Linking Risk, Implementation, and Evidence Mapping (120 minutes)

  • Integrating controls with risk assessment and treatment planning
  • Implementation strategies such as policy development, technical deployment, and process integration
  • Managing compliance evidence, preparing for audits, and adopting continuous monitoring practices
  • Activity: Develop a mini risk-treatment matrix and a control evidence checklist

Operationalizing the Framework, Alignment, and Next Steps (60 minutes)

  • Common challenges and best practices for scaling control adoption
  • Aligning ISO/IEC 27002 with regulatory frameworks such as GDPR, NIST CSF, HIPAA, and others
  • Roadmaps for certification, advanced training, and organizational rollout planning
  • Capstone Exercise: Engage in group scenario mapping and draft a 90-day control implementation roadmap
  • Q&A session, resource distribution, and course closure
 7 Hours

Testimonials (2)

Related Categories