Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction to ISO/IEC 27001:2023
- Overview of the ISO/IEC 27001 Information Security Management System (ISMS)
- Benefits and strategic value of implementing an ISMS
- The role of ISO 27001 in cybersecurity governance
- Structure of the ISO 27000 family of standards
- Core concepts including:
- Information security
- Risk management
- Security controls
- Continuous improvement
- Overview of the ISO 27001 certification journey
2. Key Changes in the ISO/IEC 27001:2023 Edition
2.1 What Has Changed?
- Summary of updates in the ISO 27001:2022/2023 revisions
- Rationale behind the standard’s revision
- Alignment with contemporary cybersecurity frameworks
- Implications for organizations already holding certification
2.2 Scope of Revisions
- Updates to terminology and structural organization
- Modifications to requirements across ISO 27001 clauses
- Impact on existing ISMS documentation
- Transition guidelines from previous versions
- Timeline and considerations for migration
2.3 Revised Annex A Security Controls
- Introduction to the new Annex A framework
- Shift from 14 control domains to four core themes:
- Organizational controls
- People controls
- Physical controls
- Technological controls
- Identification of new and updated security controls
- Changes to control attributes
- Determining control applicability
3. Information Security and Risk Management Fundamentals
3.1 Defining Security in Contemporary Organizations
- Principles of information security:
- Confidentiality
- Integrity
- Availability
- Business impact of security breaches
- Security challenges in modern digital environments
- Balancing security, usability, and business needs
3.2 Risk Management Methodology
- Identification of information security risks
- Application of risk assessment methods
- Exploring risk treatment options
- Development of risk treatment plans
- Selection of suitable security controls
- Creating the Statement of Applicability (SoA)
4. Implementing the ISO 27001:2023 Updates
4.1 Preparation for Transition
- Evaluation of current ISMS maturity
- Conducting a gap analysis
- Identification of necessary updates
- Revision of policies and procedures
- Review of existing security controls
4.2 Deployment of Updated Controls
- Mapping existing controls to the new Annex A structure
- Assessment of control effectiveness
- Integration of new security requirements
- Management of organizational change
4.3 Practical Implementation Case Study
- Analysis of a sample organization
- Identification of security gaps
- Selection of appropriate controls
- Formulation of improvement recommendations
- Construction of an implementation roadmap
5. Auditing in Compliance with ISO 27001:2023
5.1 Fundamentals of ISMS Auditing
- Purpose and core principles of auditing
- Differences between internal and certification audits
- Responsibilities of the auditor
- Defining audit criteria and scope
- Adopting an evidence-based audit approach
5.2 Planning the ISO 27001 Audit
- Development of an audit program
- Preparation of audit checklists
- Definition of audit objectives
- Identification of relevant processes and controls
- Selection of audit methodologies
5.3 Execution of the Audit
- Holding opening meetings
- Applying effective interview techniques
- Reviewing relevant documentation
- Collection of objective evidence
- Testing the effectiveness of controls
- Recording audit observations
6. Managing Audit Findings and Reporting
6.1 Handling Audit Results
- Identification of nonconformities
- Classification of findings:
- Major nonconformities
- Minor nonconformities
- Observations
- Opportunities for improvement
- Conducting root cause analysis
- Defining corrective actions
6.2 Audit Reporting
- Writing clear and effective audit reports
- Communicating findings to leadership
- Prioritizing corrective actions
- Managing follow-up activities
7. Best Practices for ISO 27001 Implementation and Auditing
- Addressing common implementation challenges
- Avoiding frequent audit errors
- Cultivating a strong security culture
- Sustaining ISMS effectiveness
- Practices for continuous improvement
- Integration with other standards:
- ISO 9001
- ISO 22301
- ISO 27701
8. Practical Workshop and Case Analysis
- Examination of a sample ISMS environment
- Execution of a gap assessment
- Identification of applicable controls
- Formulation of audit questions
- Evaluation of collected evidence
- Creation of audit findings
- Presentation of recommendations
9. Discussion and Wrap-Up
- Review of ISO 27001:2023 changes
- Key considerations for auditors
- Insights gained from case studies
- Best practices for successful implementation
- Open Q&A session
- Additional resources and next steps
Requirements
Target Audience
- Internal and lead auditors
- Professionals interested in information security management
14 Hours