Get in Touch

Course Outline

1. Introduction to ISO/IEC 27001:2023

  • Overview of the ISO/IEC 27001 Information Security Management System (ISMS)
  • Benefits and strategic value of implementing an ISMS
  • The role of ISO 27001 in cybersecurity governance
  • Structure of the ISO 27000 family of standards
  • Core concepts including:
    • Information security
    • Risk management
    • Security controls
    • Continuous improvement
  • Overview of the ISO 27001 certification journey

2. Key Changes in the ISO/IEC 27001:2023 Edition

2.1 What Has Changed?

  • Summary of updates in the ISO 27001:2022/2023 revisions
  • Rationale behind the standard’s revision
  • Alignment with contemporary cybersecurity frameworks
  • Implications for organizations already holding certification

2.2 Scope of Revisions

  • Updates to terminology and structural organization
  • Modifications to requirements across ISO 27001 clauses
  • Impact on existing ISMS documentation
  • Transition guidelines from previous versions
  • Timeline and considerations for migration

2.3 Revised Annex A Security Controls

  • Introduction to the new Annex A framework
  • Shift from 14 control domains to four core themes:
    • Organizational controls
    • People controls
    • Physical controls
    • Technological controls
  • Identification of new and updated security controls
  • Changes to control attributes
  • Determining control applicability

3. Information Security and Risk Management Fundamentals

3.1 Defining Security in Contemporary Organizations

  • Principles of information security:
    • Confidentiality
    • Integrity
    • Availability
  • Business impact of security breaches
  • Security challenges in modern digital environments
  • Balancing security, usability, and business needs

3.2 Risk Management Methodology

  • Identification of information security risks
  • Application of risk assessment methods
  • Exploring risk treatment options
  • Development of risk treatment plans
  • Selection of suitable security controls
  • Creating the Statement of Applicability (SoA)

4. Implementing the ISO 27001:2023 Updates

4.1 Preparation for Transition

  • Evaluation of current ISMS maturity
  • Conducting a gap analysis
  • Identification of necessary updates
  • Revision of policies and procedures
  • Review of existing security controls

4.2 Deployment of Updated Controls

  • Mapping existing controls to the new Annex A structure
  • Assessment of control effectiveness
  • Integration of new security requirements
  • Management of organizational change

4.3 Practical Implementation Case Study

  • Analysis of a sample organization
  • Identification of security gaps
  • Selection of appropriate controls
  • Formulation of improvement recommendations
  • Construction of an implementation roadmap

5. Auditing in Compliance with ISO 27001:2023

5.1 Fundamentals of ISMS Auditing

  • Purpose and core principles of auditing
  • Differences between internal and certification audits
  • Responsibilities of the auditor
  • Defining audit criteria and scope
  • Adopting an evidence-based audit approach

5.2 Planning the ISO 27001 Audit

  • Development of an audit program
  • Preparation of audit checklists
  • Definition of audit objectives
  • Identification of relevant processes and controls
  • Selection of audit methodologies

5.3 Execution of the Audit

  • Holding opening meetings
  • Applying effective interview techniques
  • Reviewing relevant documentation
  • Collection of objective evidence
  • Testing the effectiveness of controls
  • Recording audit observations

6. Managing Audit Findings and Reporting

6.1 Handling Audit Results

  • Identification of nonconformities
  • Classification of findings:
    • Major nonconformities
    • Minor nonconformities
    • Observations
    • Opportunities for improvement
  • Conducting root cause analysis
  • Defining corrective actions

6.2 Audit Reporting

  • Writing clear and effective audit reports
  • Communicating findings to leadership
  • Prioritizing corrective actions
  • Managing follow-up activities

7. Best Practices for ISO 27001 Implementation and Auditing

  • Addressing common implementation challenges
  • Avoiding frequent audit errors
  • Cultivating a strong security culture
  • Sustaining ISMS effectiveness
  • Practices for continuous improvement
  • Integration with other standards:
    • ISO 9001
    • ISO 22301
    • ISO 27701

8. Practical Workshop and Case Analysis

  • Examination of a sample ISMS environment
  • Execution of a gap assessment
  • Identification of applicable controls
  • Formulation of audit questions
  • Evaluation of collected evidence
  • Creation of audit findings
  • Presentation of recommendations

9. Discussion and Wrap-Up

  • Review of ISO 27001:2023 changes
  • Key considerations for auditors
  • Insights gained from case studies
  • Best practices for successful implementation
  • Open Q&A session
  • Additional resources and next steps

Requirements

Target Audience

  • Internal and lead auditors
  • Professionals interested in information security management
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories