Ransomware, phishing, insider misuse and supplier breaches now reach organisations of every size, and boards, regulators and customers expect proof that information is protected by a managed system rather than ad hoc tools. Ten days take you from the principles of security management to a working ISO 27001 information security management system. You define scope and context, secure leadership commitment, carry out asset-based risk assessment and treatment, and write the Statement of Applicability. Control sessions work through the Annex A themes, including access control, cryptography, operations security, network security, supplier relationships and physical protection.
The second week goes deeper into technical and applied topics: vulnerability management, logging and monitoring, incident response, business continuity, cloud security, secure development and privacy alignment. You also plan internal audits, management review and corrective action, and finish with an integrated project that assembles an implementation plan. The programme suits information security managers, IT managers, risk and compliance officers, auditors, system administrators and data protection officers in banks, telecoms, government and NGOs. It runs in person, online or in-house, and ends with a CPD-accredited certificate. You leave able to lead an implementation or certification readiness project.
Cyber incidents have become a routine business risk across Africa. Mobile money platforms, digital government services and cloud adoption have widened the attack surface, while skilled security managers remain scarce. Customers, donors and regulators increasingly ask suppliers and partners whether their security practices are independently assessed, and ISO/IEC 27001 has become the common reference for answering that question.
The Management of Cybersecurity & Information Security (ISO 27001) Training Course is a ten-day programme that covers both management and technical foundations. The first week builds the management system: context, scope, leadership, policy, roles, risk assessment methodology, risk treatment and the Statement of Applicability, followed by a structured walk through the control themes in Annex A. The second week develops depth in vulnerability management, security operations, incident handling, resilience, cloud and application security, privacy, supplier assurance and metrics, and then prepares participants for internal audit and certification audit.
Participants work throughout on a fictional but realistic organisation, producing the documents and records an auditor would expect to see. Hands-on labs with common security tools make the controls tangible. The course supports those preparing to lead implementation, but it does not replace formal lead implementer or lead auditor certification examinations.
By the end of the course, participants will be able to:
Participants complete the programme with practical outputs, including:
The programme combines management practice with technical exposure over ten days. Participants will experience:
Day 1: Information Security Concepts and the Threat Landscape
Day 2: Context, Leadership and Scope
Day 3: Risk Assessment
Day 4: Risk Treatment and the Statement of Applicability
Day 5: Organisational and People Controls
Day 6: Technological Controls and Network Security
Day 7: Vulnerability Management, Logging and Monitoring
Day 8: Incident Response and Business Continuity
Day 9: Cloud, Suppliers, Development and Privacy
Day 10: Audit, Improvement and Integrated Project
The programme suits people who design, run or assure security in organisations, including:
Participants who attend the ten days and complete the labs and project receive a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy. It records the learning undertaken and is separate from any external ISO 27001 certification examination.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Management of Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the structure and requirements of iso/iec 27001 and the role of iso/iec 27002 guidance, define isms scope and interested parties, then carry out asset-based risk assessment and select treatment options, prepare a statement of applicability and justify control choices, and implement organisational, people, physical and technological controls from annex a. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme suits people who design, run or assure security in organisations, including: Information security managers and chief information security officers, IT managers and heads of infrastructure, Network and systems administrators, Risk, compliance and internal audit professionals, Data protection officers and privacy managers, Business continuity and disaster recovery coordinators, Software development and DevOps leads, Government ICT officers and telecom security teams, and Consultants preparing clients for certification.
Management of Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Management of Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Management of Cybersecurity & Information Security (ISO 27001) starts October 19, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Management of Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Management of Cybersecurity & Information Security (ISO 27001) Training Course is pitched at intermediate professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Management of Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Management of Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →