Clients, regulators and funders increasingly ask whether an organisation can prove it protects information, and a ransomware outage or data leak can end that conversation. Ten days walk security and IT professionals through building an information security management system that stands up to scrutiny. You define context, interested parties and scope, secure leadership commitment, write the information security policy, and run a structured risk assessment using asset registers, threat and vulnerability analysis, and treatment plans. From there you draft the Statement of Applicability and select controls from ISO/IEC 27001 Annex A, covering access management, cryptography, logging, supplier security, incident response, business continuity and secure development.
The later days go beyond paperwork to technical safeguards and assurance: network and endpoint hardening, vulnerability management, awareness programmes, metrics, internal audit, management review, nonconformity handling and preparation for a certification audit. CISOs, security officers, IT managers, risk and compliance staff, internal auditors and systems administrators in banks, telecoms, government and technology firms are the target group. Classroom, online and in-house delivery are offered, with a CPD-accredited certificate. You finish with an implementation roadmap and a core document set ready to adapt.
Cyber incidents now rank among the most disruptive risks any organisation faces, and the pressure to demonstrate good practice comes from every side: customers in tender documents, regulators in data protection and sector rules, insurers and donors in due diligence questionnaires. ISO/IEC 27001 offers a recognised, auditable way to show that security is managed rather than improvised.
The Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course is a practical ten-day journey through the standard's requirements and the work needed to meet them. The first week covers the structure of the standard, scoping, leadership, policy, asset inventory, risk methodologies and the Statement of Applicability. The second week concentrates on implementing and testing controls, including technical measures, people and supplier security, incident management and continuity, followed by internal audit, management review and certification preparation.
Throughout, participants build the documents and records an auditor expects, using templates and a running case organisation. The course emphasises proportionate, risk-based decisions so that smaller institutions can adopt the same logic as large ones, and closes with a roadmap participants can take straight back to work.
By the end of the programme, participants will be able to:
Participants complete the programme with:
The programme is workshop-driven, using a single case organisation across the ten days, with:
Day 1: Foundations of Information Security
Day 2: Context, Leadership and Scope
Day 3: Security Policy and Asset Management
Day 4: Risk Assessment
Day 5: Risk Treatment and the Statement of Applicability
Day 6: Access, Cryptography and Operations Security
Day 7: Network, Cloud and Secure Development
Day 8: People, Suppliers and Physical Security
Day 9: Incident Response and Business Continuity
Day 10: Audit, Review and Certification Readiness
The programme is designed for professionals who plan, run or assess information security, including:
Participants who attend the programme and complete the workshops and labs receive a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy.
The certificate evidences training completed and does not constitute ISO 27001 lead implementer or auditor certification.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Planning and Implementation of Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the clauses of iso/iec 27001 and how the management system cycle operates, define context, scope and information security objectives for an organisation, conduct an information security risk assessment and produce a risk treatment plan, and prepare a statement of applicability and select annex a controls with justification. The full breakdown of topics is covered session by session in the Course Outline tab above.
The programme is designed for professionals who plan, run or assess information security, including: Chief information security officers and security managers, IT managers and heads of infrastructure, Information security and risk officers, Compliance, privacy and data protection officers, Internal and IT auditors, Network, systems and cloud administrators, Project managers leading certification projects, and Consultants supporting ISMS implementation in banks, telecoms and public bodies.
Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Planning and Implementation of Cybersecurity & Information Security (ISO 27001) starts October 26, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course is pitched at intermediate professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Planning and Implementation of Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →