Ransomware, phishing, insider misuse and cloud misconfiguration threaten every organisation that holds data, and clients, regulators and donors increasingly ask for proof of a managed security programme. Over ten days, security and IT leaders learn to build that programme around the ISO/IEC 27001 standard and to connect it to business strategy. The first week covers threat landscape, governance, scoping the information security management system, asset inventories, risk assessment methods, the statement of applicability and policy writing.
The second week moves into technical and operational depth: Annex A control families, identity and access management, network and cloud security, cryptography, vulnerability management, logging and monitoring, supplier security, business continuity and incident handling with forensic basics. Final sessions address internal audit, management review, certification audit preparation and a capstone ISMS project. Chief information security officers, IT managers, security analysts, risk and compliance officers, auditors and system administrators in banks, telecoms, government and NGOs are the intended audience. Classroom, online and in-house options lead to a CPD-accredited certificate. You return able to scope an ISMS, justify controls and brief executives with evidence.
Cyber incidents now interrupt hospitals, banks, ministries and aid agencies, and the cost of a breach reaches far beyond the technical clean-up to legal exposure, lost funding and damaged trust. Customers and partners increasingly require independent assurance, and ISO/IEC 27001 has become the most widely recognised framework for demonstrating that information security is managed systematically rather than through scattered tools.
This ten-day programme takes participants from strategic principles to hands-on control implementation. Early modules establish the context of the organisation, leadership responsibilities, scope, risk assessment and treatment, and the structure of the standard and its Annex A controls. Middle modules apply these to people, physical, organisational and technological controls, including access management, secure configuration, endpoint and network defence, cloud services, application security and data protection. Later modules cover security operations, incident response, resilience and recovery, internal audit techniques and the preparation of evidence for certification.
Teaching combines concept sessions with labs on risk registers, policy drafting, log review and tabletop exercises. By the end, each participant has built a working ISMS document set for a case organisation and an implementation roadmap for their own.
By the end of the course, participants will be able to:
Participants leave the course with:
The ten days balance standard interpretation with technical practice through:
Day 1: Cybersecurity Landscape and Governance
Day 2: Context, Leadership and Scope
Day 3: Asset Inventory and Risk Assessment
Day 4: Risk Treatment and Statement of Applicability
Day 5: Policies, People and Physical Security
Day 6: Identity, Access and Network Security
Day 7: Cloud, Application and Data Security
Day 8: Vulnerability Management and Security Operations
Day 9: Incident Response, Continuity and Resilience
Day 10: Audit, Certification and Continual Improvement
The course is intended for professionals who lead, implement or assure information security, including:
Participants who complete the ten days of sessions, labs and the capstone project are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. It records training attended and is not a certification body credential.
Upcoming cohorts
CPD-Accredited
Official invoice & confirmation letter provided
Team discount for 3+ seats
Need help with this booking?
Our training team can help with group pricing, invoicing, or picking the right schedule.
Everything you need to know about this course before you register.
By the end of the Strategic Cybersecurity & Information Security (ISO 27001) programme, you'll be able to explain the requirements of iso/iec 27001 and how its clauses and annex a controls fit together, define the scope and context of an information security management system, conduct asset-based risk assessments and prepare treatment plans and a statement of applicability, and select and implement organisational, people, physical and technological controls. The full breakdown of topics is covered session by session in the Course Outline tab above.
The course is intended for professionals who lead, implement or assure information security, including: Chief information security officers and heads of IT, Information security managers and analysts, IT risk, compliance and governance officers, Internal and external IT auditors, Network, systems and cloud administrators, Data protection officers, Business continuity and disaster recovery managers, and Security consultants supporting ISO 27001 projects.
Strategic Cybersecurity & Information Security (ISO 27001) Training Course typically runs as 10 Days. It's available as in-person classroom, live virtual, and in-house corporate training — every course can also be delivered on-site for your team on dates that suit you.
Strategic Cybersecurity & Information Security (ISO 27001) Training Course is scheduled in-classroom in Nairobi, Kenya, Mombasa, Kenya, Naivasha, Kenya, and Kisumu, Kenya, and 14 other locations, plus a live interactive virtual classroom you can join from anywhere. Check the schedule panel above for exact upcoming dates and fees in each location.
The next live virtual cohort of Strategic Cybersecurity & Information Security (ISO 27001) starts October 26, 2026, with new classroom cohorts also running on a rolling basis. Pick a date and location in the schedule panel above, then click "Register for the Course" — it takes a few minutes and your seat is confirmed once payment or a signed purchase order is received.
Yes — delegates who meet the attendance requirement receive a Certificate of Completion for Strategic Cybersecurity & Information Security (ISO 27001) Training Course from Vision Reach Global Consultancy, issued in the name you register with, so double-check the spelling at checkout.
Strategic Cybersecurity & Information Security (ISO 27001) Training Course is pitched at advanced professionals. If you're unsure whether it's the right fit for your current role or background, message our training advisors before you register and they'll help you confirm.
Fees for Strategic Cybersecurity & Information Security (ISO 27001) Training Course vary by delivery location and format and are shown in real time in the schedule panel above once you pick a date. Register 3 or more delegates on the same course together and a 5% team discount is applied automatically — larger cohorts can request a custom corporate quote.
Yes — Strategic Cybersecurity & Information Security (ISO 27001) Training Course can be delivered on-site at your offices (or virtually for distributed teams), with case studies and examples tailored to your industry and the specific challenges your team is working through. Switch to the "In-House" tab in the schedule panel above to request a proposal.
Related Training
Swipe to see more courses →