Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Cyber incidents, data protection duties and customer due diligence questionnaires have made security assurance a board concern. ISO/IEC 27001 certification is widely sought, but the standard expects organisations to monitor, measure, analyse and evaluate their own performance continually, and many struggle to do so in a meaningful way.
The Monitoring and Evaluation of Cybersecurity & Information Security (ISO 27001) Training Course applies monitoring and evaluation discipline to the information security management system. The first week sets out the standard, risk assessment and treatment, the statement of applicability and the design of measurable objectives and indicators. It then explores data collection from tools, logs, audits and people. The second week moves into evaluation: internal audit practice, control effectiveness testing, trend analysis, incident and nonconformity management, supplier and cloud assurance, resilience exercises and management review.
Practice is central. Participants build a metrics catalogue and dashboard, plan and conduct a mock audit, write findings and corrective actions, and prepare a management review pack. The ten days end with an integrated evaluation project that they can adapt for their own organisation.
By the end of the programme, participants will be able to:
The programme is aimed at professionals who run, assure or evaluate information security, including:
Participants leave with:
The programme blends standards interpretation with applied assurance work. It features:
Delegates who complete all ten days and the integrated project receive a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy. The certificate recognises participation and does not replace an auditor qualification awarded by a certification body.