Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Cyber attacks and data breaches now rank among the most significant operational risks for organisations of every size. Attackers target weak passwords, unpatched systems, misconfigured cloud services and untrained staff, and the cost of a single incident can include downtime, regulatory penalties, lost customers and legal claims. Many organisations respond with isolated technical purchases, yet resilience comes from a managed system that links risk, policy, technology, people and continual improvement. ISO/IEC 27001 provides the internationally recognised structure for that system.
This ten-day programme combines management system implementation with technical security practice. The first week covers the standard's clauses, context and scope, leadership and policy, asset and information classification, risk assessment methods, risk treatment planning, the Statement of Applicability and the control themes in Annex A. The second week deepens the technical and operational side: identity and access management, cryptography, network and endpoint security, vulnerability and patch management, logging and monitoring, secure development, cloud and supplier security, incident response, forensics basics, business continuity and disaster recovery. It then turns to measurement, internal audit, management review, corrective action and the certification process.
Participants learn through risk workshops, policy drafting, lab exercises, tabletop incident simulations and a closing project in which they assemble the core documentation of an ISMS for a fictional organisation.
By the end of the ten days, participants will be able to:
The programme is intended for professionals who protect, govern or assure information systems, including:
Participants complete the programme with:
The ten days alternate management system work with technical practice, through:
Participants who attend all ten days and complete the labs and the integrated project are awarded a CPD-accredited Certificate of Completion issued by Vision Reach Global Consultancy. The certificate recognises course completion and is not an ISO 27001 auditor qualification.