Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Every organisation now depends on information systems, and every one is a target. Attacks no longer need sophistication to succeed; weak passwords, unpatched servers, over-privileged accounts and untrained staff provide plenty of openings. Security that is limited to a few tools tends to decay, which is why standards-based management matters alongside technical skill.
This ten-day course is split deliberately between practice and management. The opening days establish the threat landscape and the fundamentals of securing networks, operating systems, applications and cloud services, with laboratory exercises in scanning, hardening, access control, encryption and log analysis. Participants learn how to detect problems, prioritise vulnerabilities and contain an incident. The second part introduces ISO/IEC 27001 and shows how to build an information security management system around real risks: defining scope, assessing and treating risk, selecting controls, writing policies and procedures, training staff and measuring performance.
The last days address supplier and cloud risk, business continuity, internal audit and certification readiness. Delegates finish with a documented set of risk and control artefacts for their own organisation, and a team simulation that tests detection, response and reporting under time pressure.
By the end of the course, participants will be able to:
The course is meant for people who secure, manage or assure information systems, including:
Participants leave the course with:
This is a laboratory-based programme in which concepts are always followed by practice:
Participants who attend the ten days and complete the labs and workshops receive a CPD-accredited Certificate of Completion from Vision Reach Global Consultancy. It confirms training completed and is not an ISO 27001 auditor qualification.