Full Programme
Everything covered in this programme, so you can confirm it's the right fit before you complete your registration above.
Cyber incidents now interrupt hospitals, banks, ministries and aid agencies, and the cost of a breach reaches far beyond the technical clean-up to legal exposure, lost funding and damaged trust. Customers and partners increasingly require independent assurance, and ISO/IEC 27001 has become the most widely recognised framework for demonstrating that information security is managed systematically rather than through scattered tools.
This ten-day programme takes participants from strategic principles to hands-on control implementation. Early modules establish the context of the organisation, leadership responsibilities, scope, risk assessment and treatment, and the structure of the standard and its Annex A controls. Middle modules apply these to people, physical, organisational and technological controls, including access management, secure configuration, endpoint and network defence, cloud services, application security and data protection. Later modules cover security operations, incident response, resilience and recovery, internal audit techniques and the preparation of evidence for certification.
Teaching combines concept sessions with labs on risk registers, policy drafting, log review and tabletop exercises. By the end, each participant has built a working ISMS document set for a case organisation and an implementation roadmap for their own.
By the end of the course, participants will be able to:
The course is intended for professionals who lead, implement or assure information security, including:
Participants leave the course with:
The ten days balance standard interpretation with technical practice through:
Participants who complete the ten days of sessions, labs and the capstone project are awarded a CPD-accredited Certificate of Completion by Vision Reach Global Consultancy. It records training attended and is not a certification body credential.