ISO/IEC 27002 Introduction Training Course
Why participate in this course?
The ISO/IEC 27002 Introduction training course allows you to gain a comprehensive understanding of Information Security Management Systems (ISMS) and Information Security Controls as outlined in ISO/IEC 27002.
By attending this course, you will appreciate the significance of ISMS and Information Security Controls, as well as the advantages they bring to businesses, society, and governmental bodies.
Who is this course for?
- Professionals with an interest in Information Security Management and Information Security Controls.
- Individuals aiming to acquire knowledge about the core processes of Information Security Management Systems and Information Security Controls.
Learning objectives
- Comprehend the Information Security standards and management practices utilized to implement and manage Information Security Controls.
- Identify the controls required to effectively manage Information Security risks.
Course Outline
ISMS Foundations & ISO/IEC 27002 Framework (90 min)
- Structure of the ISO/IEC 27000 family and its relationship to ISO/IEC 27001 certification.
- Core principles of a dynamic Information Security Management System.
- Four control themes: Organizational, People, Physical, and Technological.
- Benefits of ISO/IEC 27002 for organizations, regulators, and public trust.
- Activity: Security maturity self-assessment and gap identification exercise.
Deep Dive into the 93 ISO/IEC 27002 Controls (120 min)
- Structure of the 2022 revision: themes, categories, and control objectives.
- Key controls: Access management, cryptography, operational security, supplier relationships, compliance, and incident response.
- Distinguishing between mandatory and guideline controls, along with implementation flexibility.
- Activity: Control categorization workshop and real-world scenario mapping.
Risk Linkage, Implementation & Evidence Mapping (120 min)
- Linking controls to risk assessment and treatment plans.
- Implementation strategies: policy development, technical deployment, and process integration.
- Compliance evidence, audit readiness, and continuous monitoring practices.
- Activity: Creating a mini risk-treatment matrix and a control evidence checklist.
Operationalization, Framework Alignment & Next Steps (60 min)
- Common pitfalls and best practices for adopting controls at scale.
- Aligning ISO/IEC 27002 with regulatory frameworks (such as GDPR, NIST CSF, HIPAA, etc.).
- Pathways to certification, advanced training, and planning organizational rollout.
- Capstone Exercise: Group scenario mapping and drafting a 90-day control implementation roadmap.
- Q&A session, distribution of resources, and course conclusion.
Open Training Courses require 5+ participants.
ISO/IEC 27002 Introduction Training Course - Booking
ISO/IEC 27002 Introduction Training Course - Enquiry
ISO/IEC 27002 Introduction - Consultancy Enquiry
Testimonials (1)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Upcoming Courses
Related Courses
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in Czech Republic (online or on-site) is designed for advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
Upon completing this training, participants will be able to:
- Acquire a thorough understanding of fraud examination principles and the examination process.
- Learn to identify, investigate, and prevent various forms of financial fraud schemes.
- Understand the legal framework surrounding fraud, including its legal elements, relevant laws, and regulations.
- Gain practical skills in conducting fraud investigations, such as evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Build the confidence and knowledge necessary to successfully pass the Certified Fraud Examiner (CFE) exam.
Compliance for Payment Services in Japan
7 HoursThis instructor-led, live training in Czech Republic (online or onsite) is designed for compliance professionals in the payment services sector who wish to create, implement, and enforce a compliance program within an organization.
By the end of this training, participants will be able to:
- Understand the rules set forth by government regulators for payment service providers.
- Create the internal policies and procedures needed to satisfy government regulations.
- Implement a compliance program that adheres to relevant laws.
- Ensures that all corporate processes and procedures comply with the compliance program.
- Uphold the business's reputation while protecting it from lawsuits.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) targets intermediate-level cybersecurity professionals aiming to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers an expert introduction to the newly enacted Accessibility Law, equipping developers with the practical skills necessary to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's importance and implications, the course rapidly transitions to hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
GDPR - Certified Data Protection Officer
35 HoursThe PECB Certified Data Protection Officer training course equips you with the essential knowledge and skills, fostering the competence required to effectively perform the duties of a data protection officer within a GDPR compliance initiative.
Why should you attend?
As data protection gains increasing importance, the demand for organizations to safeguard this data continues to grow. Non-compliance with data protection regulations not only infringes upon the fundamental rights and freedoms of individuals but also exposes organizations to significant risks that can damage their credibility, reputation, and financial standing. This is precisely where your expertise as a data protection officer becomes invaluable.
The PECB Certified Data Protection Officer training course is designed to help you acquire the knowledge and skills needed to serve as a Data Protection Officer (DPO), thereby assisting organizations in meeting the requirements of the General Data Protection Regulation (GDPR).
Through practical exercises, you will master the DPO role, becoming proficient in informing, advising, and monitoring GDPR compliance, as well as cooperating with supervisory authorities.
Upon completing the training course, you may sit for the examination. Successful candidates can apply for the “PECB Certified Data Protection Officer” credential. This internationally recognized certificate demonstrates your professional capability and practical knowledge in advising controllers and processors on fulfilling their GDPR compliance obligations.
Who should attend?
- Managers or consultants looking to prepare and support an organization in planning, implementing, and maintaining a GDPR-based compliance program
- DPOs and personnel responsible for maintaining conformance with GDPR requirements
- Members of information security, incident management, and business continuity teams
- Technical and compliance professionals preparing for a data protection officer role
- Expert advisors involved in personal data security
Learning objectives
- Understand GDPR concepts and interpret its requirements
- Grasp the content and relationship between the General Data Protection Regulation and other regulatory frameworks and applicable standards, such as ISO/IEC 27701 and ISO/IEC 29134
- Gain the competence to perform the DPO role and execute daily tasks within an organization
- Develop the ability to inform, advise, and monitor GDPR compliance, and to cooperate with supervisory authorities
Educational approach
- This training course combines theoretical foundations with best practices for exercising the DPO role.
- Lecture sessions are supported by practical exercises based on case studies, including role-playing and discussions.
- Participants are encouraged to interact, engage in discussions, and take part in exercises.
- Practice exercises and quizzes mirror the format of the certification exam.
General Information
- Participants will receive training course materials comprising over 450 pages of explanatory content and practical examples.
- An Attendance Record worth 31 CPD (Continuing Professional Development) credits will be issued to those who complete the training course.
HiTrust Common Security Framework Compliance
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) is aimed at developers and administrators who wish to produce software and products that are HiTRUST compliant.
By the end of this training, participants will be able to:
- Understand the key concepts of the HiTrust CSF (Common Security Framework).
- Identify the HITRUST CSF administrative and security control domains.
- Learn about the different types of HiTrust assessments and scoring.
- Understand the certification process and requirements for HiTrust compliance.
- Know the best practices and tips for adopting the HiTrust approach.
Interpretation of Environmental Management System Standard ISO 14001:2015
24 HoursISO 14001:2015 serves as an international benchmark for creating, executing, and enhancing an Environmental Management System (EMS).
This guided, live training session, available either online or in person, is designed for professionals at beginner and intermediate levels who aim to grasp, interpret, and implement the requirements of ISO 14001:2015 within their respective organizations.
After finishing this workshop, participants will be equipped to:
- Interpret the framework, requirements, and objectives of ISO 14001:2015.
- Recognize environmental aspects and associated risks in accordance with the standard.
- Assess the organizational context and the duties of leadership.
- Evaluate operational controls, performance indicators, and improvement mechanisms.
Course Format
- Guided presentations accompanied by real-world examples.
- Hands-on exercises, case studies, and scenario-based discussions.
- Interactive sessions focused on interpreting and applying ISO 14001:2015 requirements.
Customization Options
- To adapt this course to meet your organization’s specific EMS needs, please reach out to us to explore customization possibilities.
Applied Interpretation and Implementation of ISO 20560 for Industrial Safety Signage
21 HoursISO 20560 is a worldwide standard establishing unified safety signage and pipe marking systems for industrial settings.
This instructor-led training, available online or on-site, is designed for advanced-level industrial and safety professionals seeking to apply ISO 20560 requirements in practical operational contexts.
Upon completing this training, participants will be able to:
- Accurately interpret the structure, terminology, and application guidelines of ISO 20560.
- Design and implement compliant safety signage and pipe identification systems.
- Evaluate risks related to industrial substances and processes through standardized visual communication.
- Adapt ISO 20560 requirements to local regulations and specific sector needs, including those in cosmetic manufacturing environments.
Course Format
- Expert-led presentations coupled with guided discussions.
- Scenario-based exercises and applied workshops.
- Hands-on evaluation of signage and pipe marking within simulated industrial setups.
Course Customization Options
- To tailor this course to your organization’s operational context or facility layout, please contact us to arrange a customized session.
ISO 10012:2003 – Measurement Management Systems
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) is aimed at intermediate-level quality and measurement professionals who wish to implement, audit, or improve a measurement management system based on ISO 10012:2003 to support quality assurance and regulatory compliance.
By the end of this training, participants will be able to:
- Understand the structure, scope, and intent of ISO 10012:2003.
- Implement a measurement management system that ensures equipment reliability and measurement traceability.
- Define roles, responsibilities, and documentation required for measurement control.
- Integrate ISO 10012 with broader quality and risk management frameworks (e.g., ISO 9001, ISO/IEC 17025).
ISO 14001:2015 Internal Auditor of the Environmental Management System
35 HoursObjectives
- Gain knowledge of ISO 14001:2015.
- Learn how to perform audits in accordance with the standard.
- Explore and understand best practices.
ISO 27002 Lead Manager
35 HoursThe PECB ISO/IEC 27002 Lead Manager training program equips you with the essential expertise and knowledge required to assist an organization in implementing and managing Information Security controls in accordance with ISO/IEC 27002.
Upon successful completion of this course, you will be eligible to take the exam and apply for the "PECB Certified ISO/IEC 27002 Lead Manager" credential. This PECB Lead Manager Certification validates your mastery of the principles and techniques necessary for the implementation and management of Information Security Controls based on ISO/IEC 27002.
Who should attend?
- Managers or consultants aiming to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 and ISO/IEC 27002
- Project managers or consultants seeking to master the implementation process of an Information Security Management System
- Individuals responsible for information security, compliance, risk, and governance within an organization
- Members of information security teams
- Expert advisors in information technology
- Information Security officers
- Privacy officers
- IT professionals
- CTOs, CIOs, and CISOs
Learning objectives
- Master the implementation of Information Security controls by adhering to the framework and principles of ISO/IEC 27002
- Gain a comprehensive understanding of the concepts, approaches, standards, methods, and techniques required for the effective implementation and management of Information Security controls
- Comprehend the relationship between the components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance, and human behavior
- Understand the importance of information security for organizational strategy
- Master the implementation of information security management processes
- Master the formulation and implementation of security requirements and objectives
Educational approach
- This training integrates both theory and practice
- Lecture sessions illustrated with examples based on real-world cases
- Practical exercises based on case studies
- Review exercises designed to assist with exam preparation
- Practice tests similar to the certification exam
General Information
- Certification fees are included in the exam price
- Training material containing over 500 pages of information and practical examples will be distributed to participants
- A participation certificate granting 31 CPD (Continuing Professional Development) credits will be issued to participants
- In the event of an exam failure, you may retake the exam within 12 months free of charge
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 are globally recognized benchmarks for quality management and information security management systems, respectively.
This instructor-led live training, available either online or in-person, targets intermediate-level professionals aiming to master the interpretation of ISO 9001 and ISO 27001 standards and conduct effective internal audits.
Upon completion of this training, participants will be capable of:
- Grasping the core principles and requirements of both ISO 9001 and ISO 27001.
- Interpreting specific clauses and controls within practical business contexts.
- Planning and executing internal audits that align with ISO standards.
- Identifying nonconformities and proposing appropriate corrective actions.
Course Format
- Engaging lectures paired with interactive discussions.
- Simulated auditing exercises and real-world case studies.
- Practical analysis of quality and security scenarios.
Customization Options
- To arrange a tailored version of this course, please reach out to us for customization details.
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This course is designed for all employees seeking a practical grasp of Compliance and effective Risk Management.
Course Format
The training utilizes a blended methodology that encompasses:
- Guided discussions
- Slide-driven presentations
- Case studies
- Practical real-world examples
Course Objectives
Upon completion, participants will be equipped to:
Gain a robust understanding of key Compliance principles, alongside national and international initiatives focused on managing related risks.
Articulate how organizations and their teams can implement an effective Compliance Risk Management Framework.
Outline the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles fit within a business structure.
Pinpoint critical risk areas within Financial Crime, particularly concerning international operations, offshore centers, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves supervising the lifecycle of open-source components within an organization to guarantee secure, compliant, and efficient utilization.
This instructor-led, live training (available online or onsite) targets intermediate-level IT professionals looking to apply best practices for managing open-source software in enterprise and government settings.
Upon completing this training, participants will be capable of:
- Developing effective OSS policies and governance frameworks.
- Utilizing SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Reducing risks linked to licensing and security vulnerabilities.
- Optimizing OSS adoption to enhance innovation and reduce costs.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Practical demonstrations with OSS management tools.
Customization Options
- The course can be tailored to fit specific organizational OSS policies and toolchains. Please contact us to arrange this.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Czech Republic (online or onsite) grants an individual qualification to industry practitioners seeking to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
Upon completion of this training, participants will be able to:
- Comprehend the payment process and the PCI standards established to protect it.
- Understand the roles and responsibilities of entities involved in the payment industry.
- Gain deep insight into and understanding of the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and its application to organizations involved in the transaction process.