Implementer of Information Security, Cybersecurity, and Privacy Protection Risk Management (ISO/IEC 27001, ISO/IEC 27005)
The course programme is structured progressively, beginning with the fundamental requirements of ISO/IEC 27001 and advancing to a practical roadmap for implementing the information security risk management process in accordance with the approaches of ISO/IEC 27005. Participants gain an understanding of how to establish an information security management system (ISMS), identify information assets, risks, threats, and vulnerabilities, select appropriate security controls, develop a risk register, prepare the Statement of Applicability (SoA) and the risk treatment plan, and integrate these tools into the organization’s operations.
Duration
26 hours
Language
English/Ukrainian
Format
100% online
Course objective
The objective of the course is to prepare professionals capable of independently organizing and coordinating the implementation of the information security, cybersecurity, and personal data protection risk management process within an ISMS.
Target audience
The course is intended for personnel involved in the implementation, maintenance, or continual improvement of an ISMS and information security risk management processes.
Document on completion
Upon successful completion of the course, participants are awarded a certificate conferring the qualification “Implementer of Information Security, Cybersecurity, and Privacy Protection Risk Management”, listed in the SIC international register.
Thematic plan
The course has a total duration of 26 hours and consists of 2 training modules.
Objectives
Module 1 - Description of the requirements of ISO/IEC 27001 “Information security, cybersecurity and privacy protection. Information security management systems. Requirements”. SIC.MODULE.ISO/IEC27001:2022
| № | Topic | Hours |
| 1 | Introduction to the ISMS | 3 |
| 2 | Context of the organization as a fundamental basis of the ISMS | 2 |
| 3 | Leadership and Policy development in the sphere of IS | 2 |
| 4 | Risk-based planning of the ISMS | 2 |
| 5 | Resources and documentation of the ISMS | 2 |
| 6 | Operational activities and processes of the ISMS | 4 |
| 7 | Evaluation and analysis of the effectiveness of the ISMS | 1 |
| 8 | Corrective actions and improvements to the ISMS | 1 |
| 9 | Testing | 1 |
| Hours total | 18 |
Module 2 - Implementation of the information security risk management process within an organization (ISO/IEC 27005:2022). SIC.MODULE.IM.ISO/IEC27005:2022
| № | Topic | Hours |
| 1 | ISO/IEC 27005 as a tool for meeting the requirements of ISO/IEC 27001 | 1 |
| 2 | Roadmap for implementing the risk management process | 1 |
| 3 | Organizational context, interested parties, and risk criteria | 1 |
| 4 | Risk assessment methodology and development of risk scenarios | 1 |
| 5 | Risk identification, analysis, and evaluation | 1 |
| 6 | Risk treatment and selection of security controls | 1 |
| 7 | Statement of Applicability (SoA) and the Risk Treatment Plan | 1 |
| 8 | Integration of the risk management process into the ISMS and preparation for audit | 0,5 |
| 9 | Testing | 0,5 |
| Hours total | 8 |