Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction to ISO/IEC 27001:2023
- Overview of ISO/IEC 27001 Information Security Management System (ISMS)
- Purpose and benefits of implementing an ISMS
- Role of ISO 27001 in cybersecurity governance
- Structure of the ISO 27000 family of standards
- Key concepts:
- Information security
- Risk management
- Security controls
- Continuous improvement
- Overview of ISO 27001 certification process
2. Changes in ISO/IEC 27001:2023 Edition
2.1 What Has Changed?
- Overview of ISO 27001:2022/2023 edition updates
- Reasons behind the standard revision
- Alignment with modern cybersecurity practices
- Impact on existing certified organizations
2.2 Scope of Changes
- Changes to terminology and structure
- Updates to requirements in ISO 27001 clauses
- Impact on ISMS documentation
- Transition requirements from previous editions
- Timeline and migration considerations
2.3 Updated Annex A Security Controls
- Overview of the new Annex A structure
- Transition from 14 control domains to 4 themes:
- Organizational controls
- People controls
- Physical controls
- Technological controls
- New and updated security controls
- Changes in control attributes
- Understanding control applicability
3. Understanding Information Security and Risk Management
3.1 Defining Security in Modern Organizations
- Information security principles:
- Confidentiality
- Integrity
- Availability
- Business impact of security incidents
- Security challenges in modern environments
- Balancing security, usability, and business requirements
3.2 Risk Management Approach
- Identifying information security risks
- Risk assessment methodologies
- Risk treatment options
- Creating risk treatment plans
- Selecting appropriate security controls
- Statement of Applicability (SoA)
4. Implementing ISO 27001:2023 Changes
4.1 Preparing for Transition
- Assessing current ISMS maturity
- Performing a gap analysis
- Identifying required updates
- Updating policies and procedures
- Reviewing existing security controls
4.2 Implementing Updated Controls
- Mapping existing controls to the new Annex A structure
- Evaluating control effectiveness
- Integrating new security requirements
- Managing organizational changes
4.3 Practical Implementation Case Study
- Reviewing an example organization
- Identifying security gaps
- Selecting appropriate controls
- Developing improvement recommendations
- Creating an implementation roadmap
5. Auditing According to ISO 27001:2023
5.1 Fundamentals of ISMS Auditing
- Purpose and principles of auditing
- Internal audit versus certification audit
- Auditor responsibilities
- Audit criteria and scope
- Evidence-based auditing approach
5.2 Planning an ISO 27001 Audit
- Creating an audit program
- Preparing audit checklists
- Defining audit objectives
- Identifying relevant processes and controls
- Selecting audit methods
5.3 Conducting the Audit
- Opening meetings
- Interview techniques
- Reviewing documentation
- Collecting objective evidence
- Testing control effectiveness
- Recording audit findings
6. Audit Findings and Reporting
6.1 Managing Audit Results
- Identifying nonconformities
- Classifying findings:
- Major nonconformities
- Minor nonconformities
- Observations
- Opportunities for improvement
- Root cause analysis
- Corrective actions
6.2 Audit Reporting
- Writing effective audit reports
- Communicating findings to management
- Prioritizing improvement actions
- Follow-up activities
7. Good Practices for ISO 27001 Implementation and Auditing
- Common challenges during implementation
- Avoiding common audit mistakes
- Building an effective security culture
- Maintaining ISMS effectiveness
- Continuous improvement practices
- Integrating ISO 27001 with other standards:
- ISO 9001
- ISO 22301
- ISO 27701
8. Practical Workshop and Case Study
- Reviewing an example ISMS environment
- Performing a gap assessment
- Identifying applicable controls
- Preparing audit questions
- Evaluating evidence
- Creating audit findings
- Presenting recommendations
9. Discussion and Summary
- Review of ISO 27001:2023 changes
- Key considerations for auditors
- Lessons learned from case studies
- Best practices for successful implementation
- Questions and answers
- Additional resources and next steps
Requirements
Audience
- Internal and lead auditors
- Anyone interested in the topic
14 Hours