Get in Touch

Course Outline

1. Introduction to ISO/IEC 27001:2023

  • Overview of ISO/IEC 27001 Information Security Management System (ISMS)
  • Purpose and benefits of implementing an ISMS
  • Role of ISO 27001 in cybersecurity governance
  • Structure of the ISO 27000 family of standards
  • Key concepts:
    • Information security
    • Risk management
    • Security controls
    • Continuous improvement
  • Overview of ISO 27001 certification process

2. Changes in ISO/IEC 27001:2023 Edition

2.1 What Has Changed?

  • Overview of ISO 27001:2022/2023 edition updates
  • Reasons behind the standard revision
  • Alignment with modern cybersecurity practices
  • Impact on existing certified organizations

2.2 Scope of Changes

  • Changes to terminology and structure
  • Updates to requirements in ISO 27001 clauses
  • Impact on ISMS documentation
  • Transition requirements from previous editions
  • Timeline and migration considerations

2.3 Updated Annex A Security Controls

  • Overview of the new Annex A structure
  • Transition from 14 control domains to 4 themes:
    • Organizational controls
    • People controls
    • Physical controls
    • Technological controls
  • New and updated security controls
  • Changes in control attributes
  • Understanding control applicability

3. Understanding Information Security and Risk Management

3.1 Defining Security in Modern Organizations

  • Information security principles:
    • Confidentiality
    • Integrity
    • Availability
  • Business impact of security incidents
  • Security challenges in modern environments
  • Balancing security, usability, and business requirements

3.2 Risk Management Approach

  • Identifying information security risks
  • Risk assessment methodologies
  • Risk treatment options
  • Creating risk treatment plans
  • Selecting appropriate security controls
  • Statement of Applicability (SoA)

4. Implementing ISO 27001:2023 Changes

4.1 Preparing for Transition

  • Assessing current ISMS maturity
  • Performing a gap analysis
  • Identifying required updates
  • Updating policies and procedures
  • Reviewing existing security controls

4.2 Implementing Updated Controls

  • Mapping existing controls to the new Annex A structure
  • Evaluating control effectiveness
  • Integrating new security requirements
  • Managing organizational changes

4.3 Practical Implementation Case Study

  • Reviewing an example organization
  • Identifying security gaps
  • Selecting appropriate controls
  • Developing improvement recommendations
  • Creating an implementation roadmap

5. Auditing According to ISO 27001:2023

5.1 Fundamentals of ISMS Auditing

  • Purpose and principles of auditing
  • Internal audit versus certification audit
  • Auditor responsibilities
  • Audit criteria and scope
  • Evidence-based auditing approach

5.2 Planning an ISO 27001 Audit

  • Creating an audit program
  • Preparing audit checklists
  • Defining audit objectives
  • Identifying relevant processes and controls
  • Selecting audit methods

5.3 Conducting the Audit

  • Opening meetings
  • Interview techniques
  • Reviewing documentation
  • Collecting objective evidence
  • Testing control effectiveness
  • Recording audit findings

6. Audit Findings and Reporting

6.1 Managing Audit Results

  • Identifying nonconformities
  • Classifying findings:
    • Major nonconformities
    • Minor nonconformities
    • Observations
    • Opportunities for improvement
  • Root cause analysis
  • Corrective actions

6.2 Audit Reporting

  • Writing effective audit reports
  • Communicating findings to management
  • Prioritizing improvement actions
  • Follow-up activities

7. Good Practices for ISO 27001 Implementation and Auditing

  • Common challenges during implementation
  • Avoiding common audit mistakes
  • Building an effective security culture
  • Maintaining ISMS effectiveness
  • Continuous improvement practices
  • Integrating ISO 27001 with other standards:
    • ISO 9001
    • ISO 22301
    • ISO 27701

8. Practical Workshop and Case Study

  • Reviewing an example ISMS environment
  • Performing a gap assessment
  • Identifying applicable controls
  • Preparing audit questions
  • Evaluating evidence
  • Creating audit findings
  • Presenting recommendations

9. Discussion and Summary

  • Review of ISO 27001:2023 changes
  • Key considerations for auditors
  • Lessons learned from case studies
  • Best practices for successful implementation
  • Questions and answers
  • Additional resources and next steps

Requirements

Audience

  • Internal and lead auditors
  • Anyone interested in the topic
 14 Hours

Number of participants


Price per participant

Provisional Upcoming Courses (Require 5+ participants)

Related Categories