ISO/IEC 27002 Introduction Training Course
Why should you attend?
ISO/IEC 27002 Introduction training course enables you to comprehend the Information Security Management Systems and Information Security Controls as specified in ISO/IEC 27002.
By attending the ISO/IEC 27002 Introduction training course, you will understand the importance of ISMS and Information Security Controls and the benefits that businesses, society and governments can obtain.
Who should attend?
- Individuals interested in Information Security Management and Information Security Controls
- Individuals seeking to gain knowledge about the main processes of Information Security Management Systems and Information Security Controls
Learning objectives
- Understand the Information Security standards and Information Security Management practices used to implement and manage Information Security Controls
- Understand the controls necessary to manage Information Security risks
Course Outline
ISMS Foundations & ISO/IEC 27002 Framework (90 min)
- ISO/IEC 27000 family structure & relationship to ISO/IEC 27001 certification
- Core principles of a living Information Security Management System
- The four control themes: Organizational, People, Physical, Technological
- Benefits of ISO/IEC 27002 for organizations, regulators, and public trust
- Activity: Security maturity self-assessment & gap identification exercise
Deep Dive into the 93 ISO/IEC 27002 Controls (120 min)
- Structure of the 2022 revision: themes, categories, and control objectives
- Key controls: Access management, cryptography, operations security, supplier relationships, compliance, and incident response
- Mandatory vs. guideline controls & implementation flexibility
- Activity: Control categorization workshop & real-world scenario mapping
Risk Linkage, Implementation & Evidence Mapping (120 min)
- Connecting controls to risk assessment & treatment plans
- Implementation strategies: policy drafting, technical deployment, and process integration
- Compliance evidence, audit readiness, and continuous monitoring practices
- Activity: Build a mini risk-treatment matrix & control evidence checklist
Operationalization, Framework Alignment & Next Steps (60 min)
- Common pitfalls & best practices for control adoption at scale
- Aligning ISO/IEC 27002 with regulatory frameworks (GDPR, NIST CSF, HIPAA, etc.)
- Pathways to certification, advanced training, and organizational rollout planning
- Capstone Exercise: Group scenario mapping & drafting a 90-day control implementation roadmap
- Q&A, resource distribution, and course close
Open Training Courses require 5+ participants.
ISO/IEC 27002 Introduction Training Course - Booking
ISO/IEC 27002 Introduction Training Course - Enquiry
ISO/IEC 27002 Introduction - Consultancy Enquiry
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Risk optimization is more clear than the other subjects
Munirah Alsahli - GOSI
Course - CGEIT – Certified in the Governance of Enterprise IT
Provisional Courses
Related Courses
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in Poland (online or onsite) is aimed at advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain comprehensive knowledge of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
CGEIT – Certified in the Governance of Enterprise IT
28 HoursDescription:
This four day event (CGEIT training) is the ultimate preparation for exam time and is designed to ensure that you pass the challenging CGEIT exam on your first attempt.
The CGEIT qualification is an internationally recognised symbol of excellence in IT governance awarded by ISACA. It is designed for professionals responsible for managing IT governance or with significant advisory or assurance responsibility for IT governance.
Achieving CGEIT status will provide you with wider recognition in the marketplace, as well as increased influence at executive level.
Objectives:
This seminar has been designed to prepare Delegates for the CGEIT examination by enabling them to supplement their existing knowledge and understanding to be better prepared to pass the exam, as defined by ISACA.
Target Audience:
Our training course is for IT and business professionals, with significant IT governance experience who are undertaking the CGEIT exam.
Compliance for Payment Services in Japan
7 HoursThis instructor-led, live training in Poland (online or onsite) is aimed at payment services compliance professionals who wish to create, implement, and enforce a compliance program within an organization.
By the end of this training, participants will be able to:
- Understand the rules set forth by government regulators for payment service providers.
- Create the internal policies and procedures needed to satisfy government regulations.
- Implement a compliance program that adheres to relevant laws.
- Ensures that all corporate processes and procedures comply with the compliance program.
- Uphold the business's reputation while protecting it from lawsuits.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Poland (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course provides an expert introduction to the newly enacted Accessibility Law and equips developers with the practical skills to design, develop, and maintain fully accessible applications. Starting with a contextual discussion on the law's importance and implications, the course quickly shifts to hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
GDPR - Certified Data Protection Officer
35 HoursThe PECB Certified Data Protection Officer training course enables you to acquire the necessary knowledge and skills, and develop the competence to perform the role of the data protection officer in a GDPR compliance program implementation.
Why should you attend?
As data protection is becoming more and more valuable, the need for organizations to protect these data is also constantly increasing. Besides violating the fundamental rights and freedoms of persons, not complying with the data protection regulations can lead to risky situations that could harm an organization’s credibility, reputation, and financial status. This is where your skills as a data protection officers come to place.
The PECB Certified Data Protection Officer training course will help you acquire the knowledge and skills to serve as a Data Protection Officer (DPO) so as to help organizations ensure compliance with the General Data Protection Regulation (GDPR) requirements.
Based on practical exercises, you will be able to master the role of the DPO and become competent to inform, advise, and monitor compliance with the GDPR and cooperate with the supervisory authority.
After attending the training course, you can sit for the exam, and if you successfully pass the exam, you can apply for the “PECB Certified Data Protection Officer” credential. The internationally recognized “PECB Certified Data Protection Officer” certificate will prove that you have the professional capabilities and practical knowledge to advise the controller and the processor on how to meet their obligations regarding the GDPR compliance.
Who should attend?
- Managers or consultants seeking to prepare and support an organization in planning, implementing, and maintaining a compliance program based on the GDPR
- DPOs and individuals responsible for maintaining conformance with the GDPR requirements
- Members of information security, incident management, and business continuity teams
- Technical and compliance experts seeking to prepare for a data protection officer role
- Expert advisors involved in the security of personal data
Learning objectives
- Understand the concepts of the GDPR and interpret its requirements
- Understand the content and the correlation between the General Data Protection Regulation and other regulatory frameworks and applicable standards, such as ISO/IEC 27701 and ISO/IEC 29134
- Acquire the competence to perform the role and daily tasks of the data protection officer in an organization
- Develop the ability to inform, advise, and monitor compliance with the GDPR and cooperate with the supervisory authority
Educational approach
- This training course is based on both theory and best practices used in exercising the role of the DPO.
- Lecture sessions are illustrated with practical exercises based on a case study which include role-playing and discussions.
- The participants are encouraged to intercommunicate and engage in discussions and exercises.
- Practice exercises and quizzes are similar to the certification exam.
General Information
- Participants will be provided with the training course material containing over 450 pages of explanatory information and practical examples.
- An Attendance Record worth 31 CPD (Continuing Professional Development) credits will be issued to participants who have attended the training course.
HiTrust Common Security Framework Compliance
14 HoursThis instructor-led, live training in Poland (online or onsite) is aimed at developers and administrators who wish to produce software and products that are HiTRUST compliant.
By the end of this training, participants will be able to:
- Understand the key concepts of the HiTrust CSF (Common Security Framework).
- Identify the HITRUST CSF administrative and security control domains.
- Learn about the different types of HiTrust assessments and scoring.
- Understand the certification process and requirements for HiTrust compliance.
- Know the best practices and tips for adopting the HiTrust approach.
Interpretation of Environmental Management System Standard ISO 14001:2015
24 HoursISO 14001:2015 is an international standard for developing, implementing, and improving an Environmental Management System (EMS).
This instructor-led, live training (online or onsite) is intended for beginner-level and intermediate-level professionals who wish to understand, interpret, and apply the requirements of ISO 14001:2015 within their organizations.
Upon completion of this workshop, participants will be able to:
- Interpret the structure, requirements, and intent of ISO 14001:2015.
- Identify environmental aspects and risks in alignment with the standard.
- Assess organizational context and leadership responsibilities.
- Evaluate operational controls, performance metrics, and improvement processes.
Format of the Course
- Guided presentations with real-world examples.
- Practical exercises, case studies, and scenario-based discussions.
- Interactive activities focused on interpreting and applying ISO 14001:2015 requirements.
Course Customization Options
- To tailor this course for your organization’s EMS needs, please contact us to discuss customization options.
Applied Interpretation and Implementation of ISO 20560 for Industrial Safety Signage
21 HoursISO 20560 is a global standard that defines unified safety signage and pipe marking systems for industrial environments.
This instructor-led, live training (online or onsite) is aimed at advanced-level industrial and safety personnel who wish to apply ISO 20560 requirements in real-world operational settings.
Upon completion of this training, participants will be equipped to:
- Interpret ISO 20560 structure, terminology, and application guidelines accurately.
- Design and implement compliant safety signage and pipe identification systems.
- Assess risks associated with industrial substances and processes using standardized visual communication.
- Adapt ISO 20560 requirements to local regulations and specific sector needs, including cosmetic manufacturing environments.
Format of the Course
- Expert-led presentations and guided discussion.
- Scenario-based exercises and applied workshops.
- Hands-on evaluation of signage and pipe marking in simulated industrial setups.
Course Customization Options
- To tailor this course to your organization’s operational context or plant layout, please contact us for a customized arrangement.
ISO 10012:2003 – Measurement Management Systems
14 HoursThis instructor-led, live training in Poland (online or onsite) is aimed at intermediate-level quality and measurement professionals who wish to implement, audit, or improve a measurement management system based on ISO 10012:2003 to support quality assurance and regulatory compliance.
By the end of this training, participants will be able to:
- Understand the structure, scope, and intent of ISO 10012:2003.
- Implement a measurement management system that ensures equipment reliability and measurement traceability.
- Define roles, responsibilities, and documentation required for measurement control.
- Integrate ISO 10012 with broader quality and risk management frameworks (e.g., ISO 9001, ISO/IEC 17025).
ISO 27002 Lead Manager
35 HoursISO/IEC 27002 Lead Manager training enables you to develop the necessary expertise and knowledge to support an organization in implementing and managing Information Security controls as specified in ISO/IEC 27002.
After completing this course, you can sit for the exam and apply for the “PECB Certified ISO/IEC 27002 Lead Manager” credential. A PECB Lead Manager Certification, proves that you have mastered the principles and techniques for the implementation and management of Information Security Controls based on ISO/IEC 27002.
Who should attend?
- Managers or consultants seeking to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 and ISO/IEC 27002
- Project managers or consultants seeking to master the Information Security Management System implementation process
- Individuals responsible for the information security, compliance, risk, and governance, in an organization
- Members of information security teams
- Expert advisors in information technology
- Information Security officers
- Privacy officers
- IT professionals
- CTOs, CIOs and CISOs
Learning objectives
- Master the implementation of Information Security controls by adhering to the framework and principles of ISO/IEC 27002
- Gain a comprehensive understanding of the concepts, approaches, standards, methods and techniques required for the effective implementation and management of Information Security controls
- Comprehend the relationship between the components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance, and human behavior
- Understand the importance of information security for the strategy of the organization
- Master the implementation of information security management processes
- Master the formulation and implementation of security requirements and objectives
Educational approach
- This training is based on both theory and practice
- Sessions of lectures illustrated with examples based on real cases
- Practical exercises based on case studies
- Review exercises to assist the exam preparation
- Practice test similar to the certification exam
General Information
- Certification fees are included on the exam price
- Training material containing over 500 pages of information and practical examples will be distributed to the participants
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued to the participants
- In case of exam failure, you can retake the exam within 12 months for free
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 are internationally recognized standards for quality and information security management systems, respectively.
This instructor-led, live training (online or onsite) is aimed at intermediate-level professionals who wish to interpret ISO 9001 and ISO 27001 standards and perform internal audits effectively.
By the end of this training, participants will be able to:
- Understand the principles and requirements of ISO 9001 and ISO 27001.
- Interpret the clauses and controls in real-world contexts.
- Plan and conduct internal audits aligned with ISO standards.
- Identify nonconformities and recommend corrective actions.
Format of the Course
- Interactive lecture and discussion.
- Simulated auditing exercises and case studies.
- Hands-on analysis of quality and security scenarios.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Compliance and the Management of Compliance Risk
21 HoursAudience
This course is intended for all employees who require a practical understanding of Compliance and effective Risk Management.
Format of the course
The training is delivered through a blended approach that includes:
- Facilitated discussions
- Slide-based presentations
- Case studies
- Real-world examples
Course Objectives
By the end of the course, participants will be able to:
Develop a solid understanding of the key aspects of Compliance, along with national and international initiatives aimed at managing associated risks.
Explain how organizations and their teams can establish an effective Compliance Risk Management Framework.
Describe the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles integrate within a business structure.
Identify critical risk areas in Financial Crime, particularly in the context of international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management is the practice of overseeing the lifecycle of open-source components within an organization, ensuring secure, compliant, and efficient use.
This instructor-led, live training (online or onsite) is aimed at intermediate-level IT professionals who wish to implement best practices for managing open-source software in enterprise and government environments.
By the end of this training, participants will be able to:
- Establish effective OSS policies and governance frameworks.
- Use SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks associated with licensing and security vulnerabilities.
- Streamline OSS adoption while maximizing innovation and cost savings.
Format of the Course
- Interactive lecture and discussion.
- Case studies and scenario-based exercises.
- Hands-on demonstrations with OSS management tools.
Course Customization Options
- This course can be tailored to specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Poland (online or onsite) provides an individual qualification for industry practitioners who wish to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
By the end of this training, participants will be able to:
- Understand the payment process and the PCI standards designed to protect it.
- Understand the roles and responsibilities for entities involved in the payment industry.
- Have deep insight into, and understanding of, the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and how it applies to organizations that are involved in the transaction process.