ISO 27001 Audit: Information Security

Corporate
Digital Skills

Compliance, Quality, and Occupational Health and Safety

Duration

8:00 p.m.

PRESENTATION

The Course Information Security gives you the opportunity to break into an industry in steady growth y high demand for labor. In a world where the information is one of the most valuable assets, ensure its protection has become a priority for organizations of all kinds. This course offers you a in-depth knowledge of the ISO 27001 standard and how implement an Information Security Management System (ISMS). You'll learn how to manage risks, establish security policies y promote a culture of safety in your organization. In addition, you will gain skills in auditing and certification, which are essential for ensuring the regulatory compliance and the data integrity. The online format allows you to access this valuable knowledge from anywhere, tailoring it to your needs. Upon completing this course, you will be ready to tackle today's information security challenges and become a an expert in the field that companies are looking for.

Objectives

  • Understand the fundamentals and evolution of the ISO 27001 standard.

  • Identify the key concepts such as confidentiality, integrity, and availability.

  • Analyze the general requirements of an ISMS according to the ISO 27001.

  • Assess risks y define information security policies.

  • Set safety goals y plan to achieve them.

  • Promote a culture of safety y assign roles within the organization.

  • Implement controls y Manage incidents in the ISMS.

Syllabus

TEACHING UNIT 1. Fundamentals of ISO 27001 Origin and Evolution of the ISO 27001 Standard Importance of Information Security in Organizations High-Level Structure (HLS) of ISO Standards Relationship Between ISO 27001 and Other Related ISO Standards (ISO 27002, ISO 22301, etc.) Key Concepts: Confidentiality, Integrity, and Availability LEARNING UNIT 2. Information Security Management Systems (ISMS) and the Use of ISO 27001 Definition and Scope of the ISMS General ISMS requirements according to ISO 27001 Information security policies Definition and management of assets in the ISMS Risk management: identification, assessment, and treatment TEACHING UNIT 3. Context and Planning of the ISMS Identification of the organization’s internal and external context Stakeholders and applicable requirements Analysis of risks and opportunities Establishment of information security objectives Planning to achieve the established objectives LEARNING UNIT 4. Leadership and Commitment in the ISMS Role and responsibilities of top management in the ISMS Establishing an information security policy Assigning roles and responsibilities for information security Promoting a culture of security within the organization LEARNING UNIT 5. ISMS Support and Resources Resource requirements for ISMS implementation Competence and training of involved personnel Internal and external communication in the ISMS ISMS documentation: Types of documents and requirements Control of documented information TEACHING UNIT 6. ISMS Operation Planning and Operational Control in Information Security Implementation of Controls According to Annex A of the ISO 27001 Standard Information Security Incident Management Incident Response and Recovery Plans Evaluation of Vendors and External Services LEARNING UNIT 7. ISMS Performance Evaluation ISMS Monitoring and Measurement Internal Audits: Planning, Execution, and Results Key Performance Indicators (KPIs) in Information Security Analysis of Nonconformities and Corrective Actions Management Review of the ISMS LEARNING UNIT 8. ISO 27001 Certification Certification Process: Phases and Requirements Roles and Responsibilities During the External Audit Relationship Between the Internal Audit and Certification Maintenance and Renewal of the ISO 27001 Certificate LEARNING UNIT 9. Technical Tools for ISMS Auditing Risk Management and Regulatory Compliance Software Techniques for Conducting Penetration Testing (Pentesting) Vulnerability Assessment in the ISMS Environment Use of Log Monitoring and Analysis Tools Automation in Information Security Auditing TEACHING UNIT 10. How to Conduct an ISO 27001 Audit Introduction to Auditing Audit Planning Conducting the Audit Evaluation and Analysis of the ISO 27001 Audit Audit Report Review and Approval of the Report
Request for Information

Related MOOCs

Course
The Course on Workplace Risk Prevention, Ergonomics, and Mental Health addresses the growing need to ensure environments...
Course
In the age of remote work, hyperconnectivity has put companies under the scrutiny of the Labor Inspectorate....
Course
In a world of global digitization, hyperconnectivity has gone from being an advantage to becoming a challenge...

Are the Educa PHAROS courses eligible for credit?

Many courses can be credited toward the master's programs at Structuralia.

Facts about our area

+ 1.483

Hours

+88.999

Minutes

264

Courses

Educa PHAROS is a next-generation training model that places a company’s human capital at the forefront. Through a platform that adapts to each company’s corporate identity and offers a total of more than 900 courses, it provides tailored training for each organization. The unlimited flat-rate plan provides each company with the number of courses that best suits its needs, as well as the ability to determine which employees will have access.
Scroll to Top