ISO/IEC 27002 Introduction Training Course
Reasons to Attend
The ISO/IEC 27002 Introduction training course equips you with the knowledge to understand Information Security Management Systems and Information Security Controls as outlined in ISO/IEC 27002.
By participating in this training, you will gain insight into the significance of Information Security Management Systems and Information Security Controls, as well as the advantages these bring to businesses, society, and government entities.
Target Audience
- Professionals interested in Information Security Management and Information Security Controls
- Individuals aiming to acquire knowledge regarding the core processes of Information Security Management Systems and Information Security Controls
Learning Outcomes
- Comprehend the information security standards and management practices utilized to implement and oversee Information Security Controls
- Identify the necessary controls for managing information security risks
Course Outline
Foundations of ISMS & ISO/IEC 27002 Framework (90 min)
- Structure of the ISO/IEC 27000 family & its connection to ISO/IEC 27001 certification
- Core principles of a dynamic Information Security Management System
- Four control themes: Organizational, People, Physical, Technological
- Benefits of ISO/IEC 27002 for organizations, regulators, and public trust
- Activity: Security maturity self-assessment & gap identification exercise
Deep Dive into the 93 ISO/IEC 27002 Controls (120 min)
- Structure of the 2022 revision: themes, categories, and control objectives
- Key controls: Access management, cryptography, operations security, supplier relationships, compliance, and incident response
- Mandatory vs. guideline controls & implementation flexibility
- Activity: Control categorization workshop & real-world scenario mapping
Risk Linkage, Implementation & Evidence Mapping (120 min)
- Connecting controls to risk assessment & treatment plans
- Implementation strategies: policy drafting, technical deployment, and process integration
- Compliance evidence, audit readiness, and continuous monitoring practices
- Activity: Build a mini risk-treatment matrix & control evidence checklist
Operationalization, Framework Alignment & Next Steps (60 min)
- Common pitfalls & best practices for control adoption at scale
- Aligning ISO/IEC 27002 with regulatory frameworks (GDPR, NIST CSF, HIPAA, etc.)
- Pathways to certification, advanced training, and organizational rollout planning
- Capstone Exercise: Group scenario mapping & drafting a 90-day control implementation roadmap
- Q&A, resource distribution, and course close
Open Training Courses require 5+ participants.
ISO/IEC 27002 Introduction Training Course - Booking
ISO/IEC 27002 Introduction Training Course - Enquiry
ISO/IEC 27002 Introduction - Consultancy Enquiry
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Risk optimization is more clear than the other subjects
Munirah Alsahli - GOSI
Course - CGEIT – Certified in the Governance of Enterprise IT
Upcoming Courses
Related Courses
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in Norway (online or onsite) is aimed at advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain comprehensive knowledge of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
CGEIT – Certified in the Governance of Enterprise IT
28 HoursDescription:
This intensive four-day course (CGEIT training) serves as the premier preparation for the examination, designed to equip you with the knowledge needed to successfully pass the challenging CGEIT exam on your first attempt.
The CGEIT qualification is an internationally recognized mark of excellence in IT governance, awarded by ISACA. It is tailored for professionals responsible for managing IT governance or those with significant advisory or assurance responsibilities in this domain.
Achieving CGEIT status will broaden your professional recognition in the marketplace and enhance your influence at the executive level.
Objectives:
This seminar aims to prepare delegates for the CGEIT examination by helping them supplement their existing knowledge and understanding, thereby better positioning them to pass the exam as defined by ISACA.
Target Audience:
This training course is intended for IT and business professionals who possess substantial IT governance experience and are undertaking the CGEIT exam.
Compliance for Payment Services in Japan
7 HoursThis instructor-led, live training in Norway (online or onsite) is designed for compliance professionals in the payment services sector who aim to design, implement, and enforce a robust compliance program within their organizations.
Upon completion of this training, participants will be equipped to:
- Grasp the regulatory requirements imposed by government authorities on payment service providers.
- Develop internal policies and procedures that align with governmental regulations.
- Establish a compliance program that adheres to applicable laws.
- Ensure that all corporate processes and procedures remain consistent with the compliance framework.
- Protect the business's reputation and shield it from legal liabilities.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Norway (online or onsite) targets intermediate-level cybersecurity professionals who wish to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers a comprehensive introduction to the recently enacted Accessibility Law, providing developers with the practical expertise needed to design, develop, and sustain fully accessible applications. Beginning with an analysis of the law's significance and broader implications, the curriculum rapidly transitions into practical coding techniques, essential tools, and testing methodologies to guarantee compliance and inclusivity for users with disabilities.
GDPR - Certified Data Protection Officer
35 HoursThe PECB Certified Data Protection Officer training programme empowers you with the essential knowledge, skills, and competence required to effectively assume the role of a Data Protection Officer (DPO) within an organisation implementing GDPR compliance measures.
Why should you attend?
As the value of data protection continues to rise, organisations face growing demands to safeguard this information. Non-compliance with data protection regulations not only infringes upon the fundamental rights and freedoms of individuals but also exposes organisations to significant risks that can damage their credibility, reputation, and financial standing. It is here that the expertise of a Data Protection Officer becomes crucial.
The PECB Certified Data Protection Officer training course provides the knowledge and skills needed to serve as a DPO, helping organisations meet the requirements of the General Data Protection Regulation (GDPR).
Through practical exercises, you will master the DPO role, gaining the competence to advise, monitor GDPR compliance, and liaise effectively with supervisory authorities.
Upon completing the training, you are eligible to sit for the examination. Passing the exam allows you to apply for the “PECB Certified Data Protection Officer” credential. This internationally recognised certificate demonstrates your professional capability and practical knowledge in advising controllers and processors on fulfilling their GDPR obligations.
Who should attend?
- Managers or consultants aiming to prepare and support an organisation in planning, implementing, and maintaining a GDPR-based compliance programme.
- Existing DPOs and individuals responsible for maintaining conformance with GDPR requirements.
- Members of information security, incident management, and business continuity teams.
- Technical and compliance professionals preparing for a Data Protection Officer role.
- Expert advisors involved in securing personal data.
Learning objectives
- Understand GDPR concepts and interpret its requirements.
- Grasp the relationship between the General Data Protection Regulation and other regulatory frameworks and applicable standards, such as ISO/IEC 27701 and ISO/IEC 29134.
- Acquire the competence to perform the daily tasks and responsibilities of a Data Protection Officer within an organisation.
- Develop the ability to inform, advise, and monitor GDPR compliance, as well as cooperate with supervisory authorities.
Educational approach
- The training combines theoretical knowledge with best practices for exercising the DPO role.
- Lectures are reinforced with practical exercises based on case studies, including role-playing and discussions.
- Participants are encouraged to interact and engage actively in discussions and exercises.
- Practice exercises and quizzes mirror the format of the certification exam.
General Information
- Participants receive comprehensive training materials containing over 450 pages of explanatory content and practical examples.
- An Attendance Record awarding 31 CPD (Continuing Professional Development) credits is issued to those who complete the training.
HiTrust Common Security Framework Compliance
14 HoursThis instructor-led, live training in Norway (online or onsite) is aimed at developers and administrators who wish to produce software and products that are HiTRUST compliant.
By the end of this training, participants will be able to:
- Understand the key concepts of the HiTrust CSF (Common Security Framework).
- Identify the HITRUST CSF administrative and security control domains.
- Learn about the different types of HiTrust assessments and scoring.
- Understand the certification process and requirements for HiTrust compliance.
- Know the best practices and tips for adopting the HiTrust approach.
Interpretation of Environmental Management System Standard ISO 14001:2015
24 HoursISO 14001:2015 serves as the international benchmark for creating, executing, and enhancing an Environmental Management System (EMS).
This instructor-led training session, available both online and in-person, is designed for professionals at beginner to intermediate levels who aim to comprehend, interpret, and implement the ISO 14001:2015 requirements within their respective organizations.
After finishing this workshop, participants will gain the ability to:
- Interpret the structure, requirements, and underlying intent of ISO 14001:2015.
- Identify environmental aspects and associated risks in compliance with the standard.
- Assess organizational context and leadership responsibilities.
- Evaluate operational controls, performance metrics, and improvement processes.
Course Format
- Guided presentations supported by real-world examples.
- Practical exercises, case studies, and scenario-based discussions.
- Interactive activities centered on interpreting and applying ISO 14001:2015 requirements.
Customization Options
- To tailor this course to your organization’s specific EMS needs, please contact us to discuss customization options.
Applied Interpretation and Implementation of ISO 20560 for Industrial Safety Signage
21 HoursISO 20560 serves as a worldwide standard establishing a unified system for safety signage and pipe marking within industrial settings.
This instructor-led training, available both online and on-site, is designed for advanced-level industrial and safety professionals seeking to apply ISO 20560 requirements in practical operational contexts.
Upon completing this training, participants will be able to:
- Accurately interpret the structure, terminology, and application guidelines of ISO 20560.
- Design and implement safety signage and pipe identification systems that meet compliance standards.
- Assess risks linked to industrial substances and processes through standardized visual communication.
- Adapt ISO 20560 requirements to fit local regulations and specific sector needs, including environments in the cosmetic manufacturing industry.
Course Format
- Expert-led presentations coupled with guided discussions.
- Scenario-based exercises and applied workshops.
- Practical evaluation of signage and pipe marking within simulated industrial setups.
Course Customization Options
- To tailor this course to your organization’s specific operational context or plant layout, please contact us to arrange a customized session.
ISO 10012:2003 – Measurement Management Systems
14 HoursThis instructor-led, live training in Norway (online or onsite) is aimed at intermediate-level quality and measurement professionals who wish to implement, audit, or improve a measurement management system based on ISO 10012:2003 to support quality assurance and regulatory compliance.
By the end of this training, participants will be able to:
- Understand the structure, scope, and intent of ISO 10012:2003.
- Implement a measurement management system that ensures equipment reliability and measurement traceability.
- Define roles, responsibilities, and documentation required for measurement control.
- Integrate ISO 10012 with broader quality and risk management frameworks (e.g., ISO 9001, ISO/IEC 17025).
ISO 27002 Lead Manager
35 HoursThe ISO/IEC 27002 Lead Manager training equips you with the essential expertise and knowledge to help an organization implement and manage Information Security controls as outlined in ISO/IEC 27002.
Upon completion of this course, you are eligible to sit for the exam and apply for the "PECB Certified ISO/IEC 27002 Lead Manager" credential. This PECB Lead Manager Certification demonstrates that you have mastered the principles and techniques required for implementing and managing Information Security controls in accordance with ISO/IEC 27002.
Who should attend?
- Managers or consultants aiming to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 and ISO/IEC 27002
- Project managers or consultants seeking to master the process of implementing an Information Security Management System
- Individuals responsible for information security, compliance, risk, and governance within an organization
- Members of information security teams
- Expert advisors in information technology
- Information Security officers
- Privacy officers
- IT professionals
- CTOs, CIOs, and CISOs
Learning objectives
- Master the implementation of Information Security controls by adhering to the framework and principles of ISO/IEC 27002
- Gain a comprehensive understanding of the concepts, approaches, standards, methods, and techniques necessary for the effective implementation and management of Information Security controls
- Comprehend the interrelationships between the components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance, and human behavior
- Understand the significance of information security to the organization's overall strategy
- Master the implementation of information security management processes
- Master the formulation and implementation of security requirements and objectives
Educational approach
- This training combines both theoretical knowledge and practical application
- Lecture sessions supplemented with examples from real-world cases
- Practical exercises based on case studies
- Review exercises designed to assist with exam preparation
- Practice tests that mirror the format of the certification exam
General Information
- Certification fees are included in the exam price
- Training material, comprising over 500 pages of information and practical examples, will be distributed to participants
- Participants will receive a certificate of participation awarding 31 CPD (Continuing Professional Development) credits
- In the event of an exam failure, you may retake the exam free of charge within 12 months
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 stand as globally acknowledged benchmarks for quality management and information security management systems, respectively.
This instructor-led live training, available either online or onsite, is designed for intermediate-level professionals looking to master the interpretation of ISO 9001 and ISO 27001 standards and execute internal audits with confidence.
Upon completing this training, participants will be equipped to:
- Comprehend the core principles and mandatory requirements of both ISO 9001 and ISO 27001.
- Apply the interpretation of clauses and controls to real-world business contexts.
- Plan and carry out internal audits that align with ISO standards.
- Detect nonconformities and propose appropriate corrective measures.
Course Format
- Engaging lectures combined with group discussions.
- Simulated auditing exercises and in-depth case studies.
- Practical analysis of various quality and security scenarios.
Customization Options
- To arrange a tailored training session for this course, please reach out to us.
Compliance and the Management of Compliance Risk
21 HoursAudience
This course is designed for all staff members who need a practical grasp of Compliance and effective Risk Management.
Course Format
The training employs a blended methodology comprising:
- Facilitated discussions
- Slide-based presentations
- Case studies
- Real-world examples
Learning Objectives
Upon completion of the course, participants will be able to:
Gain a robust understanding of the fundamental aspects of Compliance, alongside national and international initiatives focused on managing associated risks.
Articulate how organizations and their teams can establish an effective Compliance Risk Management Framework.
Outline the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles are integrated within a business structure.
Identify critical risk areas within Financial Crime, particularly concerning international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves overseeing the entire lifecycle of open-source components within an organization to ensure their secure, compliant, and efficient utilization.
This instructor-led training, available online or onsite, targets intermediate-level IT professionals seeking to implement best practices for managing open-source software in enterprise and government settings.
Upon completion of this training, participants will be equipped to:
- Develop effective OSS policies and governance frameworks.
- Leverage SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Reduce risks related to licensing and security vulnerabilities.
- Streamline the adoption of OSS while maximizing innovation and cost efficiencies.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations with OSS management tools.
Customization Options
- This course can be tailored to align with your organization's specific OSS policies and toolchains. Please contact us to arrange customization.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Norway (online or onsite) provides an individual qualification for industry practitioners who wish to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
By the end of this training, participants will be able to:
- Understand the payment process and the PCI standards designed to protect it.
- Understand the roles and responsibilities for entities involved in the payment industry.
- Have deep insight into, and understanding of, the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and how it applies to organizations that are involved in the transaction process.