Cybersecurity · CYC-03

ISO/IEC 27001 Information Security Management System

12 hours 2 days
Last updated
ISO/IEC 27001 ระบบบริหารความมั่นคงปลอดภัยสารสนเทศ

ISO/IEC 27001 Information Security Management System is a 12-hour training course by IT Genius Institute. Plenty of organizations get asked by a customer or partner for ISO/IEC 27001 certification, then discover the standard is hard to read, full of specialist…

Training schedule

No public rounds are open right now — register your interest and we will contact you when the next round opens, or request an in-house session for your team.

Corporate training quote

Plenty of organizations get asked by a customer or partner for ISO/IEC 27001 certification, then discover the standard is hard to read, full of specialist vocabulary and never states plainly what the organization has to do. Many respond by hiring a consultant to produce the paperwork, end up with a certificate that does not reflect how the business actually works, cannot maintain it afterwards and have spent the budget for nothing. This course explains the standard in language you can act on, then works through it step by step in the order an

organization should really follow. It covers what an information security management system is, the structure of clauses 4 through 10, defining a scope that fits the organization, assessing and treating risk systematically, selecting controls from all four Annex A groups and writing the Statement of Applicability, the documents and records you genuinely need, internal audit and management review, and finally the certification process and what assessors typically ask. It also maps the standard onto Thailand Personal Data Protection Act obligations. (2 days, 6 hours per day, 12 hours in total, no prior ISMS background required.)

Objectives

  • Understand what an information security management system is and what it really delivers
  • Explain the structure of ISO/IEC 27001 clauses 4 through 10
  • Define a scope that fits the size and nature of your organization
  • Identify information assets and assess risk systematically and repeatably
  • Select Annex A controls proportionate to risk and write a Statement of Applicability
  • Produce the documents and records the standard requires without over-documenting
  • Plan and run internal audits and management reviews
  • Understand the certification process and prepare the organization for assessment
  • Map the standard onto Thailand Personal Data Protection Act obligations

Who this course is for

  • Executives and IT managers who must drive an ISO/IEC 27001 project
  • Information security officers and risk management teams
  • Internal auditors who must audit the security management system
  • Data protection officers whose work connects to security controls
  • Organizations whose customers or partners are demanding this certification

Prerequisites

  • No prior background in standards or management systems required
  • A reasonable understanding of your own processes and data flows
  • Deep technical knowledge is not required but helps in picturing the controls
  • Bring details of one core business system to use in the workshops

Curriculum

Course Details

A 2-day course, 6 hours per day (12 hours in total), delivered as lectures with workshops that produce real documents. No prior ISMS background required. The content follows the latest ISO/IEC 27001 and draws on ISO/IEC 27002 for implementation detail. Learners take home a template set covering asset register, risk register, Statement of Applicability and audit plan, plus their own organizational risk register and draft SoA. This is a knowledge and readiness course, not an assessment or certification. Certification must be obtained separately from an accredited certification body.

Day 1: From the Standard to Risk Assessment

Section 1: What an Information Security Management System Is

  • Information security defined: confidentiality, integrity and availability
  • Why buying security products differs from running a management system that endures
  • The real benefits beyond having a certificate to show partners
  • The common trap: outsourced paperwork producing a system nobody actually follows

Section 2: The Structure of the Standard

  • An overview of clauses 4 through 10 and how they form a continual improvement cycle
  • The role of top management and what the standard demands of them directly
  • Mandatory clauses versus selectable Annex A controls
  • Its relationship to other management system standards and running them together

Section 3: Scope and Organizational Context

  • Analyzing internal and external context and identifying interested parties
  • Defining a scope that covers what matters without exceeding your capacity
  • Setting a security policy and measurable security objectives
  • Workshop: draft your own scope statement and security policy

Section 4: Asset Identification and Risk Assessment

  • Building an information asset register and assigning asset owners
  • Identifying threats and vulnerabilities and rating likelihood against impact
  • Setting risk acceptance criteria and prioritizing what to treat first
  • Workshop: assess the risk of a core business system into the risk register

Section 5: Risk Treatment and Control Selection

  • Treatment options: reduce, accept, transfer or avoid, and how to decide
  • Selecting Annex A controls proportionate to the risk and the budget
  • Writing the Statement of Applicability and justifying excluded controls
  • Workshop: produce a draft SoA from your risk assessment

Day 2: Controls, Auditing and Certification

Section 6: Organizational and People Controls

  • Policies, defined roles and segregation of duties
  • Managing external suppliers and security requirements in contracts
  • Managing people before, during and after employment
  • Building awareness and training that actually changes behaviour

Section 7: Physical and Technological Controls

  • Controlling access to premises and server rooms, and managing equipment
  • System access control, privilege management and authentication
  • Encryption, backup, and vulnerability and patch management
  • Logging, event monitoring and network security controls

Section 8: Required Documents and Records

  • The documents the standard mandates and the level of detail that suffices
  • Document control, versioning and retaining records as evidence
  • Keeping documentation from growing until nobody can follow it
  • Lab: compare your existing documents against the mandated list

Section 9: Internal Audit and Management Review

  • Planning the internal audit programme and selecting independent auditors
  • Audit technique: interviewing, requesting evidence and recording findings
  • Handling nonconformities and corrective action that reaches the root cause
  • Workshop: run a simulated internal audit and record findings against a checklist

Section 10: Certification and Assessment Readiness

  • The certification path: stage one, stage two and annual surveillance audits
  • Choosing a certification body and what to ask before committing
  • The questions assessors typically ask and the evidence to prepare in advance
  • Keeping the system alive after the certificate arrives

Section 11: Mapping to PDPA and the Rollout Plan

  • Where the standard already satisfies PDPA security obligations
  • Sharing the asset and risk registers across both programmes to avoid duplicate work
  • Assessing organizational readiness and planning the project against a real budget
  • Workshop: build your own 12-month implementation plan and present it

Frequently asked questions

Who is ISO/IEC 27001 Information Security Management System for, and what background is needed?

Built for Executives and IT managers who must drive an ISO/IEC 27001 project · Information security officers and risk management teams · Internal auditors who must audit the security management system Background you should have: No prior background in standards or management systems required · A reasonable understanding of your own processes and data flows Not sure the fit is right? Talk to our team on LINE @itgenius or call 02-570-8449.

How much does ISO/IEC 27001 Information Security Management System cost and how long does it run?

THB 9,500 (currently THB 8,550 on promotion). The course runs 12 hours. The fee covers course materials, lunch and refreshments throughout. Pay by bank transfer to the company account, confirm it on our payment page, and we can issue the receipt or tax invoice in your company's name.

Do I get a certificate?

Yes. Everyone who completes the course receives a Certificate of Completion from IT Genius Institute. Each certificate carries its own number, and anyone holding that number can verify it online on our certificate page, so you can add it to your portfolio or pass it to HR as evidence of training.

Where does the training take place, and is there an online option?

You can attend onsite at IT Genius Institute or arrange to join online, and we also run it as a private in-house session for your team. Ask about dates and venues on LINE @itgenius or call 02-570-8449.

What if I fall behind or miss a session — can I retake it?

Yes. You may retake the same course free of charge in a later round, under the institute's conditions. Tell our team which course and round you attended, and we will check it and offer you the rounds that still have seats. Ask us on LINE @itgenius or call 02-570-8449.

How do I enrol, or request a quotation for my company?

Enrol online with the registration form on this page. You can register several attendees at once and enter your tax ID and billing address for the tax invoice. Or request a company quotation straight from the quote button. For anything else call 02-570-8449 or reach us on LINE @itgenius.

Instructors

Run this course for your whole team

We run this course in-house, tailored to your stack.

Corporate training quote