Course Details
A 2-day course, 6 hours per day (12 hours in total), delivered as lectures with workshops that produce real documents. No prior ISMS background required. The content follows the latest ISO/IEC 27001 and draws on ISO/IEC 27002 for implementation detail. Learners take home a template set covering asset register, risk register, Statement of Applicability and audit plan, plus their own organizational risk register and draft SoA. This is a knowledge and readiness course, not an assessment or certification. Certification must be obtained separately from an accredited certification body.
Day 1: From the Standard to Risk Assessment
Section 1: What an Information Security Management System Is
- Information security defined: confidentiality, integrity and availability
- Why buying security products differs from running a management system that endures
- The real benefits beyond having a certificate to show partners
- The common trap: outsourced paperwork producing a system nobody actually follows
Section 2: The Structure of the Standard
- An overview of clauses 4 through 10 and how they form a continual improvement cycle
- The role of top management and what the standard demands of them directly
- Mandatory clauses versus selectable Annex A controls
- Its relationship to other management system standards and running them together
Section 3: Scope and Organizational Context
- Analyzing internal and external context and identifying interested parties
- Defining a scope that covers what matters without exceeding your capacity
- Setting a security policy and measurable security objectives
- Workshop: draft your own scope statement and security policy
Section 4: Asset Identification and Risk Assessment
- Building an information asset register and assigning asset owners
- Identifying threats and vulnerabilities and rating likelihood against impact
- Setting risk acceptance criteria and prioritizing what to treat first
- Workshop: assess the risk of a core business system into the risk register
Section 5: Risk Treatment and Control Selection
- Treatment options: reduce, accept, transfer or avoid, and how to decide
- Selecting Annex A controls proportionate to the risk and the budget
- Writing the Statement of Applicability and justifying excluded controls
- Workshop: produce a draft SoA from your risk assessment
Day 2: Controls, Auditing and Certification
Section 6: Organizational and People Controls
- Policies, defined roles and segregation of duties
- Managing external suppliers and security requirements in contracts
- Managing people before, during and after employment
- Building awareness and training that actually changes behaviour
Section 7: Physical and Technological Controls
- Controlling access to premises and server rooms, and managing equipment
- System access control, privilege management and authentication
- Encryption, backup, and vulnerability and patch management
- Logging, event monitoring and network security controls
Section 8: Required Documents and Records
- The documents the standard mandates and the level of detail that suffices
- Document control, versioning and retaining records as evidence
- Keeping documentation from growing until nobody can follow it
- Lab: compare your existing documents against the mandated list
Section 9: Internal Audit and Management Review
- Planning the internal audit programme and selecting independent auditors
- Audit technique: interviewing, requesting evidence and recording findings
- Handling nonconformities and corrective action that reaches the root cause
- Workshop: run a simulated internal audit and record findings against a checklist
Section 10: Certification and Assessment Readiness
- The certification path: stage one, stage two and annual surveillance audits
- Choosing a certification body and what to ask before committing
- The questions assessors typically ask and the evidence to prepare in advance
- Keeping the system alive after the certificate arrives
Section 11: Mapping to PDPA and the Rollout Plan
- Where the standard already satisfies PDPA security obligations
- Sharing the asset and risk registers across both programmes to avoid duplicate work
- Assessing organizational readiness and planning the project against a real budget
- Workshop: build your own 12-month implementation plan and present it