Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Udemy

ISO/IEC 27001: Information Security Management System (ISMS)

via Udemy

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Understand and implement an ISMS to ISO/IEC 27001 — all the requirements and the 93 Annex A security controls

What you'll learn:
  • Understand what is an ISMS and what are the requirements for an ISMS
  • Become familiar with ther requirements of ISO/IEC 27001:2022
  • Understand with the framework for information security management proposed by ISO/IEC 27001
  • Obtain the required knowledge to participate in ISMS audits and implementation projects
  • Understand the information security controls that should be addressed by an ISMS
  • Acquire the necessary knowledge to coordinate information security management activities in an organization

ISO/IEC 27001 is the world's most popular standard for information security management. Certification to this standard is highly sought after, as it demonstrates an organization's ability to safeguard information with robust security controls — ensuring trust and reliability.

Global leaders like Google, Apple, Adobe and Oracle — along with financial institutions, healthcare providers, insurance companies, educational institutions, manufacturers, service companies, government agencies, and businesses of all sizes — have implemented and certified information security management systems (ISMS) according to ISO/IEC 27001, showcasing their commitment to protecting the confidentiality, integrity and availability of the information they handle.

Course overview

This course covers the management system requirements of ISO/IEC 27001:2022 along with the information security controls of Annex A — a comprehensive guide to implementing an ISMS, meeting the requirements and achieving compliance. The course is structured into six sections:

  • Introduction — the concept of information security, what an ISMS is, the purpose and structure of ISO/IEC 27001, and the other standards of the ISO/IEC 27000 family relevant to an information security professional

  • The management system requirements of ISO/IEC 27001 — following the structure of the standard, covering all requirements in each clause and sub-clause: the context of the organization, the scope of the ISMS, information security risk assessment and risk treatment, the information security policy and objectives, ISMS documentation, internal audits, the management review, and the management of nonconformities

  • The 93 Annex A controls, across four sections — the information security controls of ISO/IEC 27001, divided into 4 themes: organizational controls, people controls, physical controls and technological controls. Among the subjects covered: incident management, supplier relationships, network security, business continuity and ICT readiness, equipment maintenance, storage media, secure development and secure coding, cryptography, authentication information, screening of candidates, the disciplinary process, change management, backup and redundancy, malware protection, technical vulnerability management, logging and monitoring, security awareness and training, user end-point devices, capacity management, access privileges, protection against environmental threats, and cabling security

A dedicated video at the end of the course covers certification to ISO/IEC 27001 — for organizations and for individuals.

The course is updated to account for the 2024 Amendment to ISO/IEC 27001 on climate change.

Who this course is for

The information will be very useful to you if you:

  • work as a consultant helping organizations apply standards and implement management systems

  • participate in audits — internal or external — in accordance with ISO/IEC 27001

  • work in a company that applies, or intends to apply, an information security management system

  • are looking to build a career in information security, or have an interest in information security management in general

And if none of these fits your profile, you can use the course for information security awareness — you will gain a clear picture of the requirements that many organizations around the world have decided to adopt.

After completing all the videos you will have a solid understanding of the requirements for an information security management system and how an organization can apply one and claim conformity to ISO/IEC 27001:2022. The course provides 7 hours of condensed information you can revisit anytime — and once you finish, you can demonstrate your knowledge with the certificate of completion issued by Udemy.

This course contains a promotion.

Syllabus

  • Introductive part
  • Management system requirements of ISO/IEC 27001:2022
  • Organizational controls
  • People controls
  • Physical controls
  • Technological controls

Taught by

Cristian Vlad Lupa, rigcert.education

Reviews

4.5 rating at Udemy based on 19912 ratings

Start your review of ISO/IEC 27001: Information Security Management System (ISMS)

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.