Introduction to ISO27001 Implementation
Course Content
Module 1: Foundations, roles, and implementation setup
You don't currently have access to this content
7 Topics
Step 1: Establish the implementation team
You don't currently have access to this content
Step 2: Define roles and responsibilities
You don't currently have access to this content
Step 3: Set up the governance body
You don't currently have access to this content
Step 4: Assign document and control ownership
You don't currently have access to this content
Step 5: Build the implementation roadmap
You don't currently have access to this content
Module 1 Example
You don't currently have access to this content
Module 1 Outputs
You don't currently have access to this content
Module 2: Organisation, context, scope, and interested parties
You don't currently have access to this content
7 Topics
Step 1: Create the organisation overview
You don't currently have access to this content
Step 2: Identify interested parties and their requirements
You don't currently have access to this content
Step 3: Analyse internal and external issues
You don't currently have access to this content
Step 4: Define the ISMS scope
You don't currently have access to this content
Step 5: Link context to later risk work
You don't currently have access to this content
Module 2 Example
You don't currently have access to this content
Module 2 Outputs
You don't currently have access to this content
Module 3: Legal, regulatory, contractual, and compliance obligations
You don't currently have access to this content
7 Topics
Step 1: Identify applicable laws and regulations
You don't currently have access to this content
Step 2: Identify contractual obligations
You don't currently have access to this content
Step 3: Build the obligations register
You don't currently have access to this content
Step 4: Avoid over-declaration
You don't currently have access to this content
Step 5: Link obligations to policies, risks, and controls
You don't currently have access to this content
Module 3 Example
You don't currently have access to this content
Module 3 Outputs
You don't currently have access to this content
Module 4: Assets, data, software, and suppliers
You don't currently have access to this content
7 Topics
Step 1: Build the physical and virtual asset register
You don't currently have access to this content
Step 2: Build the data asset register
You don't currently have access to this content
Step 3: Record software licences and intellectual property concerns
You don't currently have access to this content
Step 4: Build the supplier register
You don't currently have access to this content
Step 5: Identify gaps and risks
You don't currently have access to this content
Module 4 Example
You don't currently have access to this content
Module 4 Output
You don't currently have access to this content
Module 5: ISMS design, objectives, competence, and monitoring
You don't currently have access to this content
7 Topics
Step 1: Set information security objectives
You don't currently have access to this content
Step 2: Create the ISMS overview
You don't currently have access to this content
Step 3: Build the competency matrix
You don't currently have access to this content
Step 4: Summarise information classification
You don't currently have access to this content
Step 5: Define what will be measured
You don't currently have access to this content
Module 5 Example
You don't currently have access to this content
Module 5 Outputs
You don't currently have access to this content
Module 6: Policies and statement of applicability
You don't currently have access to this content
7 Topics
Step 1: Define the policy set
You don't currently have access to this content
Step 2: Write policies in clear, usable language
You don't currently have access to this content
Step 3: Determine applicable Annex A controls
You don't currently have access to this content
Step 4: Justify exclusions properly
You don't currently have access to this content
Step 5: Link policies and SoA decisions to risk treatment
You don't currently have access to this content
Module 6 Example
You don't currently have access to this content
Module 6 Outputs
You don't currently have access to this content
Module 7: Risk assessment, risk register, and treatment
You don't currently have access to this content
7 Topics
Step 1: Define the risk method
You don't currently have access to this content
Step 2: Conduct the risk review workshop
You don't currently have access to this content
Step 3: Populate the risk register
You don't currently have access to this content
Step 4: Link risks back to earlier modules
You don't currently have access to this content
Step 5: Define treatment actions
You don't currently have access to this content
Module 7 Example
You don't currently have access to this content
Module 7 Outputs
You don't currently have access to this content
Module 8: Planning, communication, training, and awareness
You don't currently have access to this content
7 Topics
Step 1: Create the annual audit plan
You don't currently have access to this content
Step 2: Create the communication plan
You don't currently have access to this content
Step 3: Create the ISMS change plan
You don't currently have access to this content
Step 4: Design the training programme
You don't currently have access to this content
Step 5: Deliver and evidence training
You don't currently have access to this content
Module 8 Example
You don't currently have access to this content
Module 8 Outputs
You don't currently have access to this content
Module 9: Business continuity, disaster recovery, and resilience testing
You don't currently have access to this content
7 Topics
Step 1: Conduct the business impact assessment
You don't currently have access to this content
Step 2: Define continuity objectives and strategy
You don't currently have access to this content
Step 3: Create continuity and recovery plans
You don't currently have access to this content
Step 4: Define realistic scenarios
You don't currently have access to this content
Step 5: Test and record evidence
You don't currently have access to this content
Module 9 Example
You don't currently have access to this content
Module 9 Outputs
You don't currently have access to this content
Module 10: Operational processes, evidence, and day-to-day control operations
You don't currently have access to this content
7 Topics
Step 1: Identify key operational processes
You don't currently have access to this content
Step 2: Write step-by-step procedures
You don't currently have access to this content
Step 3: Define exception handling
You don't currently have access to this content
Step 4: Define evidence sources
You don't currently have access to this content
Step 5: Make processes operational
You don't currently have access to this content
Module 10 Example
You don't currently have access to this content
Module 10 Outputs
You don't currently have access to this content
Module 11: Internal audit, management review, continual improvement, and certification readiness
You don't currently have access to this content
7 Topics
Step 1: Conduct the internal audit
You don't currently have access to this content
Step 2: Record findings and corrective actions
You don't currently have access to this content
Step 3: Hold the management review
You don't currently have access to this content
Step 4: Run continual improvement
You don't currently have access to this content
Step 5: Prepare for certification audit
You don't currently have access to this content
Module 11 Example
You don't currently have access to this content
Module 11 Outputs
You don't currently have access to this content
