The Information Security Leadership Forums' Certified ISO 27001 Lead Implementer Course is a 5-day information packed learning experience. Check out the course overview video, day-by-day course curriculum, and more details on this page.
Enrollment for our next available
Certified ISO 27001 Lead Implementer Course
scheduled for March 20 - 24, 2023
closes at 5:00 PM (US Eastern Time Zone) on March 16, 2023
Before Registration Closes
Who Should Take This Course?
How Does The ISO 27001 Lead Implementer Course Relate to Me?
Select the role below that best suite your situation
Disclaimer: these are not customer testimonials, but rather stories of real companies and situations to help you appreciate how this course may be seen or affect people in different roles. Names and details have been altered for privacy reasons.
Schedule, Registration, and Cost
Forum members receive an automatic $500 discount during check out off the list price as follows:
Live Online - Regular Price $2,995 to $2,495
In Person - Regular Price $3,495 to $2,995.
Self-paced Video Online Learning - Regular Price $995 to $495
Non-members are welcome to register at the standard list price noted in grey above
1. On-site Training Class Availability is Subject To - No Local Pandemic or Protest / Rioting Restrictions. Where Restrictions Are In Place, The Course will Revert to Live Online.
2. If an early registration or special discount has been offered for a course, but is no longer visible on the course registration page, then the offer has expired and is no longer available to redeem.
3. Member discounts are not stackable with non-member discount offers.
Day One - Introduction and Planning for an Information Security Management System (ISMS)
- Course introduction
- A primer on the ISO 27000 family of standards and guides
- An ISO 27001 ISMS
- Acclimating to the organization
- Business Process Mapping
- Performing an Asset Inventory to support a risk assessment
- Defining ISMS Program Goals & Priorities
- Defining the scope of the ISMS
Day Two - Planning for an ISMS and Risk Management
- Understanding and building a Business Case for an ISMS
- Understanding the requirement for, and performing the mandatory legal & regulatory review
- Understanding the mandatory Statement of Applicability, and how to create one
- Fundamental of a risk assessment
- Familiarization with and understanding how to perform a Gap and Impact Assessments, and prepare the mitigation plan
- Understanding the need for an ISMS Program Charter Development and familiarization on how to build one
- Understanding a practical approach to developing governance for your ISMS, including Information Security Policy, Policy
- Standards, Technical Security Operating Standards, and Technical Security Configuration Standards
Day Three - Develop and Implement ISMS
- ISMS Governance continued with Standard Security Operating Processes, and Technical Security Operating Directives (procedures)
- Performance Management
- Communications Program
- Mitigation Plan Implementation
- Operational Transfer and Acceptance
Day Four - Management Oversight, Auditing and Managing an ISMS based on ISO 27001
- A walk through of the ISO 27001 Annex A Control Objectives & Controls
- Understanding the mandatory requirement for an independent security assessment
- How to develop an Internal Audit program to support an ISMS
- Understanding the requirements for an ISMS Leadership Review, including direction for continuous improvement
- Understanding the end-to-end ISMS certification process, including the certification audit and its requirements
- Understanding the standard's requirement for the establishment and ongoing management of Information Security Incident with an ISMS
Day Five - Practical & Written Certification Exams
- Morning: 3 hour written exam
- Afternoon: Practical Exam - Formal Presentation of ISMS Business Case to the Organization's Board of Directors
1. Both written and practical exams are mandatory, in order to meet the certification requirements set out by the Information Security Leadership Forum, this course's certifying body.
2. Formal business attire is mandatory for you practical exam. Please be sure to pack / dress appropriately. Men are required to wear a jacket and tie, and women the equivalent.
When designing our Certified ISO 27001 Lead Implementer Course, great care is taken to identify key areas the course must focus on in order to ensure student achieve the goals the course was setup to accomplish. These learning objectives are highlighted as follows:
Understand the application of an Information Security Program as prescribed by ISO 27001.
Master the concepts, approaches, standards, methods and techniques required for the effective management of an organizational Information Security Program
Familiarity with the various sub-programs under an Information Security Program, and their interrelationships to establish a holistic enterprise information security program.
Develop the expertise to lead an organization in the design, development, implementation, management and maintenance of an Information Security Program
Familiarity with the subject matter experts and stakeholders that need to be engaged, and how to apply their expertise to support an organization in the establishment of an Information Security Management System
Develop fundamental knowledge and skills required to manage a team that is implementing the ISO27001 standard
What You Get!
Certification Exam Information
Certification training hosted by the Information Security Leadership Forum, is developed, maintained and delivered by the Center for Information Management and Assurance, the Forum's official certification training partner.