SlideShare a Scribd company logo
1 of 28
ISO/IEC 27001
Foundation Certification
Training Course
For more information please visit us at www.interpromusa.com, email us at Contact@interpromusa.com, or call us at (+1)480-699-9642
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 1
by
MART ROVERS
INTERPROM
“What’s Up?”
• ISO/IEC 27001 Explained
• Typical Benefits
• Unexpected Benefits
• Four Steps to Compliance
• ISO/IEC 27001
Foundation Course
• Wrap-up
Agenda
©InterProm USA – Confidential and Proprietary Information 24/23/2020
WHAT’S THE BUZZ?
ISO/IEC 27001 Explained
©InterProm USA – Confidential and Proprietary Information 34/23/2020
What is
ISO/IEC
27001:2013?
• The standard has been designed to “provide
requirements for establishing, implementing,
maintaining and continually improving an
information security management system or
ISMS”
• The standard “can be used by internal and
external parties to assess the organization’s
ability to meet the organization’s own
information security requirements”
• The standard also includes “requirements for
the assessment and treatment of information
security risks tailored to the needs of the
organization. The requirements set out in this
International Standard are generic and are
intended to be applicable to all organizations,
regardless of type, size or nature”
©InterProm USA – Confidential and Proprietary Information 44/23/2020
Current State ISO/IEC 27000 Series
©InterProm USA – Confidential and Proprietary Information 5
Currently the documents forming the standard are:
• ISO/IEC 27000:2012 : Overview of the ISO/IEC 27000 standard family
• ISO/IEC 27001:2013 : Information security management system requirements
• ISO/IEC 27002:2013 : Code of practice for information security controls
• ISO/IEC 27003:2010 : Guidance on ISMS implementation
• ISO/IEC 27004:2016 :Metrics for information security management measurement
• ISO/IEC 27005:2011 : Information security risk management
• ISO/IEC 27006:2011 : Guidance on certification or registration process for accredited ISMS certification
or registration bodies
• ISO/IEC 27007:2011 : Guidance on auditing an ISMS
• ISO/IEC TR 27008:2011 : Guidance on auditing technical controls
• ISO/IEC 27009 : Compliance for various versions of ISO/IEC 27001
• ISO/IEC 27010:2012 : Guidance on information security management of inter-sector and inter-
organizational communications
• ISO/IEC 27011:2008 : Guidance on the telecommunications organizations
• ISO/IEC 27013:2012 : Guidance on the joint implementation of ISO/IEC 27001 and ISO/IEC 20000-1
• ISO/IEC 27014:2013 : Guidance on information security governance
4/23/2020
Current State ISO/IEC 27000 Series
(Continued)
©InterProm USA – Confidential and Proprietary Information 6
Currently the documents forming the standard are:
• ISO/IEC TR 27015: Guidance on financial services organizations
• ISO/IEC TR 27016: Economics of information security
• ISO/IEC 27004:2009 :Metrics for information security management measurement
• ISO/IEC 27017: Guidance on secure cloud computing
• ISO/IEC 27018: Privacy in the cloud
• ISO/IEC TR 27019: Information security for process control – based on ISO/IEC 27002 for process
control systems specific to the energy utility industry
• ISO/IEC 27031:2011 : Focusing on business continuity
• ISO/IEC 27032:2012 : Focusing on cybersecurity
• ISO/IEC 27033: Developing standard focussing on network security
• ISO/IEC 27034: Partially published guidance on application security
• ISO/IEC 27035:2011 : Focusing on incident management
• ISO/IEC 27036: Upcoming standard providing guidance on supplier relationships
• ISO/IEC 27037:2012 : Guidance on the management of digital evidence
• ISO/IEC 27038: An upcoming specification for digital redaction
• ISO/IEC 27039: Focusing on intrusion detection and prevention
• ISO/IEC 27040: Guidance on secure storage
• ISO/IEC 27102:2019 Guidance on cyber insurance iso.org
4/23/2020
ISO/IEC 27001
• Risk-based Standard
• The ISMS:
– Preserves the confidentiality,
integrity and availability of
information by applying a risk
management process
– Is part of and integrated with the
organization’s processes and
overall management structure
• Information security is considered
in the design of processes,
information systems, and
controls.
Characteristics
©InterProm USA – Confidential and Proprietary Information 74/23/2020
Contents ISO/IEC 27001
Information Security Management Systems - Requirements
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organization
4.1 Understanding the organization and its
context
4.2 Understanding the needs and expectations
of interested parties
4.3 Determining the scope of the information
security management system
4.4 Information security management system
5. Leadership
5.1 Leadership and commitments
5.2 Policy
5.3 Organizational roles, responsibilities, and
authorities
6. Planning
6.1 Actions to address risks and opportunities
6.2 Information security objectives and planning
to achieve them
7. Support
7.1 Resources
7.2 Competence
7.3 Awareness
7.4 Communication
7.5 Documented information
8. Operation
8.1 Operational planning and control
8.2 Information security risk assessment
8.3 Information security risk treatment
9. Performance evaluation
9.1 Monitoring, measurement, analysis and evaluation
9.23 Internal audit
9.3 Management review
10.Improvement
10.1 Nonconformity and corrective action
10.2 Continual improvement
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 8
Contents ISO/IEC 27002
Code of Practice for Information Security Controls
1. Scope
2. Normative references
3. Terms and definitions
4. Structure of this standard
5. Information security policies
5.1 Management direction for information security
6. Organizing for information security
6.1 Internal organization
6.2 Mobile devices and teleworking
7. Human resource security
7.1 Prior to employment
7.2 During employment
7.3 Termination and change of employment
8. Asset management
8.1 Responsibility for assets
8.2 Information classification
8.3 Media handling
9. Access control
9.1 Business requirements of access control
9.2 User access management
9.3 User responsibilities
9.4 System and application access control
8. Cryptography
10.1 Cryptographic controls
9. Physical and environmental security
11.1 Secure areas
11.2 Equipment
12. Operations security
12.1 Operational procedures and responsibilities
12.2 Protection from malware
12.3 Backup
12.4 Logging and monitoring
12.5 Control of operational software
12.6 Technical vulnerability management
12.7 Information systems audit considerations
13. Communications security
13.1 Network security management
13.2 Information transfer
14. System acquisition, development and maintenance
14.1 Security requirements of information systems
14.2 Security in development and support processes
15. Supplier relationships
15.1 Information security in supplier relationships
15.2 Supplier service delivery management
16. Information security incident management
16.1 Management of information security incidents and improvements
17. Information security aspects of business continuity
management
17.1 Information security continuity
17.2 Redundancies
18. Compliance
18.1 Compliance with legal and contractual agreements
18.2 Information security reviews
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 9
WHAT’S TYPICAL?
Benefits of ISO/IEC 27001
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 10
ISO/IEC 27001
Compliance
1. Increased security posture
2. Increased security awareness
and employee satisfaction
3. Increased clarity around risks
and risk ownership
4. Improved structure and
transparency of responsibilities
and focus
5. Reduction in the need for
frequent audits
6. Easier to obtain an independent
opinion about your security
posture
Typical Internal
Benefits
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 11
ISO/IEC 27001
Compliance
1. Increased chances of winning
new business
2. Avoidance of financial penalties
and losses due to data breaches
3. Enhanced protection of your
name and reputation
4. Easier compliance with legal,
contractual and regulatory
requirements
5. Internationally accepted
standard
Typical External
Benefits
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 12
WHAT’S UNEXPECTED?
Benefits of ISO/IEC 27001
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 13
ISO/IEC 27001
Compliance
1. Cross-enterprise commitment
2. Cross-enterprise participation
3. Incorporation of information
security practices in existing
practices (to-be)
4. Implementation of a
management system
5. Compliance vs. Certification
6. 3rd-Party selection and
integration
7. …Expect the unexpected…
Unexpected
Benefits
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 14
WHAT ARE THE FOUR STEPS?
Comply with ISO/IEC 27001
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 15
ISO/IEC 27001
Compliance
Phases Towards
Compliance
1. Familiarize
2. Adopt
3. Implement
4. Improve
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 16
• Training and Awareness
• Management Commitment
• Program and Project Initiation
• Organizational Change
• Continual Improvement
TRAINING COURSE
CHARACTERISTICS
ISO/IEC 27001 Foundation
Certification
©InterProm USA – Confidential and Proprietary Information 174/23/2020
ISO/IEC 27001
Foundation
Qualification
Scheme
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 18
Get qualified!
ISO/IEC 27001
Foundation
1. Chief Information Security Officers
(CISOs)
2. Information Security Officers
3. Information Security Subject Matter
Experts
4. Program/Project Managers
5. Internal/External Auditors
6. Service/Product Managers
7. Consultants/Coaches
8. Anyone who is involved with an
effort to become or uphold ISO/IEC
27001 compliance or certification
Target Audience
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 19
No Prerequisites!
ISO/IEC 27001
Foundation
• What are some of the definitions of information
security management?
• Who in my organization plays a role in information
security? And what are these roles?
• How to establish the information security
management system? And what does it take to
improve it? How do I know that it is effective?
• What does it mean to manage information
security risks? And what is risk treatment?
• ISO/IEC 27001 has 114 information security
controls? What are they? Why do I need them?
And what does ISO/IEC 27002 have to offer?
• What is the path to ISO/IEC 27001 certification?
Training Course
Curriculum
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 20
Get educated!
ISO/IEC 27001
Foundation
Duration
• 2 days for instructor-led courses
• 2-4 days for self-paced courses
Formats
• Instructor-led
– Live Online
– Onsite
• Self-paced online
Training Course
Duration and
Formats
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 21
Learn from the best!
ISO/IEC 27001
Foundation
Examination Institute
• APMG International
Exam
• 40 multiple-choice questions
• 60 minutes exam time
• Paper-based or online
• INTERPROM’s pass rate: 100%
Certification
Exam
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 22
With Exam Prep!
ISO/IEC 27001
Foundation
Fees per Participant
• Instructor-led
– Live Online: USD $1,195
– Onsite: USD $1,495
• Self-paced online
– USD $495
– 4 months access
– Exam fees: $200
Training Course
Fees
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 23
Exam included for
Instructor-led!
ISO/IEC 27001
Foundation
Schedule
• Instructor-led
– Live Online:
https://interpromusa.com/events/?tribe_paged=1&tribe_
event_display=list&tribe-bar-
search=ISO%2FIEC+27001+Foundation
– Onsite:
https://interpromusa.com/contact-us/
• Self-paced online
https://interpromusa.com/product/isoiec-27001-
foundation-course-self-paced-online/
Training Course
Schedule
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 24
Sign up and learn!
MORE INFORMATION?
Wrap-Up
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 25
ISO/IEC 27001
Foundation
More Information
• Visit Us
– https://interpromusa.com/iec-iso-
27001-certification-training/
• Email Us
– Contact@InterPromUSA.com
• Call Us
– (+1) 480-699-9642
Glad to Help!
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 26
See you soon!
About INTERPROM
Elevating Business Performance through:
• Coaching, Training, Workshop and Auditing Services
• Specialty Areas:
• Service Management
• E.g. ISO/IEC 20000, FitSM, ITIL, VeriSM
• Information Security Management
• E.g. ISO/IEC 27001, NIST
• Business Relationship Management
• E.g. ISO 44001, BRMiBOK®
• Organizational Change Management
• E.g. CMBOK®
• IT Governance
• E.g. ISO/IEC 38500, COBIT®
• Business Continuity Management
• E.g. ISO 22301
• Risk Management
• E.g. ISO 31000, MoR®
©InterProm USA – Confidential and Proprietary Information 274/23/2020
IF YOU HAVE ANY QUESTIONS OR FEEDBACK, PLEASE DO NOT
HESITATE TO CONTACT US:
CONTACT@INTERPROMUSA.COM / +1 480-699-9642
4/23/2020 ©InterProm USA – Confidential and Proprietary Information 28

More Related Content

What's hot

Implementing ISO27001 2013
Implementing ISO27001 2013Implementing ISO27001 2013
Implementing ISO27001 2013scttmcvy
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementationRalf Braga
 
Overview of ISO 27001 ISMS
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMSAkhil Garg
 
Why ISO27001 For My Organisation
Why ISO27001 For My OrganisationWhy ISO27001 For My Organisation
Why ISO27001 For My OrganisationVigilant Software
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?PECB
 
ISMS Part I
ISMS Part IISMS Part I
ISMS Part Ikhushboo
 
Isms awareness presentation
Isms awareness presentationIsms awareness presentation
Isms awareness presentationPranay Kumar
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentationMidhun Nirmal
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001PECB
 
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to Know
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to KnowISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to Know
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to KnowPECB
 
2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdfControlCase
 
ISO 27001 - information security user awareness training presentation - Part 1
ISO 27001 - information security user awareness training presentation - Part 1ISO 27001 - information security user awareness training presentation - Part 1
ISO 27001 - information security user awareness training presentation - Part 1Tanmay Shinde
 

What's hot (20)

Implementing ISO27001 2013
Implementing ISO27001 2013Implementing ISO27001 2013
Implementing ISO27001 2013
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementation
 
Overview of ISO 27001 ISMS
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
 
ISO 27001 Benefits
ISO 27001 BenefitsISO 27001 Benefits
ISO 27001 Benefits
 
ISO 27001:2022 Introduction
ISO 27001:2022 IntroductionISO 27001:2022 Introduction
ISO 27001:2022 Introduction
 
Iso 27001 2013
Iso 27001 2013Iso 27001 2013
Iso 27001 2013
 
ISO 27001 - Information Security Management System
ISO 27001 - Information Security Management SystemISO 27001 - Information Security Management System
ISO 27001 - Information Security Management System
 
Why ISO27001 For My Organisation
Why ISO27001 For My OrganisationWhy ISO27001 For My Organisation
Why ISO27001 For My Organisation
 
27001.pptx
27001.pptx27001.pptx
27001.pptx
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
ISMS Part I
ISMS Part IISMS Part I
ISMS Part I
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
Isms awareness presentation
Isms awareness presentationIsms awareness presentation
Isms awareness presentation
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to Know
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to KnowISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to Know
ISO/IEC 27701 vs. ISO/IEC 27001 vs. NIST: Essential Things You Need to Know
 
2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf
 
ISO 27001 - information security user awareness training presentation - Part 1
ISO 27001 - information security user awareness training presentation - Part 1ISO 27001 - information security user awareness training presentation - Part 1
ISO 27001 - information security user awareness training presentation - Part 1
 

Similar to Iso iec 27001 foundation training course by interprom

20CS024 Ethics in Information Technology
20CS024 Ethics in Information Technology20CS024 Ethics in Information Technology
20CS024 Ethics in Information TechnologyKathirvel Ayyaswamy
 
Achieving ISO 27001 Certification.pdf
Achieving ISO 27001 Certification.pdfAchieving ISO 27001 Certification.pdf
Achieving ISO 27001 Certification.pdfmicroteklearning21
 
Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Chandan Singh Ghodela
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterOperational Excellence Consulting
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
Cyber resolution ban-ana comparing to ana-nas.pdf
Cyber resolution ban-ana comparing to ana-nas.pdfCyber resolution ban-ana comparing to ana-nas.pdf
Cyber resolution ban-ana comparing to ana-nas.pdftoncik
 
Iso iec 27032 foundation - cybersecurity training course
Iso iec 27032 foundation - cybersecurity training courseIso iec 27032 foundation - cybersecurity training course
Iso iec 27032 foundation - cybersecurity training courseMart Rovers
 
ISMS Requirements
ISMS RequirementsISMS Requirements
ISMS Requirementshumanus2
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness TrainingISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness TrainingOperational Excellence Consulting
 
102 Information security standards and specifications
102 Information security standards and specifications102 Information security standards and specifications
102 Information security standards and specificationsSsendiSamuel
 
english_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxenglish_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxssuser00d6eb
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksIT Governance Ltd
 
Continual Compliance for PCI DSS, E13PA and ISO 27001/2
Continual Compliance for PCI DSS, E13PA and ISO 27001/2Continual Compliance for PCI DSS, E13PA and ISO 27001/2
Continual Compliance for PCI DSS, E13PA and ISO 27001/2ControlCase
 
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?PECB
 
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701PECB
 
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to Know
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to KnowCMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to Know
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to KnowPECB
 
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...ControlCase
 
Continual Compliance Monitoring
Continual Compliance MonitoringContinual Compliance Monitoring
Continual Compliance MonitoringKimberly Simon MBA
 
What is ISO 27001 and why you should get compliant
What is ISO 27001 and why you should get compliant What is ISO 27001 and why you should get compliant
What is ISO 27001 and why you should get compliant Ajay Unni
 

Similar to Iso iec 27001 foundation training course by interprom (20)

20CS024 Ethics in Information Technology
20CS024 Ethics in Information Technology20CS024 Ethics in Information Technology
20CS024 Ethics in Information Technology
 
Achieving ISO 27001 Certification.pdf
Achieving ISO 27001 Certification.pdfAchieving ISO 27001 Certification.pdf
Achieving ISO 27001 Certification.pdf
 
Presentaion.pptx
Presentaion.pptxPresentaion.pptx
Presentaion.pptx
 
Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
Cyber resolution ban-ana comparing to ana-nas.pdf
Cyber resolution ban-ana comparing to ana-nas.pdfCyber resolution ban-ana comparing to ana-nas.pdf
Cyber resolution ban-ana comparing to ana-nas.pdf
 
Iso iec 27032 foundation - cybersecurity training course
Iso iec 27032 foundation - cybersecurity training courseIso iec 27032 foundation - cybersecurity training course
Iso iec 27032 foundation - cybersecurity training course
 
ISMS Requirements
ISMS RequirementsISMS Requirements
ISMS Requirements
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness TrainingISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
 
102 Information security standards and specifications
102 Information security standards and specifications102 Information security standards and specifications
102 Information security standards and specifications
 
english_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxenglish_bok_ismp_202306.pptx
english_bok_ismp_202306.pptx
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
 
Continual Compliance for PCI DSS, E13PA and ISO 27001/2
Continual Compliance for PCI DSS, E13PA and ISO 27001/2Continual Compliance for PCI DSS, E13PA and ISO 27001/2
Continual Compliance for PCI DSS, E13PA and ISO 27001/2
 
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
 
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
 
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to Know
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to KnowCMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to Know
CMMC, ISO/IEC 27001, ISO/IEC 27032, and NIST – What You Need to Know
 
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
 
Continual Compliance Monitoring
Continual Compliance MonitoringContinual Compliance Monitoring
Continual Compliance Monitoring
 
What is ISO 27001 and why you should get compliant
What is ISO 27001 and why you should get compliant What is ISO 27001 and why you should get compliant
What is ISO 27001 and why you should get compliant
 

More from Mart Rovers

Business continuity management per ISO 22301 - a certification training cour...
 Business continuity management per ISO 22301 - a certification training cour... Business continuity management per ISO 22301 - a certification training cour...
Business continuity management per ISO 22301 - a certification training cour...Mart Rovers
 
Brmp certification training course by interprom
Brmp certification training course by interpromBrmp certification training course by interprom
Brmp certification training course by interpromMart Rovers
 
Fitsm foundation training course by interprom
Fitsm foundation training course by interpromFitsm foundation training course by interprom
Fitsm foundation training course by interpromMart Rovers
 
Change management foundation training course by interprom
Change management foundation training course by interpromChange management foundation training course by interprom
Change management foundation training course by interpromMart Rovers
 
Iso iec 20000 foundation training course by interprom
Iso iec 20000 foundation training course by interpromIso iec 20000 foundation training course by interprom
Iso iec 20000 foundation training course by interpromMart Rovers
 
What is iso iec 20000
What is iso iec 20000What is iso iec 20000
What is iso iec 20000Mart Rovers
 
What is iso iec 20000
What is iso iec 20000What is iso iec 20000
What is iso iec 20000Mart Rovers
 

More from Mart Rovers (7)

Business continuity management per ISO 22301 - a certification training cour...
 Business continuity management per ISO 22301 - a certification training cour... Business continuity management per ISO 22301 - a certification training cour...
Business continuity management per ISO 22301 - a certification training cour...
 
Brmp certification training course by interprom
Brmp certification training course by interpromBrmp certification training course by interprom
Brmp certification training course by interprom
 
Fitsm foundation training course by interprom
Fitsm foundation training course by interpromFitsm foundation training course by interprom
Fitsm foundation training course by interprom
 
Change management foundation training course by interprom
Change management foundation training course by interpromChange management foundation training course by interprom
Change management foundation training course by interprom
 
Iso iec 20000 foundation training course by interprom
Iso iec 20000 foundation training course by interpromIso iec 20000 foundation training course by interprom
Iso iec 20000 foundation training course by interprom
 
What is iso iec 20000
What is iso iec 20000What is iso iec 20000
What is iso iec 20000
 
What is iso iec 20000
What is iso iec 20000What is iso iec 20000
What is iso iec 20000
 

Recently uploaded

Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibitjbellavia9
 
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxExploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxPooja Bhuva
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxmarlenawright1
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxJisc
 
FSB Advising Checklist - Orientation 2024
FSB Advising Checklist - Orientation 2024FSB Advising Checklist - Orientation 2024
FSB Advising Checklist - Orientation 2024Elizabeth Walsh
 
Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfSherif Taha
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxDenish Jangid
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfDr Vijay Vishwakarma
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsKarakKing
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxPooja Bhuva
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...Poonam Aher Patil
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...Pooja Bhuva
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.christianmathematics
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - Englishneillewis46
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structuredhanjurrannsibayan2
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17Celine George
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...Nguyen Thanh Tu Collection
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxDr. Ravikiran H M Gowda
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...Nguyen Thanh Tu Collection
 

Recently uploaded (20)

Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibit
 
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxExploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
FSB Advising Checklist - Orientation 2024
FSB Advising Checklist - Orientation 2024FSB Advising Checklist - Orientation 2024
FSB Advising Checklist - Orientation 2024
 
Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdf
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structure
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptx
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 

Iso iec 27001 foundation training course by interprom

  • 1. ISO/IEC 27001 Foundation Certification Training Course For more information please visit us at www.interpromusa.com, email us at Contact@interpromusa.com, or call us at (+1)480-699-9642 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 1 by MART ROVERS INTERPROM
  • 2. “What’s Up?” • ISO/IEC 27001 Explained • Typical Benefits • Unexpected Benefits • Four Steps to Compliance • ISO/IEC 27001 Foundation Course • Wrap-up Agenda ©InterProm USA – Confidential and Proprietary Information 24/23/2020
  • 3. WHAT’S THE BUZZ? ISO/IEC 27001 Explained ©InterProm USA – Confidential and Proprietary Information 34/23/2020
  • 4. What is ISO/IEC 27001:2013? • The standard has been designed to “provide requirements for establishing, implementing, maintaining and continually improving an information security management system or ISMS” • The standard “can be used by internal and external parties to assess the organization’s ability to meet the organization’s own information security requirements” • The standard also includes “requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this International Standard are generic and are intended to be applicable to all organizations, regardless of type, size or nature” ©InterProm USA – Confidential and Proprietary Information 44/23/2020
  • 5. Current State ISO/IEC 27000 Series ©InterProm USA – Confidential and Proprietary Information 5 Currently the documents forming the standard are: • ISO/IEC 27000:2012 : Overview of the ISO/IEC 27000 standard family • ISO/IEC 27001:2013 : Information security management system requirements • ISO/IEC 27002:2013 : Code of practice for information security controls • ISO/IEC 27003:2010 : Guidance on ISMS implementation • ISO/IEC 27004:2016 :Metrics for information security management measurement • ISO/IEC 27005:2011 : Information security risk management • ISO/IEC 27006:2011 : Guidance on certification or registration process for accredited ISMS certification or registration bodies • ISO/IEC 27007:2011 : Guidance on auditing an ISMS • ISO/IEC TR 27008:2011 : Guidance on auditing technical controls • ISO/IEC 27009 : Compliance for various versions of ISO/IEC 27001 • ISO/IEC 27010:2012 : Guidance on information security management of inter-sector and inter- organizational communications • ISO/IEC 27011:2008 : Guidance on the telecommunications organizations • ISO/IEC 27013:2012 : Guidance on the joint implementation of ISO/IEC 27001 and ISO/IEC 20000-1 • ISO/IEC 27014:2013 : Guidance on information security governance 4/23/2020
  • 6. Current State ISO/IEC 27000 Series (Continued) ©InterProm USA – Confidential and Proprietary Information 6 Currently the documents forming the standard are: • ISO/IEC TR 27015: Guidance on financial services organizations • ISO/IEC TR 27016: Economics of information security • ISO/IEC 27004:2009 :Metrics for information security management measurement • ISO/IEC 27017: Guidance on secure cloud computing • ISO/IEC 27018: Privacy in the cloud • ISO/IEC TR 27019: Information security for process control – based on ISO/IEC 27002 for process control systems specific to the energy utility industry • ISO/IEC 27031:2011 : Focusing on business continuity • ISO/IEC 27032:2012 : Focusing on cybersecurity • ISO/IEC 27033: Developing standard focussing on network security • ISO/IEC 27034: Partially published guidance on application security • ISO/IEC 27035:2011 : Focusing on incident management • ISO/IEC 27036: Upcoming standard providing guidance on supplier relationships • ISO/IEC 27037:2012 : Guidance on the management of digital evidence • ISO/IEC 27038: An upcoming specification for digital redaction • ISO/IEC 27039: Focusing on intrusion detection and prevention • ISO/IEC 27040: Guidance on secure storage • ISO/IEC 27102:2019 Guidance on cyber insurance iso.org 4/23/2020
  • 7. ISO/IEC 27001 • Risk-based Standard • The ISMS: – Preserves the confidentiality, integrity and availability of information by applying a risk management process – Is part of and integrated with the organization’s processes and overall management structure • Information security is considered in the design of processes, information systems, and controls. Characteristics ©InterProm USA – Confidential and Proprietary Information 74/23/2020
  • 8. Contents ISO/IEC 27001 Information Security Management Systems - Requirements 1. Scope 2. Normative references 3. Terms and definitions 4. Context of the organization 4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.3 Determining the scope of the information security management system 4.4 Information security management system 5. Leadership 5.1 Leadership and commitments 5.2 Policy 5.3 Organizational roles, responsibilities, and authorities 6. Planning 6.1 Actions to address risks and opportunities 6.2 Information security objectives and planning to achieve them 7. Support 7.1 Resources 7.2 Competence 7.3 Awareness 7.4 Communication 7.5 Documented information 8. Operation 8.1 Operational planning and control 8.2 Information security risk assessment 8.3 Information security risk treatment 9. Performance evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.23 Internal audit 9.3 Management review 10.Improvement 10.1 Nonconformity and corrective action 10.2 Continual improvement 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 8
  • 9. Contents ISO/IEC 27002 Code of Practice for Information Security Controls 1. Scope 2. Normative references 3. Terms and definitions 4. Structure of this standard 5. Information security policies 5.1 Management direction for information security 6. Organizing for information security 6.1 Internal organization 6.2 Mobile devices and teleworking 7. Human resource security 7.1 Prior to employment 7.2 During employment 7.3 Termination and change of employment 8. Asset management 8.1 Responsibility for assets 8.2 Information classification 8.3 Media handling 9. Access control 9.1 Business requirements of access control 9.2 User access management 9.3 User responsibilities 9.4 System and application access control 8. Cryptography 10.1 Cryptographic controls 9. Physical and environmental security 11.1 Secure areas 11.2 Equipment 12. Operations security 12.1 Operational procedures and responsibilities 12.2 Protection from malware 12.3 Backup 12.4 Logging and monitoring 12.5 Control of operational software 12.6 Technical vulnerability management 12.7 Information systems audit considerations 13. Communications security 13.1 Network security management 13.2 Information transfer 14. System acquisition, development and maintenance 14.1 Security requirements of information systems 14.2 Security in development and support processes 15. Supplier relationships 15.1 Information security in supplier relationships 15.2 Supplier service delivery management 16. Information security incident management 16.1 Management of information security incidents and improvements 17. Information security aspects of business continuity management 17.1 Information security continuity 17.2 Redundancies 18. Compliance 18.1 Compliance with legal and contractual agreements 18.2 Information security reviews 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 9
  • 10. WHAT’S TYPICAL? Benefits of ISO/IEC 27001 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 10
  • 11. ISO/IEC 27001 Compliance 1. Increased security posture 2. Increased security awareness and employee satisfaction 3. Increased clarity around risks and risk ownership 4. Improved structure and transparency of responsibilities and focus 5. Reduction in the need for frequent audits 6. Easier to obtain an independent opinion about your security posture Typical Internal Benefits 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 11
  • 12. ISO/IEC 27001 Compliance 1. Increased chances of winning new business 2. Avoidance of financial penalties and losses due to data breaches 3. Enhanced protection of your name and reputation 4. Easier compliance with legal, contractual and regulatory requirements 5. Internationally accepted standard Typical External Benefits 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 12
  • 13. WHAT’S UNEXPECTED? Benefits of ISO/IEC 27001 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 13
  • 14. ISO/IEC 27001 Compliance 1. Cross-enterprise commitment 2. Cross-enterprise participation 3. Incorporation of information security practices in existing practices (to-be) 4. Implementation of a management system 5. Compliance vs. Certification 6. 3rd-Party selection and integration 7. …Expect the unexpected… Unexpected Benefits 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 14
  • 15. WHAT ARE THE FOUR STEPS? Comply with ISO/IEC 27001 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 15
  • 16. ISO/IEC 27001 Compliance Phases Towards Compliance 1. Familiarize 2. Adopt 3. Implement 4. Improve 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 16 • Training and Awareness • Management Commitment • Program and Project Initiation • Organizational Change • Continual Improvement
  • 17. TRAINING COURSE CHARACTERISTICS ISO/IEC 27001 Foundation Certification ©InterProm USA – Confidential and Proprietary Information 174/23/2020
  • 18. ISO/IEC 27001 Foundation Qualification Scheme 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 18 Get qualified!
  • 19. ISO/IEC 27001 Foundation 1. Chief Information Security Officers (CISOs) 2. Information Security Officers 3. Information Security Subject Matter Experts 4. Program/Project Managers 5. Internal/External Auditors 6. Service/Product Managers 7. Consultants/Coaches 8. Anyone who is involved with an effort to become or uphold ISO/IEC 27001 compliance or certification Target Audience 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 19 No Prerequisites!
  • 20. ISO/IEC 27001 Foundation • What are some of the definitions of information security management? • Who in my organization plays a role in information security? And what are these roles? • How to establish the information security management system? And what does it take to improve it? How do I know that it is effective? • What does it mean to manage information security risks? And what is risk treatment? • ISO/IEC 27001 has 114 information security controls? What are they? Why do I need them? And what does ISO/IEC 27002 have to offer? • What is the path to ISO/IEC 27001 certification? Training Course Curriculum 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 20 Get educated!
  • 21. ISO/IEC 27001 Foundation Duration • 2 days for instructor-led courses • 2-4 days for self-paced courses Formats • Instructor-led – Live Online – Onsite • Self-paced online Training Course Duration and Formats 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 21 Learn from the best!
  • 22. ISO/IEC 27001 Foundation Examination Institute • APMG International Exam • 40 multiple-choice questions • 60 minutes exam time • Paper-based or online • INTERPROM’s pass rate: 100% Certification Exam 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 22 With Exam Prep!
  • 23. ISO/IEC 27001 Foundation Fees per Participant • Instructor-led – Live Online: USD $1,195 – Onsite: USD $1,495 • Self-paced online – USD $495 – 4 months access – Exam fees: $200 Training Course Fees 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 23 Exam included for Instructor-led!
  • 24. ISO/IEC 27001 Foundation Schedule • Instructor-led – Live Online: https://interpromusa.com/events/?tribe_paged=1&tribe_ event_display=list&tribe-bar- search=ISO%2FIEC+27001+Foundation – Onsite: https://interpromusa.com/contact-us/ • Self-paced online https://interpromusa.com/product/isoiec-27001- foundation-course-self-paced-online/ Training Course Schedule 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 24 Sign up and learn!
  • 25. MORE INFORMATION? Wrap-Up 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 25
  • 26. ISO/IEC 27001 Foundation More Information • Visit Us – https://interpromusa.com/iec-iso- 27001-certification-training/ • Email Us – Contact@InterPromUSA.com • Call Us – (+1) 480-699-9642 Glad to Help! 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 26 See you soon!
  • 27. About INTERPROM Elevating Business Performance through: • Coaching, Training, Workshop and Auditing Services • Specialty Areas: • Service Management • E.g. ISO/IEC 20000, FitSM, ITIL, VeriSM • Information Security Management • E.g. ISO/IEC 27001, NIST • Business Relationship Management • E.g. ISO 44001, BRMiBOK® • Organizational Change Management • E.g. CMBOK® • IT Governance • E.g. ISO/IEC 38500, COBIT® • Business Continuity Management • E.g. ISO 22301 • Risk Management • E.g. ISO 31000, MoR® ©InterProm USA – Confidential and Proprietary Information 274/23/2020
  • 28. IF YOU HAVE ANY QUESTIONS OR FEEDBACK, PLEASE DO NOT HESITATE TO CONTACT US: CONTACT@INTERPROMUSA.COM / +1 480-699-9642 4/23/2020 ©InterProm USA – Confidential and Proprietary Information 28

Editor's Notes

  1. ISO/IEC 27001 Foundation Certification Training Course