|
Introduction to
the management
of an
Information
Security
Management
System (ISMS)
based on ISO
27001 and
launching an
ISMS |
Planning an ISMS
based on
ISO27001 |
Launching and
implementing an
ISMS based on
ISO27001 |
Control, act and
the
certification
audit of the
ISMS according
to ISO/IEC 27001 |
Exam: Duration –
3 Hours |
-
Introduction
to
management
systems and
the process
approach
-
Detailed
presentation
of the
standards
ISO/IEC
27001:2005,
ISO/IEC
27002:2005
and ISO/IEC
27003:2009
-
Fundamental
principles
of
Information
Security
-
Preliminary
analysis and
determining
the level of
maturity of
the existing
management
of the
Information
Security
based upon
ISO/IEC
21827:2008
-
Writing the
business
case and
preliminary
design of
the ISMS
-
Developing a
project plan
of
compliance
to ISO/IEC
27001:2005
|
-
Establishment
of the
Governance
Framework
-
Definition
of roles &
responsibilities
-
Drafting of
the ISMS
policy
-
Defining the
scope of the
ISMS
-
Risk
management
according to
ISO/IEC
27005:2008:
identification,
analysis and
treatment of
risk
-
Drafting the
Statement of
Applicability
|
-
Implementation
of a
document
management
framework
-
Design of
controls and
writing
procedures
-
Implementation
of controls
-
Development
of a
training &
awareness
program and
communication
around the
information
security
-
Incident
Management
according to
ISO/IEC TR
18044:2004
-
Operations
management
of an ISMS
|
-
Monitoring
controls and
the
management
of records
-
Development
of metrics,
performance
indicators
and the
dashboard in
accordance
with ISO/IEC
27004:2009
-
Internal
ISMS Audit
-
Management
review of
the ISMS
-
Implementation
of a
continuous
improvement
program
-
Preparing
for the ISO/IEC
27001:2005
audit
|
-
Open Book
Exam: Except
for the use
of a
computer,
all
documents
and
references
are allowed
during the
exam. The
exam is
comprised of
development
questions.
|