Training - ISO/IEC 27001 Information Security Standard

ISO/IEC 27001 Information Security Standard Training

The ISO/IEC 27001 training course provides a clear overview of a risk-based information security management system and its key requirements. During the training, you will learn to interpret the ISO/IEC 27000 series of standards—and, in particular, the ISO/IEC 27001 requirements standard—using practical examples. Our trainers are leading experts in the field who have a thorough understanding of the standards and their application. The price for the two-day training course is €1,300 + VAT.

What are the benefits of ISO/IEC 27001 training?

This training will provide you with practical skills and a deeper understanding of how to build, develop, and maintain an information security management system (ISMS). You’ll learn how to apply the ISO/IEC 27001 standard in practice and apply what you’ve learned directly to your organization’s information security operations.
An Overview of the Standard

You will understand the ISO/IEC 27001 requirements and the structure of the management system.

Practical Skills

You will be able to design, implement, and maintain an ISMS in accordance with business needs.

Readiness for Certification

You will help the organization prepare for audits and the certification process.

Better Risk Management

You will learn to systematically identify, assess, and manage information security risks.

Building Trust

Operating in accordance with the standard builds trust among customers, partners, and stakeholders.

Career Development Support

You'll gain valuable expertise that will strengthen your professional skills and career opportunities.

Trainer – ISO/IEC 27001 Information Security Standard

DEKRA’s trainers have exceptionally extensive experience in audits and the application of standards across dozens of different industries, which brings in-depth expertise and a practical approach to the training programs.
“As a trainer, I combine the theory outlined in the standards with practical experience and real-life examples. I, too, learn something new from every training session.”
Jyrki Lahnalahti
Lead Auditor, Management Consultant, Trainer in Information Security, Business Continuity Management, and IT Services

Learn more about our trainers' expertise and experience

Jyrki Lahnalahti

Management consultant, lead auditor, and trainer in information security and IT services.

Working with clients is important to me, and it’s what drives me in my roles as a management system consultant, lead auditor, and trainer. I have long been involved in standardization work in the areas of service management and information security.
My previous experience—including as an entrepreneur and in a variety of roles—forms the basis for my training offerings. My training topics include management system standards for information security (ISO/IEC 27001), service management (ISO/IEC 20000-1), business continuity management (ISO 22301), and quality management (ISO 9001). In addition to these, my other areas of expertise and training include corporate security management systems, risk management, and internal auditing. Among the training programs and certifications I have completed, I must mention the Security Management Training Program (TJK 13), which broadened my perspective on the big picture of corporate security and its various subfields.
As a trainer, it’s important to me that, in addition to providing theoretical or conceptual background, I can also share my own personal experiences with the participants. My style involves close interaction with participants through discussions, challenging assumptions, and sharing real-life, authentic examples. I can’t recall a training session I’ve led from which I didn’t also learn or gain something myself.
I have been working as an auditor for 20 years. Before that, I spent many years in various roles in the ICT sector, including as a programmer, project manager, and consultant. I have been conducting training sessions for over 15 years.
In my free time, I enjoy spending time outdoors, working on my old farmhouse, and tinkering with computers.

Who is ISO/IEC 27001 training suitable for?

This training is ideal for individuals involved in the design, implementation, maintenance, or assessment of an information security management system (ISMS).

This training is particularly suitable for those in the following roles:

  • For information security managers, those in CISO roles, and others in leadership positions who are responsible for strategic decisions regarding an organization's information security.
  • IT executives and specialists, system architects, and those responsible for technical information security who want more information, particularly on technical control measures and their role in information security management.
  • For those responsible for risk management, internal auditing, compliance, or quality management, for whom interpreting and applying the requirements of standards is essential to their work.
  • For managers and supervisors of the company’s business units who want to understand how ISO/IEC 27001 affects their unit and how collaboration can ensure compliance.

ISO/IEC 27001 Training Content

  • Information Security and Management Systems
  • Building an Information Security Management System
  • Risk Management
  • Certification and Assessments of Information Security Management Systems
The trainer did an excellent job of making a challenging and rather dry topic into an engaging and interesting session that kept us engaged even during the final hours of the afternoon
ISO 27001 training participant

Standards Used in Training

For the training, you will need the SFS-EN ISO/IEC 27001:2023 standard (or ISO/IEC 27001:2022). It would also be a good idea to have the SFS-EN ISO/IEC 27002:2022 standard (or ISO/IEC 27002:2022) on hand. For more information and to place an order, contact SFS Finnish Standards, tel. (09) 149 9331/sales or visit the SFS online store. The standards are not included in the training fee.

Objectives of ISO/IEC 27001 Training

After this two-day training course, you will understand what the requirements of the ISO/IEC 27001:2022 standard for an information security management system entail. We will cover all the requirements of the standard and the control measures in Annex A through numerous practical examples.
What is included in the price?
The course fee includes instruction, course materials, lunch, and morning and afternoon coffee breaks. The course includes interactive, lecture-style introductions to the topic, discussions, and group work.

Program and Schedule - ISO/IEC 27001 Information Security Standard Training

Program

The training is spread over two separate days. The training days begin at 8:30 a.m. and end at 4:00 p.m. Lunch and coffee are included for each day of the training.

Day 1

8:30 a.m. Registration and morning coffee
9:00 a.m. Opening
9:00 a.m. Information Security and Management Systems
  • Integration with other management systems, such as a quality management system
  • The ISO/IEC 27000 series of standards and other standards
  • Building a Management System
  • Risk Assessment and Management
  • Requirements for an Information Security Management System
11:30 a.m. Lunch
12:30 p.m. Practice
1:00 p.m. Requirements for an Information Security Management System (continued)
4:00 p.m. Information Security Management System Certification and Assessments
4:30 p.m. The day ends

Day 2

8:15 a.m. Morning coffee
8:30 a.m. Information Security Management Practices According to the ISO/IEC 27002 Standard
11:30 a.m. Lunch
12:30 p.m. Practice
1:00 p.m. Information Security Management Measures (continued)
3:00 p.m. Review of training topics through discussion
4:00 p.m. Training ends
Why Choose DEKRA?
DEKRA is a leading international expert organization with extensive experience in ISO standards training and audits. Our trainers have in-depth knowledge of management system standards such as ISO 9001, ISO 14001, ISO 45001, ISO 50001, and ISO/IEC 27001, and provide up-to-date information on topics such as best practices for internal audits.
We offer flexible training options: open enrollment courses, online courses, and customized training tailored to your company's needs.

Register for the training

Ask an ISO/IEC 27001 Information Security Standard trainer

Would you like more information about the training? We'd be happy to help! Fill out the form below to get in touch with an ISO/IEC 27001 Information Security Standard trainer.
Share page :