Training

ISMS to ISO 27001 – implementation explained in practice

From the standard to a working management system: scope, risks, evidence, certification.

Reading the standard is one thing, making it work in your own company is another. This course guides you through building a complete ISMS – with examples from real certification projects, typical audit findings and the points where projects tend to get stuck.

Request this course

At a glance

Level
Advanced
Duration
2 days
Audience
Information security officers, project leads, IT management, quality management
Format
In-house – on site or remote
Language
German or English

Structure

This is how the course is built up. I agree the order and focus with you in advance, based on your audience and prior knowledge.

  1. Day 1 – standard & scope

    Structure of the standard and Annex A, context of the organisation and a sensible cut of the scope.

  2. Day 1 – risk management

    Methodology, assessment and risk treatment plus a statement of applicability without walls of text.

  3. Day 2 – documentation & operations

    What is really required, internal audits, management review and continual improvement anchored in daily work.

  4. Day 2 – certification

    Stage 1 and stage 2, surveillance audits, plus typical nonconformities and how to avoid them in advance.

Course content

  • Structure of the standard and its interplay with Annex A
  • Cutting the scope sensibly – the single biggest lever in the whole project
  • Context of the organisation and interested parties
  • Risk management: methodology, assessment, risk treatment
  • A statement of applicability without walls of text
  • Documentation: what is really required and what is not
  • Internal audits and management review
  • Anchoring continual improvement in everyday work
  • The certification process: stage 1, stage 2, surveillance audits
  • Typical nonconformities and how to avoid them in advance

What you take away

  • A realistic roadmap to certification with a feel for the effort involved
  • Confidence in handling scope, SoA and risk methodology
  • Less documentation, but more robust evidence

More training courses

Advanced · 1 day including a tabletop exercise

Incident response basics

What happens in the first hours of a security incident – and who makes which decision.

Workshop · 1-day workshop

Creative awareness measures

A workshop for everyone responsible for awareness – and tired of mandatory e-learning.

Interested in “ISMS to ISO 27001 – implementation explained in practice”?

Tell me briefly about group size, prior knowledge and your preferred date – I will come back with a proposal including effort.