We use cookies to provide a better user experience and personalised service. By consenting to the use of cookies, we can develop an even better service and will be able to provide content that is interesting to you. You are in control of your cookie preferences, and you may change them at any time. Read more about our cookies.
These cookies are technically required for our core website to work properly, e.g. security functions or your cookie consent preferences.
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
In order to improve our website going forward, we anonymously collect data for statistical and analytical purposes. With these cookies we can, for instance, monitor the number or duration of visits of specific pages of our website helping us in optimizing user experience.
These cookies help us in measuring and optimizing our marketing efforts.
Building an ISO 27001 Information Security Management System and the Data Protection Extension
Learn the structure of the ISO 27001 standard, the stages of building your system, and tips for internal auditors
Managing and protecting information matters more than ever, now that so many different systems and devices are connected in a networked world.
Individuals may end up able to access information they don’t have the rights to. And when it comes to managing information security, traditional physical safeguards shouldn’t be overlooked either.
The structure of the ISO 27001 standard follows the same pattern as the most common ISO standards — the ones covering quality, environmental management, and occupational safety. If your organization already has an ISO standard in place, integrating an ISO 27001–based information security management system into your existing management system is straightforward.
The training walks through the structure of the ISO 27001 information-security standard and the stages of building an information security management system, and gives tips for internal auditors. It also looks at what the ISO 27701 data-protection extension adds to information security management. That standard provides guidance and requirements for protecting the processing of personal data and improving data protection within organizations.
“The training thoroughly covered the essentials of building an information security management system, and gave me real confidence in bringing our own work toward certification-readiness.”
What you’ll get from this course
You’ll get practical tips for building an information security management system.
You’ll understand the key requirements of ISO 27001, and what it adds to information security management.
You’ll get help interpreting how to apply the requirements and putting them into practice.
You’ll gain the skills to carry out internal audits of your information security system.
Who’s it for?
This training is aimed especially at specialists responsible for managing and developing their organization’s information security, and for building an ISO 27001 information security management system.
These roles might include, for example, an information security manager, IT director, data protection officer, internal auditor, risk manager, or compliance manager.
Learning methods
This is a one-day course that walks through the essential requirements of ISO 27001 and ISO 27701, unpacks what they mean, and works through examples applying them in practice. Participants receive a rich set of materials — models and templates that let you start applying what you’ve learned in your own organization.
Walking through the requirements, with tips for those building and auditing the system
The organization’s operating context
Leadership
Planning
Support functions
12:00Lunch break
13:00Course continues
Operations
Performance evaluation
Improvement
Reference list of control objectives and controls
Applying and making use of them
Integrating and auditing management-system standards
Phasing an information-security-system project
How to continue from here
Recap of the day and discussion
16:00End of course
Would you like an organization-specific quote?
All of our courses are also available on an organization-specific basis. The content can be tailored exactly to your development needs, and delivered for anything from a small group up to your whole staff.
Tiina Riutta works at Arter as head of sales, marketing and training. She is responsible for Arter’s sales and marketing, organizing trainings, and developing the training. Contact Tiina for any matters related to Arter’s trainings, whether you wish to participate in an open training session or arrange a customized organization-specific training.
Get in touch with Tiina directly, or request a quote!