Cookie Preferences

We use cookies to provide a better user experience and personalised service. By consenting to the use of cookies, we can develop an even better service and will be able to provide content that is interesting to you. You are in control of your cookie preferences, and you may change them at any time. Read more about our cookies.

Skip to content

Building an ISO 27001 Information Security Management System and the Data Protection Extension

Learn the structure of the ISO 27001 standard, the stages of building your system, and tips for internal auditors

Managing and protecting information matters more than ever, now that so many different systems and devices are connected in a networked world.

Individuals may end up able to access information they don’t have the rights to. And when it comes to managing information security, traditional physical safeguards shouldn’t be overlooked either.

The structure of the ISO 27001 standard follows the same pattern as the most common ISO standards — the ones covering quality, environmental management, and occupational safety. If your organization already has an ISO standard in place, integrating an ISO 27001–based information security management system into your existing management system is straightforward.

The training walks through the structure of the ISO 27001 information-security standard and the stages of building an information security management system, and gives tips for internal auditors. It also looks at what the ISO 27701 data-protection extension adds to information security management. That standard provides guidance and requirements for protecting the processing of personal data and improving data protection within organizations.

“The training thoroughly covered the essentials of building an information security management system, and gave me real confidence in bringing our own work toward certification-readiness.”

What you’ll get from this course

  • You’ll get practical tips for building an information security management system.
  • You’ll understand the key requirements of ISO 27001, and what it adds to information security management.
  • You’ll get help interpreting how to apply the requirements and putting them into practice.
  • You’ll gain the skills to carry out internal audits of your information security system.

Who’s it for?

  • This training is aimed especially at specialists responsible for managing and developing their organization’s information security, and for building an ISO 27001 information security management system.
  • These roles might include, for example, an information security manager, IT director, data protection officer, internal auditor, risk manager, or compliance manager.

Learning methods

  • This is a one-day course that walks through the essential requirements of ISO 27001 and ISO 27701, unpacks what they mean, and works through examples applying them in practice. Participants receive a rich set of materials — models and templates that let you start applying what you’ve learned in your own organization.

Explore the course content below

Sample schedule and content

09:00 Opening of the course
  • Introductions
  • Program and objectives for the day
Walking through the requirements, with tips for those building and auditing the system
  • The organization’s operating context
  • Leadership
  • Planning
  • Support functions
12:00 Lunch break

13:00 Course continues
  • Operations
  • Performance evaluation
  • Improvement
Reference list of control objectives and controls
  • Applying and making use of them
  • Integrating and auditing management-system standards
  • Phasing an information-security-system project
How to continue from here
  • Recap of the day and discussion
16:00 End of course


Would you like an organization-specific quote?

All of our courses are also available on an organization-specific basis. The content can be tailored exactly to your development needs, and delivered for anything from a small group up to your whole staff.

Get in touch with Tiina directly, or request a quote!

This field is for validation purposes and should be left unchanged.
Suoramarkkinointiviestit