Coordinator: Alessandro Cerasoli
Hours: 24
Prerequisites: Information Security & Risk Management module or equivalent, Business Continuity and Crisis Management module or equivalent
Programme:
- The framework of Management System standards: Harmonized Structure according to Annex SL and common requirements
- Overview of the guidelines in the ISO/IEC 270xx and ISO 223xx families
- ISO/IEC 27001 and ISO 22301 requirements: understanding aspects related to the governance framework of Management Systems
- The risk-based approach in ISO standards (with an overview of ISO 31000) and implementation methods for ISMS and BCMS
- Overview of ISO/IEC 27002 controls and audit organization
- Examples of applying controls in real-world situations
- Extension of ISO/IEC 27002 to the application of security controls in cloud environments – ISO/IEC 27017
- Third-party certification: objectives and benefits for organizations
- The third-party audit process: planning and execution
Key skills acquired:
- Knowledge of ISO standards relating to information security
- An approach to establishing an Information Security Management System and a Business Continuity Management System compliant with ISO standards
- Knowledge of security controls in traditional and cloud environments
- Basic knowledge for conducting third-party audit activities (certification)