Information Security
ISO/IEC 27002 — Information Security Controls
Levels available
Course types, duration & fees
| Course type | Who should attend | What your company benefits | Duration | Fee |
|---|---|---|---|---|
| Foundation | Those who wish to learn the basis of implementing the management system and its processes | Provide the organization with best-practice based orientation and mindset culture by understanding the main important elements of ISO standards | 2 days | HKD 4,400 |
| Lead Manager | Managers in the relevant field who wish to master the guidelines specified by best practices | Lead your organization to follow the guidelines specified by ISO standards that can help you increase the skills of your staff and improve efficiency | 3 days | HKD 9,600 |
About the standard
ISO/IEC 27002 provides guidelines for selecting and implementing information security controls, applicable to organizations of any industry or size. Its 2022 revision reorganized the standard's catalog of controls into four categories — organizational, people, physical, and technological — giving organizations a generic, flexible set of practices they can tailor to their own information security needs and risk profile.
Levels available
- Foundation — Introduces the four control categories and core concepts of ISO/IEC 27002, giving learners a working understanding of the standard.
- Manager — Builds practical skills to select, implement, and manage information security controls within an organization.
- Lead Manager — For those responsible for leading the selection and management of information security controls, developing advanced skills to continually improve an organization's control environment.
Who should attend
This course track is for information security officers, IT managers, and ISMS implementation team members responsible for selecting and managing security controls. It's also useful for consultants and auditors who need a practical, standards-based reference for evaluating an organization's control environment.
Learning objectives
- Understand the implementation of information security controls and control policies based on ISO/IEC 27002
- Learn practical approaches and techniques for implementing and managing information security controls
- Gain the competence to support an organization in planning, implementing, and managing its controls
- Understand the role of risk management in determining appropriate controls
- Learn how to support the continual improvement of an information security management system
Why attend
Since different organizations face different information security needs, having practitioners who can select and tailor the right mix of controls is essential to an effective ISMS. This training builds the practical knowledge to manage information security risk day to day, positions professionals as valuable members of an ISMS implementation team, and boosts career opportunities in one of the fastest-growing, most in-demand fields.
PECB link
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27002
