Hanligent Education
Back to courses

Information Security

ISO/IEC 27002 — Information Security Controls

Levels available

Course types, duration & fees

Course typeWho should attendWhat your company benefitsDurationFee
FoundationThose who wish to learn the basis of implementing the management system and its processesProvide the organization with best-practice based orientation and mindset culture by understanding the main important elements of ISO standards2 daysHKD 4,400
Lead ManagerManagers in the relevant field who wish to master the guidelines specified by best practicesLead your organization to follow the guidelines specified by ISO standards that can help you increase the skills of your staff and improve efficiency3 daysHKD 9,600

About the standard

ISO/IEC 27002 provides guidelines for selecting and implementing information security controls, applicable to organizations of any industry or size. Its 2022 revision reorganized the standard's catalog of controls into four categories — organizational, people, physical, and technological — giving organizations a generic, flexible set of practices they can tailor to their own information security needs and risk profile.

Levels available

  • Foundation — Introduces the four control categories and core concepts of ISO/IEC 27002, giving learners a working understanding of the standard.
  • Manager — Builds practical skills to select, implement, and manage information security controls within an organization.
  • Lead Manager — For those responsible for leading the selection and management of information security controls, developing advanced skills to continually improve an organization's control environment.

Who should attend

This course track is for information security officers, IT managers, and ISMS implementation team members responsible for selecting and managing security controls. It's also useful for consultants and auditors who need a practical, standards-based reference for evaluating an organization's control environment.

Learning objectives

  • Understand the implementation of information security controls and control policies based on ISO/IEC 27002
  • Learn practical approaches and techniques for implementing and managing information security controls
  • Gain the competence to support an organization in planning, implementing, and managing its controls
  • Understand the role of risk management in determining appropriate controls
  • Learn how to support the continual improvement of an information security management system

Why attend

Since different organizations face different information security needs, having practitioners who can select and tailor the right mix of controls is essential to an effective ISMS. This training builds the practical knowledge to manage information security risk day to day, positions professionals as valuable members of an ISMS implementation team, and boosts career opportunities in one of the fastest-growing, most in-demand fields.

PECB link

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27002

Official PECB page