S107
·
Weiterbildung

ISMS Based on ISO 27001: Setup and Evidence

An information security management system based on ISO 27001 has to work in everyday operations and be verifiable in an audit. You learn to structure the scope, risk assessment, controls, and certification according to ISO.

Security officer shows the auditor an opened network cabinet during an internal audit as an admin holds the key
Duration

55 min

Format

Multimodal

Languages

Über 30 Sprachen

Proof

Teilnahmebescheinigung

Challenge

ISO/IEC 27001:2022 is the internationally recognized standard for information security and is increasingly expected as proof by customers, insurers, and regulation (NIS-2, DORA, TISAX). Many companies fail not because of technology but because of the system: an unclear scope, a missing risk methodology, policies that are not lived, and incomplete evidence. An ISMS must therefore be set up from the start so that it works in everyday operations and is verifiable in an audit.

Learning objectives
  • You know the structure and requirements of ISO/IEC 27001:2022 and its interplay with ISO 27002.
  • You define the scope, context, and information security objectives and secure the support of top management.
  • You carry out risk assessment and risk treatment and prepare the Statement of Applicability (SoA).
  • You have an overview of the 93 controls in Annex A and select them on a risk basis.
  • You plan internal audits, management review, and the process of certification according to ISO with stage 1 and stage 2 audits.
Agenda
00 Fundamentals and structure of ISO 27001
01 Scope, context, and leadership
02 Risk assessment, risk treatment, and SoA
03 Controls under Annex A
04 Operation, audit, and certification according to ISO
05 Summary
06 Knowledge check incl. certificate of completion
Target group

Information security officers, IT management, compliance managers, and project leads who want to introduce an ISMS or seek certification according to ISO.

Leading organizations trust Bridgly

Logo von Ols
Logo von Ols
Logo von Ols
All training courses on one platform:

Bridgly learning platform

Our platform bundles all training management functions, from planning to reporting, in one place.

Training organization

Define who is trained on which content and when.

Training documentation

See at any time who completed which content and when.

Manage participants

CSV import, learning groups, and access rights in one place.

Automated
reminders

Deadlines and recurring training run automatically.

FAQ

Frequently Asked Questions

Here you will find the most important answers.

Is data protection training for employees mandatory under the GDPR?
Which cyber threats should companies train their employees on?
What are the consequences of missing data protection training in the event of a data breach?
What training obligations arise from NIS-2 and the BSI Act (BSIG)?
How often must data protection and IT security training be repeated?
How does GDPR training for employees differ from the qualification as a data protection officer?
Contact

Train your employees in a legally compliant and verifiable way

Training and professional development for companies and public-sector clients – with audit-proof documentation and a practical focus.

Get in touch now
Eine Hand blättert in einem grauen Ringordner mit Tabellen, dahinter ein aufgeklappter Laptop

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.