ISO 27001 training is designed for organizations that want to establish, run or audit an information security management system.
ISO/IEC 27001 is the international information security management system standard published jointly by
ISO and the IEC. The version in force is the 2022 edition; the transition period from the 2013 version has been completed.
The standard covers not only information technology but information itself: physical records, human-related risks, supplier relationships and business continuity are also within scope.
Why a management system?
The approach that treats information security as a set of technical measures falls short in audits and in real incidents. A significant share of security breaches arises not from technical vulnerabilities but from process- and human-related weaknesses.
ISO 27001’s approach is this: determine which information assets you have, assess the risks to them, select controls appropriate to the risk, justify your selections and measure effectiveness.
This cycle is
risk-based thinking applied to information security.
The structure of the 2022 version