ISO 27001 is a management system and sets the framework standards describing the administrative or technical basic rules for establishing an Information Security Management System (ISMS) in an institution or organization. ISO 27002 is used as an implementation guide for technical details. Some upper rule determining institutions, affiliated institutions and organizations also have made the implementation of this standard mandatory.
The aim of the training is to contribute to the creation of an effective information security management system by interpreting the basic concepts of information security and the ten basic principles of risk analysis and information security management system standards. The training covers topics such as information security policy, information security objectives, information security handbook, procedures, applicability declaration, risk table, programs, and processes in the information security management systems documentation. The training also covers effective planning, implementation, and control of the information security policy, objectives, handbook, procedures, applicability declaration, risk table, programs, and processes. The ultimate goal of the training is to ensure the preparation of the necessary documents for the organization's information security management system.
Who Should Participate?
IT governance, risk management and audit, SOME personnel, Process and Standardization experts, all IT personnel, all technical experts who are interested in ISO 27001 and want to improve themselves.
Program
• Information and Information Security Concepts, Terms
• Risk Analysis
• Interpretation of the Articles of TS ISO / IEC 27001 Standard
• Safety Controls and Precautions
• Documentation
• Information Security Handbook
• Procedures
• Statement of Applicability
• Risk Table (Risk Assessment, Risk Analysis, Risk Management, Application-WorkShop)
• Support Documents (Procedures, Policies, Forms )
• Certification Process
• ISO 27001 Annex A Controls