Open training, B2

Risk analysis and ISMS documentation under ISO 27001

Two days of work on the participants own data: risk analysis methodology, selection of controls, and documentation that will stand up to an auditor.

Duration: 2 days

Programme

  1. 1.The structure of the standard, the context of the organisation, interested parties, ISMS scope
  2. 2.Risk analysis methodology: assets, threats, vulnerabilities, acceptance criteria
  3. 3.Carrying out the analysis on the participants own data
  4. 4.Risk treatment and the selection of controls from Annex A
  5. 5.The statement of applicability: justifying inclusions and exclusions
  6. 6.Mandatory documentation: what really has to exist
  7. 7.Internal audit and management review under PN-EN ISO 19011, the Polish edition of ISO 19011
  8. 8.Workshop: part of a risk register and part of a statement of applicability

Who it is for

ISMS managers, security coordinators, teams preparing for certification.

Outcome

Participants can carry out a risk analysis on their own and justify the selection of controls to an auditor.

Materials

Risk register template, statement of applicability template, a list of the mandatory documentation, certificate.

Format and group size

Live online or on site, group of 6 to 15 people.

Prerequisites

Basic knowledge of ISO 27001 or completion of module B1.

Date to be announced

We run this course in the open format, but no date has been announced yet. Leave your e-mail address and we will write once a date is set.

Training sessions are not recorded.

Prices are net amounts, to which VAT at 23% is added. Buyers financing the training at least 70% from public funds are asked to notify us before the invoice is issued.

Back to the schedule