Open training, B2
Risk analysis and ISMS documentation under ISO 27001
Two days of work on the participants own data: risk analysis methodology, selection of controls, and documentation that will stand up to an auditor.
Duration: 2 days
Programme
- 1.The structure of the standard, the context of the organisation, interested parties, ISMS scope
- 2.Risk analysis methodology: assets, threats, vulnerabilities, acceptance criteria
- 3.Carrying out the analysis on the participants own data
- 4.Risk treatment and the selection of controls from Annex A
- 5.The statement of applicability: justifying inclusions and exclusions
- 6.Mandatory documentation: what really has to exist
- 7.Internal audit and management review under PN-EN ISO 19011, the Polish edition of ISO 19011
- 8.Workshop: part of a risk register and part of a statement of applicability
Who it is for
ISMS managers, security coordinators, teams preparing for certification.
Outcome
Participants can carry out a risk analysis on their own and justify the selection of controls to an auditor.
Materials
Risk register template, statement of applicability template, a list of the mandatory documentation, certificate.
Format and group size
Live online or on site, group of 6 to 15 people.
Prerequisites
Basic knowledge of ISO 27001 or completion of module B1.
Date to be announced
We run this course in the open format, but no date has been announced yet. Leave your e-mail address and we will write once a date is set.
Training sessions are not recorded.
Prices are net amounts, to which VAT at 23% is added. Buyers financing the training at least 70% from public funds are asked to notify us before the invoice is issued.
