Developing and implementing an information security management system in accordance with the requirements of the international standard ISO 27001:2022

Duration 2 days

The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation

Seminar dates

Schedule: 10:00 to 17:30
Cost 296 500 tenge

excluding VAT

* VAT of 16% will be added to the invoice

The price includes:

  • Seminar
  • Exclusive handout materials
  • IBA certificates
  • Notepads, pens
  • Lunches and 2 coffee breaks
Register

Programme goal:

Training managers, IT specialists and security staff in the principles and methods of building a NON-FORMAL, risk-based information security management system (ISMS) in accordance with the international standard ISO 27001:2022, one that will genuinely help to protect information and reduce cyber threats by covering the following areas in the training:

— Reducing information security risks — protection against cyber-attacks, data leaks and information security incidents
— Increasing the resilience of IT systems — minimising failures and downtime by introducing risk-based processes
— Optimising information security processes — integrating risk management into IT and business processes, cutting inefficient costs
— Increasing the effectiveness of internal monitoring — moving from formal checks to a risk-based internal audit of the ISMS
— Compliance with the requirements of legislation and certification bodies — fewer nonconformities in inspections and audits
— Improving the quality of management decisions — introducing decision-making methods based on quantitative assessment of cyber risks
— Supporting digital transformation and ESG goals — ensuring the trust of customers and partners in the company's digital services

Objectives:

— Examine the requirements of the ISO 27001:2022 standard
— Master methods of identifying, analysing and managing information security risks based on ISO 31010
— Learn to apply algorithmic analysis tools (SWOT, PEST, «Porter's 5 Forces») to define the organisation's context in the field of information security
— Develop a risk-based model of business processes for the information security part
— Study methods of quantitative assessment of cyber risks (Monte Carlo simulation, the scoring model, the Tornado diagram)
— Build a system of KPIs (by process) and KRIs (key risk indicators) for managing information security
— Master approaches to planning and conducting risk-based internal audits of the ISMS (ISO 19011)
— Consolidate knowledge in practical cases, group work (for example, modelling data leak risks) and interactive games

Skills developed:

— Strategic thinking in information security — the ability to link the company's strategy to information security objectives
— The process approach — describing and optimising information security processes in accordance with ISO 27001
— Information security risk management — methods of identifying, analysing, evaluating and treating cyber threats
— Making decisions based on quantitative assessment of cyber risks — improving the quality of planning and the resilience of the business
— Auditing skills — conducting internal audits of the ISMS in accordance with ISO 19011
— Evaluating ISMS performance — monitoring KPIs and KRIs, analysing incidents and corrective actions
— Working with interested parties — taking into account the requirements of regulators, customers and partners when building the information security system

Using artificial intelligence tools — mastering the skills of applying AI for analysing, planning and documenting processes; participants are given a ready-made prompt that they can use independently in their further work

Key Account Manager

Natalya Batukhtina
ns@iba.kz +7 702 777 44 11 WhatsApp

Key Account Manager

Юлия Копцева
manager@iba.kz +7 702 777 44 11 WhatsApp
Seminar programme Download programme as PDF
Get a personalised commercial proposal in PDF format
Download proposal as PDF

Programme

Introduction

Getting acquainted / introduction / course overview / participants introduce themselves.

The history of standardisation. Introduction to ISO.

The seven management principles.

The company's context

Understanding the organisation and its context in relation to risks and the company's structure.

The «5C» method, Michael Porter's «5 Forces», SWOT analysis, PEST analysis.

Interested parties, their requirements and expectations

Understanding interested parties. The link between interested parties and context.

Compliance obligations and their link to the company's context.

Assessing the degree of fulfilment of compliance obligations.

Examples of methods for assessing fulfilment of compliance obligations.

Scope of the information security management system (ISMS)

The scope of the ISMS and its link to context.

Business processes

The process approach.

The link between context and processes.

The procedure for identifying processes — best practices.

Options for describing processes.

Process criteria (KPI)

Types of criteria: input KPI and output KPI.

The link between criteria and the company's strategy.

Introduction to risk management

Common myths in the field of risk management and debunking them.

System 1, System 2 and the concept of «mental traps».

Risk identification

Mental traps at the risk identification stage.

Risk identification methods (from ISO 31010:2019):

— Goal decomposition and the MECE method (Mutually Exclusive & Collectively Exhaustive)

— «Brainstorming»

— A database of materialised risks

— The «RIR — Risk Identification Report» method

— Control «checklists»

— Business impact analysis (the «process approach»).

Risk analysis

Mental traps at the risk analysis stage.

Risk analysis methods (from ISO 31010:2019):

— The «5 Whys» method

— The «bow-tie» method

— The «decision trees» method

— The «Monte Carlo» simulation method, etc.

Examples of risk analysis and completing the Risk Register.

Determining the level of risk

Mental traps at the risk evaluation stage.

Different options for evaluating risk (qualitative, quantitative and their combination, from ISO 31010:2019).

Assessing and analysing the influence of risks on the decision being made

Ways of visualising the results of evaluation: Risk maps, Decision trees, the Scoring model.

Risk treatment

Mental traps at the risk treatment stage.

Six ways of treating risk.

Choosing the risk treatment method.

Examples of risk treatment.

Risk monitoring and review

Key risk indicators (KRI). The relationship between KRI and KPI.

Leadership

Risk-based decision-making.

Methods of improving the quality of corporate decisions from the «Decision Quality» methodology.

The relationship between strategy, context and the ISMS Policy.

Recommendations on developing the ISMS Policy.

Responsibility and authority

Methods of describing actions by process (in the form of regulations / control procedures).

Designing business processes and controls.

Basic requirements / recommendations for developing control procedures, and common mistakes.

ISMS objectives

The standards' requirements for objective setting.

The relationship between strategy, context, the Policy and the ISMS Objectives.

Best practices in risk-based objective setting.

Resources

Determining the competence of personnel needed for the processes to function.

Determining the infrastructure needed for the processes to function.

The in-house knowledge base.

Effective communication. Documented information.

Operations

Assessing information security risks

Treating information security risks

Performance evaluation

Internal audit of the ISMS.

The procedure for planning, conducting and analysing the results of a risk-based internal audit of the ISMS.

ISMS review. Best practices.

Improvement

Corrective actions. Examples and best practices.

Continual improvement.

Group game «interactive review of requirements and situations from ISO 27001»

All areas