Cybersecurity
Information Security - Information Security - Security Officer (IS)
by New Horizons Dortmund Computer Learning Center GmbH & Co.KG
- Provider
- New Horizons Dortmund Computer Learning Center GmbH & Co.KG
- Category
- Cybersecurity
- Duration
- 3–6 Monate
- Schedule
- Vollzeit, Teilzeit
- Locations
- Dortmund
- Next start
- 2026-08-16T22:00:00+00:00
Course overview
ISO 27001 Information Security Officer (CISO) Focus: Providing in-depth knowledge for an information security management system based on ISO 27001. Participants will be able to establish and effectively implement an ISMS based on the ISO 27001 standard. Topics: - Related standards and frameworks - Harmonized Structure - Normative part of the standard - The 93 controls of the annex and the amendment - Explanation of requirements - Implementation options for key requirements - Certification options according to ISO/IEC 27001 and audit process Additional content: - Introduction, context & fundamentals, overview of ISO 27001 and 27002, terms, scope, interested parties, context analysis, overview of risks, building an ISMS / PDCA cycle, risk management according to ISO 27001 / 27005, methodology, risk identification, assessment & treatment options, planning and documenting risk treatment, control & documentation, information security policy, roles and responsibilities, documented information (procedures, etc.), communication plan & awareness, ISO 27002 controls & implementation, overview of the 93 controls, technical selection and adaptation, example controls and implementation plans, internal audit, management review, certification, audit planning and execution, non-conformities & corrective actions, management review, certification preparation - Define scope & applicability, formulate scope statement for the ISMS, identify boundaries & interfaces - Context analysis - internal factors - compile internal topics (processes, assets, organization), define external factors, external topics (legal, regulatory, market environment) - Interested parties and requirements, create stakeholder list, derive security requirements - ISMS guideline / security policy draft, write the first version of the information security guideline - Define roles and responsibilities, develop roles matrix / RACI table, clearly name responsibilities - Prepare risk identification, start protection needs analysis / asset list, collect risks - Conduct risk assessment, evaluate risks according to defined method (e.g., likelihood/impact) - Plan risk treatment, select treatment options, create risk treatment plan - Select controls (ISO 27002) - choose controls from Annex A (or 27002) that cover the risks - Create Statement of Applicability (SoA) - fill out SoA matrix, document justifications for selection/non-selection - Develop documented information, fill out or adapt procedures/templates - Design awareness and communication plan, create plan for internal training and communication - Prepare audit planning, create audit checklist and plan, formulate example questions - Management review & self-assessment, prepare review agenda, conduct self-assessment of ISMS status
Upcoming dates
- 2026-08-16T22:00:00.000Z · 2026-09-10T22:00:00.000Z · Dortmund · Combined Learning
- 2026-08-16T22:00:00.000Z · 2026-10-08T22:00:00.000Z · Dortmund · Combined Learning
- 2026-09-13T22:00:00.000Z · 2026-11-05T23:00:00.000Z · Dortmund · Combined Learning
- 2026-09-13T22:00:00.000Z · 2026-10-08T22:00:00.000Z · Dortmund · Combined Learning
Funding
Bildungsgutschein funding depends on the course details and the decision of the responsible authority.
Data last synced: 2026-07-28