ISO/IEC 27001 Foundation - virtual



Kursarrangør: Glasspaper AS
Sted: Nettkurs / Nettstudie
Hele landet
Type:Nettkurs og nettstudie
Studie / yrkesutdanning (13 studiepoeng)
Undervisningstid: kl 09:00 - 16:00
Varighet: 2 days
Pris: 14.500
Neste kurs: 29.10.2026 | Vis alle kursdatoer

We provide virtual course about ISO/IEC 27001 Foundation. ISO/IEC 27001 Foundation is an introductory course designed to give participants a solid understanding of the internationally recognised information security standard ISO/IEC 27001.

Course description:
This course focuses on the key principles, terminology and requirements of the standard, helping delegates to understand how an Information Security Management System (ISMS) should be structured to support risk-based security governance. This course provides a clear overview of the structure and requirements of ISO/IEC 27001, and explains how these elements support the establishment, implementation and continual improvement of an ISMS.

Participants will explore core concepts such as confidentiality, integrity and availability, risk assessment fundamentals, and how the standard’s clauses relate to business processes. The course is suitable for those who need to understand ISO/IEC 27001 for compliance, professional development or preparation for more advanced certification levels.

Course objectives:
Upon completion of this course, participants will be able to:
• Understand the key concepts and terminology in ISO/IEC 27001
• Explain the structure, clauses and requirements of the standard
• Understand how an ISMS supports organisational information security goals
• Recognise the purpose of risk assessment and treatment in ISO/IEC 27001
• Prepare for the ISO/IEC 27001 Foundation certification exam

Course outline:
Module 1 - Introduction to Information Security and ISO/IEC 27001:
• The course begins with an overview of information security fundamentals and key drivers for establishing an Information Security Management System (ISMS). Participants explore the basic principles of confidentiality, integrity and availability, and learn why structured governance and risk-based approaches are critical to protecting organisational information assets.

Module 2 - Structure and Requirements of ISO/IEC 27001:
• This section breaks down the structure of the ISO/IEC 27001 standard. Participants are introduced to the clauses of the standard and how each contributes to a structured ISMS. Emphasis is placed on understanding requirements rather than memorising text, enabling participants to interpret and apply the standard in practical settings.

Module 3 - Risk Assessment and Treatment in ISO/IEC 27001:
• Participants learn the fundamentals of risk assessment and risk treatment as required by ISO/IEC 27001. This includes how risk identification, analysis and evaluation activities contribute to the design of an effective set of controls. Delegates gain insight into how risk drives decision-making in the context of information security.

Module 4 - Information Security Controls and Documentation:
• This part of the course covers control objectives and the use of documented information to support implementation, measurement and continual improvement. Participants discuss the role of policies, procedures and records in building a robust ISMS that can withstand audit and certification processes.

Module 5 - Preparation for the Foundation Exam:
• The course concludes with a review of key topics and structured preparation for the ISO/IEC 27001 Foundation exam. Participants will gain insight into what to expect in the exam and how best to apply their learning in order to succeed.

Target audience:
This course is aimed at anyone who wants to understand the fundamentals of information security, governance and an ISO/IEC 27001 Information Security Management System. Typical participants include IT staff, security professionals, compliance officers, consultants and managers involved in information risk and security activities.

Prerequisites:
• There are no formal prerequisites to attend this course. A general interest in information security or governance is helpful, but not required.

Language:
• English course material, norwegian or english speaking instructor

Certification:
For Virtual courses we will send out a voucher that gives you access to an online exam. This can be booked and taken home monitored by a proctor via camera. More information about the exam rules will be send from PECB.