Skip to Content

ISO 27001 Lead Implementer

This intensive 5-day course will enable participants to develop the expertise necessary to manage structures related to information security management systems based on ISO 27001. The training will also allow participants to rigorously understand the best practices used to implement information security controls related to ISO 27002. This training is in accordance with the project management practices established in ISO 10006 (Quality Management Systems – Guidelines for Quality Management in Projects). This course is also aligned with ISO 27003 (Guidelines for the

Implementation of an ISMS), ISO 27004 (Measurement of Information Security) and ISO 27005 (Risk Management in Information Security)

0.000 DT 0.000 DT
  • Understand the implementation of an Information Security Management System compliant with ISO 27001
  • Acquire a comprehensive understanding of the concepts, approaches, standards, methods, and techniques necessary to effectively manage an Information Security Management System
  • Acquire the expertise necessary to assist an organization in the implementation, management, and maintenance of an ISMS, as specified in ISO 27001
  • Acquire the expertise necessary to manage an ISO 27001 implementation team
  • Request the qualification of Certified ISO/IEC 27001 Provisional Implementer, Certified ISO/IEC 27001 Implementer or Certified ISO/IEC 27001 Lead Implementer (after passing the exam), depending on the level of experience

• Code : ISO 27001 LI

• Duration : 5 days

• Schedule : 9:30 AM – 4:00 PM

• Location : Tunis

• Exam: Included*

• Project managers or consultants wanting to prepare and manage a structure in the implementation and management of information security systems

• Auditors who wish to understand information security systems and their operation

• CxOs and managers responsible for IT management in a company as well as risk management

• Members of an information security team

• Expert advisors in information technology

• Technical experts who want to prepare for a position in information security or for managing a project related to information security

• A basic knowledge of information systems security

• Course materials in French

• Course taught in French

• Copy of the ISO 27001 standard

Days 1, 2, 3 & 4

Introduction to the concept of Information Security Management System (ISMS) as defined by ISO 27001 – Initialization of an ISMS

  • Introduction to management systems and the process approach

  • Presentation of the ISO 27000 series of standards as well as the normative, legal, and regulatory framework

  • Fundamental principles of information security

  • Preliminary analysis and determination of the maturity level of an existing information security management system according to ISO 21827

  • Drafting a feasibility study and a project plan for the implementation of an ISMS

Planning the implementation of an ISMS based on ISO 27001

  • Definition of the scope (area of application) of the ISMS

  • Development of the policy and objectives of the ISMS

  • Selection of the approach and method for risk assessment

  • Risk management: identification, analysis, and treatment of risk (according to the provisions of ISO 27005)

  • Drafting the Statement of Applicability

Establishing an ISMS based on ISO 27001

  • Establishing a documentation management structure

  • Design and implementation of security measures

  • Development of a training and awareness program, and communication regarding information security

  • Incident management (according to the provisions of ISO 27035)

  • Management of ISMS operations

Control, monitor, measure, and improve an ISMS in accordance with ISO 27001

  • Control the security measures of the ISMS

  • Development of measures, performance indicators, and dashboards in accordance with ISO 27004

  • ISO 27001 internal audit

  • Review of the ISMS by management

  • Implementation of a continuous improvement program

  • Preparation for the ISO 27001 certification audit

Day 5

  • Taking the exam

*Taking the exam on the last day of the training