Information Security 27001 foundation course, 27001 foundation training, 27001 foundation certification, 27001 foundation exam, information security
Acquire the fundamental knowledge to establish and operate an Information Security Management System (ISMS) based on ISO/IEC 27001.
The Information Security 27001 Foundation course is a course based on ISO/IEC 27001. The course follows a real-world adapted case-study approach so students can be better prepared to apply the concepts of this ISO information security standard on a real-world scenario. This course prepares the students to support the establishment and operation of an ISMS based on ISO/IEC 27001 and provides them the fundamental knowledge on the audit concepts, principles and best practices based on ISO 19011.
Training material updated with the last released editions of all the related best practices. It also considers the new edition of ISO/IEC 27001:2022 and the new edition of ISO/IEC 27002:2022.
Next GUARANTEED DATES (*)
21-Jul-2023, Live Training Price | Register 08-Sep-2023, Live Training Price | Register 02-Nov-2023, Live Training Price | Register
course evaluation 4.2 in 5
ISO 27001 foundation course, ISO 27001 foundation training, ISO 27001 foundation certification, ISO 27001 foundation exam, information security
Introduction
This course is available to be delivered in a classroom and Live-Training model.
Live Training brings you the dynamic environment of the classroom, to your desk. Using your computer, you interact with the trainer and the trainees as if you were with them in the classroom.

On this course, the students will acquire the fundamental knowledge to establish and operate an Information Security Management System (ISMS) based on the ISO/IEC 27001 standard.
The course covers the fundamental concepts related with information security, an overview clause-by-clause of the ISO/IEC 27001 standard with high-level implementation guidance and discussion-based practical examples to implement the requirements of the standard, and best practices for the implementation of the ISO/IEC 27001 Annex A 114 controls, and/or others applicable according with the ISO/IEC 27002 control catalogue guidance.
As the students advance through the subjects of course, they will be presented with the main supporting standards of the ISO/IEC 27000 family, this includes, but not only, the guidance for information security controls implementation (ISO/IEC 27002), the guidance for implementation of the standard requirements (ISO/IEC 27003), the guidance for performance evaluation (ISO/IEC 27004), and the guidance for information security risk assessment (ISO/IEC 27005). These standards provide guidance to establish, implement, maintain, and continually improve an ISO/IEC 27001 Information Security Management System.
This course also provides an overview of other non-family and Information Security related best practices, legislation, and regulation and, on the last module, it covers an overview of the main concepts, principles, and best practices for auditing an ISMS based on the guidance of ISO 19011.
Training Methodology
This course is based on theorical, and practical sessions supported by a real-world adapted case-study.
The course includes hands-on practical and theorical exercises to:
- better prepare the students for the real-world challenges,
- to prepare and increase the likelihood of success on the certification exam,
- train and prepare professionals for participating in an ISMS implementation program or ISMS audit based on ISO/IEC 27001.
This course is available to be delivered in a Classroom and Live-Training model.
Live Training brings you the dynamic environment of the classroom, to your desk. Using your computer, you interact with the trainer and the trainees as if you were with them in the classroom.
Audience
This course is intended to:
- Information Security and/or IT Consultants, Auditors, Managers or Risk Professionals
- CISO, CIO, CSO or any Executive or Senior Manager responsible to ensure the alignment and delivery of value from Information Security to the organization
- Professionals responsible for the Information Security/IT Governance on the organization
- Any professional, either, IT, information security, business or any other, involved on the establishment, implementation, operations and/or continual improvement of an Information Security Management System (ISMS) based on ISO/IEC 27001
- Anyone who wants to learn the fundamentals of ISO/IEC 27001
Prerequisites
Students should understand English as the course documentation is in this language. Please consult BEHAVIOUR to verify the availability of the course on other languages.
Duration (days)
2 days
Learning Objectives
At the end of this course students will be able to:
- Understand the fundamental information security concepts, and the main requirements and controls of ISO/IEC 27001
- Get to know and understand the correlation of the ISO/IEC 27000 family standards, including ISO/IEC 27001, ISO/IEC 27002, and related ISO and other best practices, legislation and regulation
- Support an organization on the implementation and operation of an ISMS based on ISO/IEC 27001, as part of an ISMS implementation team and/or during an implementation project
- Understand the fundamental audit concepts and principles based on the ISO 19011 standard
- Understand the several information security related source of requirements to discuss with the peers about relevant subjects to the maintenance and improvement of information security on the organization
- Support the organization on the achievement and maintenance of the ISO/IEC 27001 certification
Program
- Introduction to Information Security, the ISO/IEC 27001 standard and, related best practices
- Course introduction
- Information security standards, legislation and regulation
- Advancing for ISO/IEC 27001 Certification
- Information security fundamentals
- Presentation and overview of the ISMS requirements (Part 1- Clauses 4 to 6.1)
- Information security context
- Leadership and commitment
- Planning (actions to address risks and opportunities)
- ISMS and Audit concepts and principles
- Presentation and overview of the ISMS requirements (Part 2 - Clauses 6.2 to 10; and Annex A)
- Planning (objectives and plans to achieve them)
- Support
- Operation
- Performance evaluation
- Improvement
- Annex A controls: overview and high-level implementation guidance
- Introduction to audit concepts and principles based on ISO 19011
- Certified Information Security 27001 Foundation (CIS27001FD) Exam
Exam
- The “Certified Information Security 27001 Foundation” exam covers the following competence domains:
- Domain 1: Information security fundamentals
- Domain 2: Information Security Management System ISO/IEC 27001 requirements
- Domain 3: Fundamental audit concepts and principles based on ISO 19011
Language(s): English and Portuguese (please consult BEHAVIOUR for availability on additional languages).
Duration: 1 hour.
Exam details: One part exam
Results: “Pass or Fail” quantitative score. In the case of a failure, the result will be accompanied with the list of domains in which you had a mark lower than the passing grade. If the candidate fails the exam, he is entitled to one free retake within a 1-year period from the initial exam date.
Passing score: 260/400 marks.
Exam type: Multiple-choice questions.
Certification
After successfully completing the certification exam, and signing the code of ethics, participants will achieve the credentials of Certified Information Security 27001 Foundation.
A certificate will be issued to participants who successfully pass the exam and comply with all the other requirements related to the selected credential. Candidates also receive the digital badge of the certification achieved.
The “Certified Information Security 27001 Foundation” personnel certification program is drafted and maintained according to the ISO/IEC 17024 standard.
(Note: This program does not provide the competencies for a specific function or role, thus, it does not have any personnel certification maintenance requirements).
Trainer
Our specialists are renowned consultants and auditors, with several years of experience in the areas of implementation, auditing and training in family ISO 27000, with particular focus on standards ISO27001, ISO27005 and their associated standards.
General Information
CLASSROOM TRAINING
- Training in English language.
- Training material in English.
- Behaviour Participation Certificate of 14 CPD/CPE credits.
- Certification Exam in Portuguese or English language.
- Certification Diploma and certification badge after successful examination and formal process registration. This process has no associated cost.
- If the candidate fails the exam, he is entitled to one free retake within a 12 month period from the initial exam date.
- Coffee break in the morning and afternoon (Applies to all training that take place in Behaviour facilities)
LIVE ONLINE TRAINING
- Training in English language.
- Online training material in English, with online access.
- Behaviour Digital Participation Certificate of 14 CPD/CPE credits.
- Online Certification Exam in Portuguese or English language. The exam can be taken up to 3 months after completing of the course.
- Certification Diploma and certification badge after successful examination and formal process registration. This process has no associated cost.
- If the candidate fails the exam, he is entitled to one free retake within a 12 month period from the initial exam date.
Benefits
- ISO/IEC 27001 is an auditable Information Security Management System (ISMS).
- ISO/IEC 27001 allows certification and international recognition of an organization; access to new markets and optimization of operations; and improves quality, increases productivity, competitive advantage, customer satisfaction and sales revenues.
- Information Security 27001 Lead Implementer course bases its pedagogical model in a certification program based on the ISO/IEC 17024 standard, which defines the requirements for certification of people, fulfilling the recommendations of ISO.
- Information Security 27001 Lead Implementer course geared towards to the implementation of the standard, through a step-by-step implementation process. Thus, throughout the course, in addition to the basic concepts of ISMS, are presented the steps needed to prepare and start the ISMS implementation program, which includes the selection of the approach, the implementation methodology, among other activities needed to implement the ISMS, based on the customized methodology presented, including ISMS operation and therefore the control, monitoring and continuous improvement.
- One of the strengths of the Information Security 27001 Lead Implementer course, in addition to inclusion of customized implementation methodology, is that it allows to prepare professionals for the audit of ISO/IEC 27001 certification and the registration in a certifying body. Addresses itself to this end, the recommendations of ISO 19011 and the ISO/IEC 17021 – requirements for certification bodies.
- Certification exam is monitored by an official Behaviour administrator.
- The Certified Information Security 27001 Lead Implementer certification exam is conducted at the end of the course, on the last day of training, which focuses on development questions and case studies allowing the certifying entity to measure, more effectively, the knowledge of the candidates.
- Upon success in the exam, the professional will achieve one of the Information Security 27001 certifications levels. In case of failure, professional may repeat the exam at no additional cost, within 1 year after the date of the 1st examination.
- Behaviour Pedagogical Model aims to provide a learning environment conducive to acquisition of competences, in accordance with objectives of each training program. Promoting interaction, participation and appreciation of experiences, we contribute to meaningful learning, certification and international recognition but, above all to the development of critical thinking and autonomy.
- Behaviour is an organization accredited by DGERT (Portuguese Government Entity) and has its Quality Management System (QMS) implemented in accordance with the requirements of ISO 9001, the requirements of DGERT, the requirements of the European standard NP 4512 and the standard ISO 10015.
Dates and Price
Guaranteed Dates Program
(*) All dates of this course are guaranteed only for the events that take place in Lisbon. In other locations the events are subject to a minimum number of participants.
On Behaviour all courses at Lisbon occur regardless of the number of trainees in room. The concept of setting up classes does not exist in our educational model, which is why all public dates, presented on the website, are guaranteed. So if you're in Portugal or anywhere else in the world, you can prepare your week and your trip, as long as you ensure your registration in the course.
Volume Discounts
For companies, Behaviour offer discounts, starting from the registration of the 2nd participant, in the same course and on the same date.
Simulate the prices for the number of participants you want to register to
training@behaviour-group.com or contact us via chat.
Hotels and Useful Information
Know where you can stay in Lisbon, near Behaviour.
For more information please see >> Booking <<