資訊安全
ISO/IEC 27001 — Information Security Management System
課程類型、時長及學費
| 課程類型 | 適合對象 | 企業得益 | 時長 | 學費 |
|---|---|---|---|---|
| Foundation | 希望學習管理系統及其流程實施基礎的人士 | 透過理解 ISO 標準的核心要素,為機構建立以最佳實務為本的取向與文化 | 2 天 | HKD 4,400 |
| Lead Implementer | 負責在公司實施及管理管理系統的人員 | 由具備能力的人員帶領推行最佳實務,改善整體流程,邁向符合 ISO 標準 | 5 天 | HKD 11,200 |
| Lead Auditor | 負責在公司審核及監察管理系統的人員 | 由具備能力的人員審核流程,確保管理系統妥善實施,邁向成功合規與認證 | 5 天 | HKD 11,200 |
About the standard
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), setting out how to preserve the confidentiality, integrity, and availability of information through a risk management process. Organizations that implement an ISMS compliant with ISO/IEC 27001 can systematically assess and treat the information security risks they face. The 2022 revision restructured Annex A's controls into four themes — organizational, people, physical, and technological — reducing the count from 114 to 93 controls and broadening the standard's scope to explicitly cover cybersecurity and privacy protection alongside information security.
Levels available
- Foundation — Introduces the core concepts of an ISMS and ISO/IEC 27001's requirements, giving learners a solid grounding in information security management.
- Lead Implementer — For those responsible for implementing and managing an ISMS, covering the skills to build information security policies and procedures tailored to an organization's needs.
- Lead Auditor — For those responsible for auditing an ISMS, developing the competence to assess conformity and support certification.
- Transition — For professionals already certified against a prior edition of the standard who need to update their credential to the current 2022 version.
Who should attend
This track suits information security managers, IT professionals, risk and compliance officers, and anyone responsible for protecting an organization's information assets. It's equally relevant to internal and external auditors who need to assess an ISMS against ISO/IEC 27001's requirements.
Learning objectives
- Understand the requirements of ISO/IEC 27001 for establishing and maintaining an ISMS
- Learn to support an organization in implementing information security policies and procedures tailored to its needs
- Gain the competence to integrate an ISMS into an organization's wider processes
- Understand the risk assessment and risk treatment process central to ISO/IEC 27001
- Learn how to apply the four categories of Annex A controls: organizational, people, physical, and technological
Why attend
Information security threats keep growing in scale and sophistication, making a certified ISMS a competitive necessity rather than a formality. Certification proves the expertise to implement, manage, and continually improve an ISMS, opening doors to information security careers and equipping professionals to lead or audit implementations with confidence.
PECB link
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001
