資訊安全
ISO/IEC 27002 — Information Security Controls
課程類型、時長及學費
| 課程類型 | 適合對象 | 企業得益 | 時長 | 學費 |
|---|---|---|---|---|
| Foundation | 希望學習管理系統及其流程實施基礎的人士 | 透過理解 ISO 標準的核心要素,為機構建立以最佳實務為本的取向與文化 | 2 天 | HKD 4,400 |
| Lead Manager | 相關領域的管理人員,希望掌握最佳實務所訂明的指引 | 帶領機構依循 ISO 標準指引,提升員工技能並改善效率 | 3 天 | HKD 9,600 |
About the standard
ISO/IEC 27002 provides guidelines for selecting and implementing information security controls, applicable to organizations of any industry or size. Its 2022 revision reorganized the standard's catalog of controls into four categories — organizational, people, physical, and technological — giving organizations a generic, flexible set of practices they can tailor to their own information security needs and risk profile.
Levels available
- Foundation — Introduces the four control categories and core concepts of ISO/IEC 27002, giving learners a working understanding of the standard.
- Manager — Builds practical skills to select, implement, and manage information security controls within an organization.
- Lead Manager — For those responsible for leading the selection and management of information security controls, developing advanced skills to continually improve an organization's control environment.
Who should attend
This course track is for information security officers, IT managers, and ISMS implementation team members responsible for selecting and managing security controls. It's also useful for consultants and auditors who need a practical, standards-based reference for evaluating an organization's control environment.
Learning objectives
- Understand the implementation of information security controls and control policies based on ISO/IEC 27002
- Learn practical approaches and techniques for implementing and managing information security controls
- Gain the competence to support an organization in planning, implementing, and managing its controls
- Understand the role of risk management in determining appropriate controls
- Learn how to support the continual improvement of an information security management system
Why attend
Since different organizations face different information security needs, having practitioners who can select and tailor the right mix of controls is essential to an effective ISMS. This training builds the practical knowledge to manage information security risk day to day, positions professionals as valuable members of an ISMS implementation team, and boosts career opportunities in one of the fastest-growing, most in-demand fields.
PECB link
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27002
