The protection and availability of information is critical to the survival and success of every organization. The best way to do this is for organizations to create an information security management system aligned with ISO27001. ISO27001 is the global standard for a specification for an ISMS.
To implement ISO27001 organizations should use the practical guidelines outlined in ISO27002. Drawing on the experience of information security practitioners in over 40 countries, ISO27002 provides practical guidance for those involved in initiating, implementing and maintaining an information security programme.
An understanding of the best practice guidance as outlined in ISO2702 is essential to ensure the compliance to ISO27001 in any organization.
The ISO27002 ISMS Foundation Course delivers a comprehensive education in ISO27002 best practice and a recognized industry standard certification awarded by EXIN.
Who is this course suitable for?
The one-day ISO27002 ISMS Foundation Course is designed for anyone in an organization who is interested or responsible for the implementation of an effective information security programme based on the ISO27001/2 Standards. It is particularly suited for managers who are responsible in any way for the security or availability of confidential information assets. This includes Information Security, IT Service Management, Data Protection Officers and all Heads of Department.
What does this course cover?
During the course you will learn about:
- The contents of ISO27002 and its relationship to ISO27001
- Key roles and responsibilities of all staff responsible for information security
- Information and data relationships (security, governance, assurance)
- Defining threats and vulnerabilities and understanding Risk Management
- Risk analysis with an understanding of Impacts, Likelihood and Probability
- Required policies and Information Security Plan
- External relationships with 3rd party organisations and individuals
- Information Architecture and data flows
- Protective marking and the relationship to Impact (Risk)
This course is presented by an experienced trainer in a class-room format and includes relevant workshop exercise and discussion sessions.
Are there entry requirements?
There are no formal entry requirements. The course is designed to provide a comprehensive introduction to information security management. Given the close relationship of ISO27002 with ISO27001, we strongly recommend that delegates attend our ISO27001 ISMS Foundation Course prior to taking this course.
Available dates
What's included?
Our package includes lunch and refreshments, and full course materials. Although the course is non-residential, we offer help finding appropriate hotels, close to the training venue. Please contact us on 1 877 317 3454 or email us for help with your arrangements.
Achieve EXIN certification
This course is based on the EXIN Information Security Foundation syllabus and prepares delegates for the EXIN ISFS examination which is taken at the end of the day. Successful candidates will be awarded the EXIN Information Security Foundation Certificate.

The ISO27001 learning path
IT Governance is responsible for world’s first certificated programme of ISO27001 education offering delegates the opportunity to attain an industry - standard qualification and to help their organization achieve compliance and best practice with the standard.
Read more about our training courses here
Other courses include ISO27001 Certified ISMS Lead Implementer, Internal Auditor and Lead Auditor.
In-house training
For a larger number of delegates attending from one company, we can deliver any IT Governance training course at your business premises. This offers you the flexibility of choosing a date and a location which is convenient for your team and the opportunity to discuss your business issues in the strictest confidence. It also has the advantage of reducing the cost and inconvenience of travel and accommodation associated with attendance at our training centres.
Contact us directly on 1 877 317 3454 or email us for an initial, no-obligation discussion of your requirements.