PECB ISO 27001:2022 Transition Training Course
ISO 27001:2022 is a standard for information security management systems, providing criteria for compliance certification for organizations and professionals. This standard helps in the creation, implementation, maintenance, and improvement of an information security management system (ISMS).
This instructor-led, live training (online or onsite) is designed for intermediate to expert-level IT professionals who want to enhance their skills and qualifications in information security or related fields.
By the end of this training, participants will be able to:
- Understand the differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022.
- Gain the knowledge and skills to plan and implement the transition from the 2013 to the 2022 version of the standard efficiently.
- Apply the knowledge in real-world scenarios, facilitating a smooth transition in their respective organizations.
Format of the Course
- Interactive lecture and discussion.
- Plenty of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Introduction
- Brief review of ISO/IEC 27001:2013
- Overview of ISO/IEC 27001:2022
- Importance of Information Security Management Systems (ISMS)
Understanding the Changes
- ISO/IEC 27001:2013 vs. ISO/IEC 27001:2022
- Major changes in Annex A
- Updates to the clauses
- Implications of the title change
New Concepts and Elements in ISO/IEC 27001:2022
- Introduction to new concepts
- Risk management enhancements
- Enhanced focus on leadership and commitment
- Compliance and continuous improvement aspects
Transitioning to ISO/IEC 27001:2022
- Key steps for transitioning to the new standard
- Identifying areas of change
- Planning and implementing changes
- Transition timeline and deadlines
Auditing and Certification Process
- Changes in the auditing process for the 2022 standard
- Certification requirements and procedures
- Transition exam overview
- Compliance with PECB's code of ethics standards ISO/IEC 17024
Taking the Examination
- Registration procedures
- Tips and tricks for passing the exam
Summary and Next Steps
Requirements
- Basic understanding of the principles and concepts of the ISO/IEC 27001:2013 standard
Audience
- Information security managers
- ISO/IEC 27001 auditors
- IT professionals
Open Training Courses require 5+ participants.
PECB ISO 27001:2022 Transition Training Course - Booking
PECB ISO 27001:2022 Transition Training Course - Enquiry
PECB ISO 27001:2022 Transition - Consultancy Enquiry
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
Upcoming Courses
Related Courses
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led live training in Mexico (online or on-site) is tailored for advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain a comprehensive understanding of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
Compliance for Payment Services in Japan
7 HoursThis instructor-led, live training in Mexico (online or onsite) is designed for compliance professionals in the payment services sector who aim to develop, implement, and enforce a robust compliance program within their organizations.
Upon completion of this training, participants will be capable of:
- Grasping the regulations established by government regulators for payment service providers.
- Developing the internal policies and procedures necessary to meet government regulatory requirements.
- Implementing a compliance program that aligns with applicable laws.
- Ensuring that all corporate processes and procedures adhere to the compliance program.
- Safeguarding the company's reputation while protecting it from legal litigation.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led live training in Mexico (available online or onsite) is designed for intermediate-level cybersecurity professionals seeking to expand their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the core components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop strategies to mitigate risks.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers a comprehensive introduction to the newly implemented Accessibility Law, equipping developers with the practical skills necessary to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's significance and implications, the training quickly transitions into hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
HiTrust Common Security Framework Compliance
14 HoursThis instructor-led, live training in Mexico (online or in-person) targets developers and administrators who aim to create software and products that are HiTRUST compliant.
Upon completion of this training, participants will be able to:
- Grasp the fundamental concepts of the HiTrust CSF (Common Security Framework).
- Identify the administrative and security control domains defined by HITRUST CSF.
- Learn about the various types of HiTrust assessments and scoring mechanisms.
- Understand the certification process and requirements for achieving HiTrust compliance.
- Acquire best practices and tips for adopting the HiTrust approach.
ISO 27001:2023 Internal Auditor of the Information Security Management System
35 HoursObjectives
- Acquire comprehensive knowledge of ISO 27001:2023.
- Learn how to conduct audits in alignment with the standard's requirements.
- Discover industry best practices.
ISO 27001:2023 Lead Auditor of the Information Security Management System
35 HoursObjectives
- Developing a solid understanding of ISO 27001:2023
- Learning how to conduct audits in compliance with the standard
- Familiarizing with industry best practices
ISO 27001:2023 Requirements
14 HoursObjectives
- Gaining knowledge about changes to ISO 27001 2023 edition
- Gaining knowledge on how to audit in accordance with the standard
- Getting to know good practices
PECB ISO/IEC 27001 Foundation
14 HoursWhy participate in this course?
The ISO/IEC 27001 Foundation training equips you with the essential knowledge to implement and manage an Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards. Throughout this course, you will gain a comprehensive understanding of the various ISMS components, including ISMS policies, procedures, performance metrics, leadership commitment, internal auditing, management reviews, and continuous improvement practices.
Upon completion of the course, you will be eligible to take the examination and apply for the "PECB Certified ISO/IEC 27001 Foundation" credential. Earning a PECB Foundation Certificate demonstrates that you have mastered the fundamental methodologies, requirements, framework, and management approaches associated with ISO/IEC 27001.
Who is this course for?
- Professionals currently involved in Information Security Management
- Individuals looking to acquire knowledge about the core processes of Information Security Management Systems (ISMS)
- Aspiring professionals interested in building a career in Information Security Management
Te methodology
- Lectures are enhanced with practical questions and real-world examples
- Hands-on exercises incorporate illustrative examples and group discussions
- Practice tests mirror the format and difficulty of the official Certification Exam
ISO 27002 Lead Manager
35 HoursThe ISO/IEC 27002 Lead Manager training program is designed to equip you with the essential expertise and knowledge required to support your organization in implementing and managing Information Security controls, as outlined in ISO/IEC 27002.
Upon completing this course, you will be eligible to take the exam and apply for the "PECB Certified ISO/IEC 27002 Lead Manager" credential. This PECB Lead Manager Certification demonstrates your mastery of the principles and techniques for implementing and managing Information Security Controls in accordance with ISO/IEC 27002.
Who should attend?
- Managers or consultants aiming to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 and ISO/IEC 27002
- Project managers or consultants who wish to master the implementation process for Information Security Management Systems
- Professionals responsible for information security, compliance, risk, and governance within an organization
- Members of information security teams
- Expert advisors in information technology
- Information Security officers
- Privacy officers
- IT professionals
- CTOs, CIOs, and CISOs
Learning objectives
- Master the implementation of Information Security controls by adhering to the framework and principles of ISO/IEC 27002
- Gain a comprehensive understanding of the concepts, approaches, standards, methods, and techniques necessary for the effective implementation and management of Information Security controls
- Understand the relationships between components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance, and human behavior
- Appreciate the significance of information security for organizational strategy
- Master the implementation of information security management processes
- Master the formulation and implementation of security requirements and objectives
Educational approach
- This training combines both theory and practice
- Lecture sessions illustrated with examples from real-world cases
- Practical exercises based on case studies
- Review exercises to assist with exam preparation
- Practice tests similar to the certification exam
General Information
- Certification fees are included in the exam price
- Training materials containing over 500 pages of information and practical examples will be distributed to participants
- A participation certificate granting 31 CPD (Continuing Professional Development) credits will be issued to participants
- In the event of an exam failure, you may retake the exam within 12 months at no additional cost
PECB ISO/IEC 27001 Lead Implementer
35 HoursInformation security threats and attack methods are constantly evolving and becoming more sophisticated. The most effective way to counter these risks is through the proper implementation and management of information security controls and industry best practices. Furthermore, robust information security is a critical expectation and mandate from customers, regulators, and other stakeholders.
This training course is structured to equip participants with the skills needed to implement an Information Security Management System (ISMS) in accordance with ISO/IEC 27001. It provides a thorough understanding of ISMS best practices and establishes a framework for its ongoing management and enhancement.
Upon completion of the training, you are eligible to sit for the examination. If you pass, you can pursue the “PECB Certified ISO/IEC 27001 Lead Implementer” credential, which validates your practical knowledge and ability to implement an ISMS based on ISO/IEC 27001 requirements.
Who Can Attend?
- Project managers and consultants engaged in or interested in the implementation of an ISMS
- Expert advisors looking to master ISMS implementation
- Professionals responsible for ensuring organizational conformity with information security requirements
- Members of an ISMS implementation team
General information
- Certification fees are included in the exam price
- Participants will receive training materials comprising over 450 pages of content and practical examples
- A participation certificate granting 31 CPD (Continuing Professional Development) credits will be issued
- In the event of an exam failure, a free retake is available within 12 months
Educational approach
- The course features essay-type exercises, multiple-choice quizzes, real-world examples, and best practices for ISMS implementation.
- Participants are encouraged to interact and engage in discussions during quizzes and exercises.
- Exercises are grounded in a case study.
- The format of the quizzes mirrors that of the certification exam.
Learning objectives
This training course will help you:
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques for implementing and effectively managing an ISMS
- Recognize the relationship between ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks
- Understand how an ISMS and its processes operate in accordance with ISO/IEC 27001
- Learn to interpret and apply ISO/IEC 27001 requirements within a specific organizational context
- Acquire the necessary knowledge to support an organization in planning, implementing, managing, monitoring, and maintaining an ISMS effectively
Compliance and the Management of Compliance Risk
21 HoursAudience
This course is designed for all employees who need a practical grasp of Compliance and effective Risk Management.
Course Format
The training employs a blended methodology that features:
- Guided discussions
- Slide-based presentations
- Case studies
- Real-world examples
Course Objectives
By the end of the course, participants will be able to:
Gain a solid understanding of the key aspects of Compliance, alongside national and international initiatives aimed at managing associated risks.
Explain how organizations and their teams can establish an effective Compliance Risk Management Framework.
Describe the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles integrate within a business structure.
Identify critical risk areas in Financial Crime, particularly in the context of international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves overseeing the entire lifecycle of open-source components within an organization, ensuring their use is secure, compliant, and efficient.
This instructor-led, live training, available online or onsite, targets intermediate-level IT professionals seeking to implement best practices for managing open-source software in enterprise and government settings.
By the conclusion of this training, participants will be able to:
- Develop effective OSS policies and governance frameworks.
- Utilize SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks related to licensing and security vulnerabilities.
- Streamline OSS adoption to maximize innovation and cost savings.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations using OSS management tools.
Customization Options
- This course can be customized to align with specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Mexico (available online or in-person) offers a professional qualification for practitioners aiming to showcase their expertise and comprehension of the PCI Data Security Standard (PCI DSS).
Upon completing this training, participants will be able to:
- Comprehend the payment process and the PCI standards established to safeguard it.
- Grasp the roles and responsibilities of entities operating within the payment industry.
- Gain deep insight into and understanding of the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and its application to organizations involved in the transaction process.