Choose your language
ISO 27001 Foundation Training
More than 2 million students worldwide

ISO 27001 Foundation Training

ISO 27001 Foundation Training gives you the structured knowledge to build, manage, and audit an Information Security Management System from the ground up. You'll master every clause of the standard, from organizational context through continual improvement, and learn how to apply Annex A controls to real organizational risks. This course is built for IT professionals, compliance officers, and security practitioners who need a credible, practical command of ISO 27001.

Dedika for businesses

What you will learn:

You will gain a thorough understanding of the ISO 27001 standard, including its clause structure, the PDCA improvement cycle, and the full risk assessment and treatment process. You will learn how to design an ISMS scope, produce a Statement of Applicability, and manage documented information that satisfies certification auditors. The course covers Annex A controls across organizational, people, physical, and technological categories, giving you the vocabulary and judgment to select and justify controls. You will also explore incident management, supplier security, privacy alignment, and stakeholder communication. By the end, you will be prepared to support or lead an ISO 27001 certification effort in your organization.

How you study in practice ISO 27001 Foundation Training

How you practice ISO 27001 Foundation Training

For companies that want to train their team

With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 33 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Introduction to Information Security Concepts

  • Lesson 1 • Business Drivers for Information Security

    Examines regulatory pressure, reputational risk, and competitive advantage as security motivators. Prepares students to articulate the business case for ISO 27001 adoption.

  • Lesson 2 • Threats, Vulnerabilities, and Risk

    Explains the relationship among threats, vulnerabilities, and risk in practical terms. Provides the risk language needed for all subsequent ISO 27001 discussions.

  • Lesson 3 • What Is Information Security

    Defines information security and distinguishes it from cybersecurity and IT security. Anchors the chapter by establishing shared vocabulary used throughout the course.

  • Lesson 4 • Security Controls Overview

    Introduces preventive, detective, and corrective control categories. Connects control types to the risk treatment options explored later in the course.

Chapter 2See details

Overview of ISO 27001 and the ISMS

  • Lesson 1 • What Is an ISMS

    Defines the Information Security Management System as a set of policies, processes, and controls. Establishes the ISMS as the central artifact students will learn to build and audit.

  • Lesson 2 • History and Purpose of ISO 27001

    Traces the standard's evolution from earlier codes of practice to the current version. Contextualizes why the standard exists and who it is designed to serve.

  • Lesson 3 • Structure of the ISO 27001 Standard

    Maps the clause-by-clause layout of the standard from scope through improvement. Gives students a navigation framework for all detailed clause study ahead.

  • Lesson 4 • High-Level Certification Process

    Outlines the stages from gap assessment through surveillance audits. Sets realistic expectations for the certification journey students may support or lead.

Chapter 3See details

Plan-Do-Check-Act and ISO 27001 Clauses 4–6

  • Lesson 1 • Clause 4: Organizational Context

    Covers internal and external issue analysis and identification of interested parties. Teaches students to define the ISMS scope based on organizational realities.

  • Lesson 2 • The PDCA Cycle in an ISMS Context

    Maps Plan, Do, Check, and Act stages to ISMS activities and ISO 27001 clauses. Provides the iterative improvement model that underpins every subsequent chapter.

  • Lesson 3 • Clause 6: Planning

    Addresses risk and opportunity identification, risk assessment methodology, and objective setting. Connects planning outputs to the risk treatment activities in the next chapter.

  • Lesson 4 • Clause 5: Leadership and Commitment

    Examines top management obligations, policy requirements, and role assignments. Demonstrates how leadership engagement directly enables ISMS effectiveness.

Chapter 4See details

Risk Assessment and Treatment

  • Lesson 1 • Risk Treatment Options

    Covers modify, avoid, share, and retain as the four treatment strategies. Links each option to control selection from Annex A and other sources.

  • Lesson 2 • Designing the Risk Assessment Process

    Establishes criteria for risk identification, analysis, and evaluation before any assessment begins. Ensures students can document a repeatable, auditable methodology.

  • Lesson 3 • Statement of Applicability

    Explains the purpose, required content, and maintenance of the Statement of Applicability. Demonstrates how it bridges risk treatment decisions and Annex A control selection.

  • Lesson 4 • Identifying and Analyzing Risks

    Guides students through asset inventory, threat-vulnerability pairing, and risk scoring. Produces the raw risk register that feeds treatment decisions.

  • Lesson 5 • Risk Treatment Plan and Approval

    Structures the risk treatment plan document and the management approval process. Prepares students to present risk decisions to leadership for formal sign-off.

Chapter 5See details

ISO 27001 Clauses 7–8: Support and Operation

  • Lesson 1 • Awareness and Communication

    Addresses what staff must know about the ISMS and how communication plans are structured. Ensures the ISMS is understood and supported across the organization.

  • Lesson 2 • Clause 8: Operational Planning and Control

    Covers planning and controlling processes that implement risk treatment decisions. Links operational controls to the risk treatment plan produced in Chapter 4.

  • Lesson 3 • Documented Information Management

    Explains creation, control, and retention requirements for ISMS documents and records. Prepares students to build a document control system that satisfies auditors.

  • Lesson 4 • Clause 7: Resources and Competence

    Covers determining and providing resources and ensuring staff competence through training. Connects workforce capability directly to ISMS effectiveness.

Chapter 6See details

Annex A Controls Deep Dive

  • Lesson 1 • Technological Controls

    Analyzes access control, cryptography, logging, vulnerability management, and data masking. Provides the technical control vocabulary needed for risk treatment decisions.

  • Lesson 2 • Organizational Controls

    Examines policy, roles, threat intelligence, and supplier security controls. Establishes the governance layer that enables all technical controls to function effectively.

  • Lesson 3 • Physical Controls

    Reviews perimeter security, equipment protection, clear desk, and secure disposal controls. Connects physical safeguards to information asset protection goals.

  • Lesson 4 • People Controls

    Covers pre-employment screening, security training, disciplinary processes, and offboarding. Addresses the human element as a primary risk vector in any ISMS.

Chapter 7See details

Performance Evaluation and Internal Audit

  • Lesson 1 • Conducting the Internal Audit

    Walks through opening meetings, evidence collection, finding classification, and closing meetings. Gives students practical skills for executing a compliant ISMS audit.

  • Lesson 2 • Clause 9: Monitoring and Measurement

    Defines what to measure, how to measure it, and when to analyze results. Establishes the metrics foundation that feeds management review and continual improvement.

  • Lesson 3 • Internal Audit Program Design

    Covers audit program planning, scope definition, frequency, and auditor competence. Prepares students to establish a credible, risk-based internal audit function.

  • Lesson 4 • Management Review

    Details the required inputs, agenda items, and outputs of the ISO 27001 management review. Connects review outputs to corrective actions and ISMS improvement decisions.

Chapter 8See details

Continual Improvement and Nonconformity Management

  • Lesson 1 • Root Cause Analysis Techniques

    Introduces five-whys, fishbone diagrams, and fault tree analysis for ISMS nonconformities. Ensures corrective actions address causes rather than symptoms.

  • Lesson 2 • Understanding Nonconformities

    Distinguishes major from minor nonconformities and explains their impact on certification. Provides the classification knowledge needed before corrective action can begin.

  • Lesson 3 • Corrective Action Process

    Structures the corrective action workflow from finding through verification of effectiveness. Links corrective actions back to the risk register and control updates.

  • Lesson 4 • Embedding Continual Improvement

    Explores how lessons learned, trend analysis, and innovation feed ISMS maturity growth. Prepares students to sustain and advance the ISMS beyond initial certification.

Certification

Your valid completion certificate

This course is for you:

  • IT administrator: ready to move into a formal security management role.

  • Compliance coordinator: needs a structured framework to anchor existing responsibilities.

  • Risk analyst: wants to extend expertise into information security governance.

  • Career changer: transitioning from a non-security background into cybersecurity or GRC.

  • Operations manager: responsible for teams handling sensitive data or regulated systems.

  • Junior security professional: building credentials toward a first specialist certification.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in the United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course