
ISO 27001 Foundation Training
ISO 27001 Foundation Training gives you the structured knowledge to build, manage, and audit an Information Security Management System from the ground up. You'll master every clause of the standard, from organizational context through continual improvement, and learn how to apply Annex A controls to real organizational risks. This course is built for IT professionals, compliance officers, and security practitioners who need a credible, practical command of ISO 27001.
What you will learn:
You will gain a thorough understanding of the ISO 27001 standard, including its clause structure, the PDCA improvement cycle, and the full risk assessment and treatment process. You will learn how to design an ISMS scope, produce a Statement of Applicability, and manage documented information that satisfies certification auditors. The course covers Annex A controls across organizational, people, physical, and technological categories, giving you the vocabulary and judgment to select and justify controls. You will also explore incident management, supplier security, privacy alignment, and stakeholder communication. By the end, you will be prepared to support or lead an ISO 27001 certification effort in your organization.
How you study in practice ISO 27001 Foundation Training
How you practice ISO 27001 Foundation Training
For companies that want to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 33 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Information Security Concepts
Introduction to Information Security Concepts
Lesson 1 • Business Drivers for Information Security
Examines regulatory pressure, reputational risk, and competitive advantage as security motivators. Prepares students to articulate the business case for ISO 27001 adoption.
Lesson 2 • Threats, Vulnerabilities, and Risk
Explains the relationship among threats, vulnerabilities, and risk in practical terms. Provides the risk language needed for all subsequent ISO 27001 discussions.
Lesson 3 • What Is Information Security
Defines information security and distinguishes it from cybersecurity and IT security. Anchors the chapter by establishing shared vocabulary used throughout the course.
Lesson 4 • Security Controls Overview
Introduces preventive, detective, and corrective control categories. Connects control types to the risk treatment options explored later in the course.
Chapter 2HideHide detailsSee detailsOverview of ISO 27001 and the ISMS
Overview of ISO 27001 and the ISMS
Lesson 1 • What Is an ISMS
Defines the Information Security Management System as a set of policies, processes, and controls. Establishes the ISMS as the central artifact students will learn to build and audit.
Lesson 2 • History and Purpose of ISO 27001
Traces the standard's evolution from earlier codes of practice to the current version. Contextualizes why the standard exists and who it is designed to serve.
Lesson 3 • Structure of the ISO 27001 Standard
Maps the clause-by-clause layout of the standard from scope through improvement. Gives students a navigation framework for all detailed clause study ahead.
Lesson 4 • High-Level Certification Process
Outlines the stages from gap assessment through surveillance audits. Sets realistic expectations for the certification journey students may support or lead.
Chapter 3HideHide detailsSee detailsPlan-Do-Check-Act and ISO 27001 Clauses 4–6
Plan-Do-Check-Act and ISO 27001 Clauses 4–6
Lesson 1 • Clause 4: Organizational Context
Covers internal and external issue analysis and identification of interested parties. Teaches students to define the ISMS scope based on organizational realities.
Lesson 2 • The PDCA Cycle in an ISMS Context
Maps Plan, Do, Check, and Act stages to ISMS activities and ISO 27001 clauses. Provides the iterative improvement model that underpins every subsequent chapter.
Lesson 3 • Clause 6: Planning
Addresses risk and opportunity identification, risk assessment methodology, and objective setting. Connects planning outputs to the risk treatment activities in the next chapter.
Lesson 4 • Clause 5: Leadership and Commitment
Examines top management obligations, policy requirements, and role assignments. Demonstrates how leadership engagement directly enables ISMS effectiveness.
Chapter 4HideHide detailsSee detailsRisk Assessment and Treatment
Risk Assessment and Treatment
Lesson 1 • Risk Treatment Options
Covers modify, avoid, share, and retain as the four treatment strategies. Links each option to control selection from Annex A and other sources.
Lesson 2 • Designing the Risk Assessment Process
Establishes criteria for risk identification, analysis, and evaluation before any assessment begins. Ensures students can document a repeatable, auditable methodology.
Lesson 3 • Statement of Applicability
Explains the purpose, required content, and maintenance of the Statement of Applicability. Demonstrates how it bridges risk treatment decisions and Annex A control selection.
Lesson 4 • Identifying and Analyzing Risks
Guides students through asset inventory, threat-vulnerability pairing, and risk scoring. Produces the raw risk register that feeds treatment decisions.
Lesson 5 • Risk Treatment Plan and Approval
Structures the risk treatment plan document and the management approval process. Prepares students to present risk decisions to leadership for formal sign-off.
Chapter 5HideHide detailsSee detailsISO 27001 Clauses 7–8: Support and Operation
ISO 27001 Clauses 7–8: Support and Operation
Lesson 1 • Awareness and Communication
Addresses what staff must know about the ISMS and how communication plans are structured. Ensures the ISMS is understood and supported across the organization.
Lesson 2 • Clause 8: Operational Planning and Control
Covers planning and controlling processes that implement risk treatment decisions. Links operational controls to the risk treatment plan produced in Chapter 4.
Lesson 3 • Documented Information Management
Explains creation, control, and retention requirements for ISMS documents and records. Prepares students to build a document control system that satisfies auditors.
Lesson 4 • Clause 7: Resources and Competence
Covers determining and providing resources and ensuring staff competence through training. Connects workforce capability directly to ISMS effectiveness.
Chapter 6HideHide detailsSee detailsAnnex A Controls Deep Dive
Annex A Controls Deep Dive
Lesson 1 • Technological Controls
Analyzes access control, cryptography, logging, vulnerability management, and data masking. Provides the technical control vocabulary needed for risk treatment decisions.
Lesson 2 • Organizational Controls
Examines policy, roles, threat intelligence, and supplier security controls. Establishes the governance layer that enables all technical controls to function effectively.
Lesson 3 • Physical Controls
Reviews perimeter security, equipment protection, clear desk, and secure disposal controls. Connects physical safeguards to information asset protection goals.
Lesson 4 • People Controls
Covers pre-employment screening, security training, disciplinary processes, and offboarding. Addresses the human element as a primary risk vector in any ISMS.
Chapter 7HideHide detailsSee detailsPerformance Evaluation and Internal Audit
Performance Evaluation and Internal Audit
Lesson 1 • Conducting the Internal Audit
Walks through opening meetings, evidence collection, finding classification, and closing meetings. Gives students practical skills for executing a compliant ISMS audit.
Lesson 2 • Clause 9: Monitoring and Measurement
Defines what to measure, how to measure it, and when to analyze results. Establishes the metrics foundation that feeds management review and continual improvement.
Lesson 3 • Internal Audit Program Design
Covers audit program planning, scope definition, frequency, and auditor competence. Prepares students to establish a credible, risk-based internal audit function.
Lesson 4 • Management Review
Details the required inputs, agenda items, and outputs of the ISO 27001 management review. Connects review outputs to corrective actions and ISMS improvement decisions.
Chapter 8HideHide detailsSee detailsContinual Improvement and Nonconformity Management
Continual Improvement and Nonconformity Management
Lesson 1 • Root Cause Analysis Techniques
Introduces five-whys, fishbone diagrams, and fault tree analysis for ISMS nonconformities. Ensures corrective actions address causes rather than symptoms.
Lesson 2 • Understanding Nonconformities
Distinguishes major from minor nonconformities and explains their impact on certification. Provides the classification knowledge needed before corrective action can begin.
Lesson 3 • Corrective Action Process
Structures the corrective action workflow from finding through verification of effectiveness. Links corrective actions back to the risk register and control updates.
Lesson 4 • Embedding Continual Improvement
Explores how lessons learned, trend analysis, and innovation feed ISMS maturity growth. Prepares students to sustain and advance the ISMS beyond initial certification.
Your valid completion certificate
This course is for you:
IT administrator: ready to move into a formal security management role.
Compliance coordinator: needs a structured framework to anchor existing responsibilities.
Risk analyst: wants to extend expertise into information security governance.
Career changer: transitioning from a non-security background into cybersecurity or GRC.
Operations manager: responsible for teams handling sensitive data or regulated systems.
Junior security professional: building credentials toward a first specialist certification.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















