Choose your language
ISO 27001 and 27002 Training
More than 2 million students worldwide

ISO 27001 and 27002 Training

Master ISO/IEC 27001 and 27002 from foundational concepts to full certification readiness. This training covers risk management, control implementation, internal auditing, and continual improvement across all standard clauses. Whether you're building an ISMS from scratch or strengthening an existing one, you'll gain the practical skills to protect your organization and pass the certification audit.

Dedika for businesses

What you will learn:

You will learn how to design, implement, and maintain an Information Security Management System that meets ISO/IEC 27001 requirements. The course covers the complete risk assessment and treatment process, including asset identification, threat analysis, and control selection from ISO/IEC 27002. You will develop a Statement of Applicability, build an internal audit program, and manage corrective actions using root cause analysis. Leadership obligations, documentation control, and performance measurement are addressed in detail. You will also explore supplementary topics including supply chain security, privacy alignment, incident response, and emerging threats such as ransomware and AI-driven attacks.

How you study in practice ISO 27001 and 27002 Training

How you practice ISO 27001 and 27002 Training

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 35 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Information Security Fundamentals and Context

  • Lesson 1 • Business Drivers for an ISMS

    Examines regulatory pressure, customer expectations, and breach costs that motivate ISMS adoption. Connects security investment to measurable business outcomes.

  • Lesson 2 • Organizational Context and Interested Parties

    Applies Clause 4 thinking to identify internal and external issues and stakeholder needs. Learners practice scoping an ISMS around real organizational context.

  • Lesson 3 • Core Information Security Concepts

    Defines confidentiality, integrity, and availability as the CIA triad and introduces key terminology. Grounds all subsequent ISMS discussions in shared vocabulary.

  • Lesson 4 • The ISO/IEC Standards Landscape

    Maps the ISO/IEC 27000 family structure and clarifies the relationship between 27001 and 27002. Learners understand which standard governs requirements versus guidance.

Chapter 2See details

ISMS Scope, Leadership, and Planning

  • Lesson 1 • Information Security Objectives

    Teaches how to set measurable, aligned security objectives and link them to operational plans. Objectives translate policy intent into trackable performance targets.

  • Lesson 2 • Defining and Documenting ISMS Scope

    Guides learners through boundary-setting decisions, exclusions, and scope statement drafting. A well-defined scope prevents audit gaps and resource waste.

  • Lesson 3 • Leadership Commitment and Governance

    Details top management responsibilities under Clause 5, including policy ownership and role assignment. Strong leadership commitment is the primary predictor of ISMS success.

  • Lesson 4 • Planning for Change and Opportunities

    Addresses how to incorporate opportunities and manage planned changes within the ISMS. Proactive planning reduces disruption when the organization or threat landscape evolves.

Chapter 3See details

Information Security Risk Management

  • Lesson 1 • Information Asset Identification

    Covers asset inventory methods, ownership assignment, and classification as prerequisites to risk assessment. Accurate asset data is the foundation of meaningful risk analysis.

  • Lesson 2 • Risk Treatment and Acceptance

    Explains the four treatment options—modify, avoid, share, retain—and links treatment decisions to control selection. Learners produce a risk treatment plan with justified residual risk acceptance.

  • Lesson 3 • Risk Assessment Methodology

    Teaches qualitative and quantitative risk assessment techniques, threat-vulnerability pairing, and likelihood-impact scoring. Learners apply a repeatable methodology to produce defensible risk ratings.

  • Lesson 4 • Ongoing Risk Monitoring and Review

    Establishes processes for continuous risk monitoring, trigger-based reassessment, and risk register maintenance. Keeps the ISMS responsive to emerging threats and organizational changes.

  • Lesson 5 • Risk Management Principles and Framework

    Introduces ISO 31000-aligned risk concepts and explains how they integrate with ISMS requirements. Establishes the mental model learners apply throughout the risk process.

Chapter 4See details

ISO/IEC 27002 Controls Deep Dive

  • Lesson 1 • People Controls

    Examines controls governing the full employment lifecycle, from pre-hire screening to offboarding. Human-layer controls reduce insider threat and unintentional security failures.

  • Lesson 2 • Physical and Environmental Controls

    Addresses secure areas, equipment protection, and environmental threat mitigation. Physical controls prevent unauthorized access and protect hardware assets.

  • Lesson 3 • Organizational Controls

    Covers the 37 organizational controls addressing policies, roles, supplier relationships, and incident management. Learners map each control to risk scenarios and draft implementation notes.

  • Lesson 4 • Statement of Applicability Development

    Guides learners through building a complete Statement of Applicability linking controls to risks and justifying inclusions and exclusions. The SoA is the central audit evidence document.

  • Lesson 5 • Technological Controls

    Covers the largest control theme: network security, endpoint protection, cryptography, logging, and vulnerability management. Learners evaluate technical control effectiveness against threat scenarios.

Chapter 5See details

ISMS Support, Operation, and Documentation

  • Lesson 1 • Communication Planning

    Establishes what, when, and how to communicate security information internally and externally. Structured communication prevents misunderstanding and supports incident response.

  • Lesson 2 • Operational Planning and Control

    Applies Clause 8 to plan, implement, and control security processes and manage outsourced functions. Operational control ensures risk treatment plans are executed as designed.

  • Lesson 3 • Documented Information Management

    Covers creation, control, retention, and disposal of ISMS documents and records per Clause 7.5. Proper document control is essential for audit readiness and operational consistency.

  • Lesson 4 • Competence and Awareness Programs

    Defines competence requirements for ISMS roles and designs awareness programs for all staff. Competent, aware personnel are the human firewall of any ISMS.

Chapter 6See details

Performance Evaluation and Internal Audit

  • Lesson 1 • ISMS Internal Audit Program

    Covers audit program planning, auditor competence, audit criteria, and evidence collection techniques. Internal audits provide independent assurance before certification.

  • Lesson 2 • Nonconformity Identification and Reporting

    Defines nonconformity types, grading severity, and documenting findings in audit reports. Clear nonconformity reporting drives targeted corrective action.

  • Lesson 3 • Management Review Process

    Structures the management review meeting agenda, required inputs, and expected outputs per Clause 9.3. Management reviews translate audit data into strategic ISMS decisions.

  • Lesson 4 • Monitoring and Measurement Design

    Teaches selection of security metrics, KPIs, and measurement methods that produce actionable data. Metrics must demonstrate ISMS effectiveness, not just activity.

Chapter 7See details

Corrective Action and Continual Improvement

  • Lesson 1 • Continual Improvement Planning

    Establishes a structured improvement backlog, prioritization criteria, and integration with ISMS planning cycles. Continual improvement is a certification requirement, not an optional activity.

  • Lesson 2 • Nonconformity and Corrective Action Workflow

    Maps the end-to-end corrective action process from nonconformity detection to closure verification. A disciplined workflow prevents recurrence and demonstrates ISMS maturity.

  • Lesson 3 • Root Cause Analysis Techniques

    Introduces 5-Whys, fishbone diagrams, and fault tree analysis applied to security incidents and audit findings. Selecting the right technique improves the quality of corrective actions.

  • Lesson 4 • Lessons Learned and Knowledge Sharing

    Captures lessons from incidents, audits, and exercises and distributes them to prevent recurrence across the organization. Institutionalized learning accelerates ISMS maturity.

Chapter 8See details

Certification Audit and ISMS Maintenance

  • Lesson 1 • Post-Certification ISMS Maintenance

    Establishes routines for keeping the ISMS current as the organization, technology, and threat landscape evolve. Maintenance activities protect the value of certification over time.

  • Lesson 2 • Surveillance and Recertification Cycles

    Describes annual surveillance audit requirements and the three-year recertification cycle. Ongoing compliance prevents certificate suspension and maintains stakeholder confidence.

  • Lesson 3 • Certification Body Selection and Engagement

    Covers accreditation criteria for certification bodies, pre-audit engagement, and contract considerations. Choosing an accredited body ensures certification is globally recognized.

  • Lesson 4 • Stage 2 On-Site Certification Audit

    Prepares staff for interviews, evidence walkthroughs, and auditor interactions during Stage 2. Confident, consistent responses demonstrate ISMS operational effectiveness.

  • Lesson 5 • Stage 1 Documentation Review

    Explains what auditors examine in Stage 1, common documentation gaps, and how to prepare evidence packages. Stage 1 readiness prevents costly delays before the on-site audit.

Certification

Your valid completion certificate

This course is for you:

  • IT Manager: responsible for security decisions but lacking formal ISMS training.

  • Compliance Officer: managing regulatory obligations that now require ISO certification evidence.

  • Security Analyst: ready to move beyond technical tasks into governance and risk roles.

  • Risk Consultant: expanding service offerings to include information security management frameworks.

  • Operations Manager: overseeing business processes where data protection gaps create liability.

  • Career Changer: coming from auditing or legal and pivoting into cybersecurity governance work.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course