PECB ISO 27001:2022 Transition Training Course
ISO 27001:2022 serves as a standard for information security management systems, providing criteria for organizational and professional compliance certification. This standard supports the development, implementation, maintenance, and improvement of an information security management system (ISMS).
Delivered as an instructor-led, live training session (available online or onsite), this programme is designed for IT professionals at intermediate to advanced levels who aim to bolster their expertise and credentials in information security and related disciplines.
Upon completing this training, participants will be equipped to:
- Identify the differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022.
- Acquire the knowledge and skills necessary to efficiently plan and execute the migration from the 2013 to the 2022 version of the standard.
- Apply learned concepts in practical settings, ensuring a seamless transition within their respective organisations.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical practice.
- Hands-on implementation in a live-lab environment.
Customisation Options
- To arrange a tailored training session for this course, please contact us to make the necessary arrangements.
Course Outline
Introduction
- Brief review of ISO/IEC 27001:2013
- Overview of ISO/IEC 27001:2022
- Importance of Information Security Management Systems (ISMS)
Understanding the Changes
- ISO/IEC 27001:2013 vs. ISO/IEC 27001:2022
- Major changes in Annex A
- Updates to the clauses
- Implications of the title change
New Concepts and Elements in ISO/IEC 27001:2022
- Introduction to new concepts
- Risk management enhancements
- Enhanced focus on leadership and commitment
- Compliance and continuous improvement aspects
Transitioning to ISO/IEC 27001:2022
- Key steps for transitioning to the new standard
- Identifying areas of change
- Planning and implementing changes
- Transition timeline and deadlines
Auditing and Certification Process
- Changes in the auditing process for the 2022 standard
- Certification requirements and procedures
- Transition exam overview
- Compliance with PECB's code of ethics standards ISO/IEC 17024
Taking the Examination
- Registration procedures
- Tips and tricks for passing the exam
Summary and Next Steps
Requirements
- Fundamental understanding of the principles and concepts underpinning the ISO/IEC 27001:2013 standard
Target Audience
- Information security managers
- ISO/IEC 27001 auditors
- IT professionals
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
PECB ISO 27001:2022 Transition Training Course - Enquiry
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at intermediate-level IT auditors who wish to effectively incorporate AI tools in their audit practices.
By the end of this training, participants will be able to:
- Grasp the core concepts of artificial intelligence and how it is applied in the context of IT auditing.
- Utilize AI technologies such as machine learning, NLP, and RPA to improve audit efficiency, accuracy, and scope.
- Perform risk assessments using AI tools, enabling continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, enhancing the overall effectiveness of IT audits.
Micro Focus ArcSight ESM Advanced
35 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at advanced-level security analysts who wish to elevate their skills in utilizing advanced Micro Focus ArcSight ESM content to improve an organization's ability to detect, respond, and mitigate cyber threats with greater precision and speed.
By the end of this training, participants will be able to:
- Optimize the use of Micro Focus ArcSight ESM to enhance monitoring and threat detection capabilities.
- Construct and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules for effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
BCS Practitioner Certificate in Information Risk Management (CIRM)
35 HoursTarget Audience:
This certification is designed for any professional involved in the fields of information security and information assurance.
Learning Outcomes:
Upon completion, candidates will be able to demonstrate:
- The significant business benefits derived from effective information risk management.
- How to utilize information risk management terminology accurately and comprehensively.
- Methods for conducting threat and vulnerability assessments, business impact analyses, and risk assessments.
- The underlying principles of controls and risk treatment.
- Techniques for presenting results in a format suitable for developing a risk treatment plan.
- The application of information classification schemes.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Nigeria (online or onsite) is tailored for intermediate-level cybersecurity professionals seeking to deepen their knowledge of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Comprehend the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and formulate risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers an expert introduction to the newly enacted Accessibility Law, empowering developers with the practical skills needed to design, build, and maintain fully accessible applications. Beginning with a contextual discussion on the law's significance and implications, the course swiftly transitions into hands-on coding practices, tools, and testing techniques designed to ensure compliance and inclusivity for users with disabilities.
ISO 27001:2023 Internal Auditor of the Information Security Management System
35 HoursObjectives
- Acquire a thorough understanding of ISO 27001:2023
- Learn how to conduct audits in compliance with the standard
- Explore industry best practices
ISO 27001 Lead Auditor
35 HoursCourse Objectives
- Develop a comprehensive understanding of ISO 27001:2023.
- Acquire the skills to conduct audits in strict adherence to the standard.
- Learn and apply industry best practices.
ISO 27001:2023 Requirements
14 HoursObjectives
- To acquire knowledge regarding the updates in the ISO 27001 2023 edition
- To understand how to conduct audits in compliance with the standard
- To learn about industry best practices
PECB ISO/IEC 27001 Foundation
14 HoursWhy Should You Attend?
Through ISO/IEC 27001 Foundation training, you will acquire the essential knowledge required to implement and manage an Information Security Management System (ISMS) as outlined in ISO/IEC 27001. During this course, you will gain a clear understanding of the various components of an ISMS, such as ISMS policy, procedures, performance measurement, management commitment, internal audit, management review, and continuous improvement.
Upon successful completion of the course, you will be eligible to sit for the examination and apply for the “PECB Certified ISO/IEC 27001 Foundation” credential. Earning a PECB Foundation Certificate demonstrates your proficiency in the fundamental methodologies, requirements, frameworks, and management approaches associated with ISO/IEC 27001.
Who Should Attend?
- Professionals engaged in Information Security Management
- Individuals aiming to deepen their understanding of the key processes within Information Security Management Systems (ISMS)
- Aspiring experts looking to build a career in Information Security Management
Educational Approach
- Lectures are enriched with practical questions and real-world examples
- Practical exercises feature illustrative examples and group discussions
- Practice tests mirror the format and rigour of the official Certification Exam
PECB ISO/IEC 27001 Lead Implementer
35 HoursInformation security threats and attacks are constantly evolving and becoming more sophisticated. The most effective defence against these risks is the proper implementation and management of information security controls and best practices. Furthermore, robust information security is a critical expectation and requirement from customers, legislators, and other stakeholders.
This training course is designed to equip participants with the skills needed to implement an Information Security Management System (ISMS) based on ISO/IEC 27001. It aims to provide a comprehensive understanding of ISMS best practices and establish a framework for its ongoing management and improvement.
Upon completing the training course, you may sit for the exam. If you successfully pass, you can apply for the “PECB Certified ISO/IEC 27001 Lead Implementer” credential, which validates your practical knowledge and ability to implement an ISMS in accordance with ISO/IEC 27001 requirements.
Who Can Attend?
- Project managers and consultants involved in or concerned with the implementation of an ISMS
- Expert advisors seeking to master the implementation of an ISMS
- Individuals responsible for ensuring conformity to information security requirements within an organization
- Members of an ISMS implementation team
General information
- Certification fees are included in the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months free of charge
Educational approach
- This training course contains essay-type exercises, multiple-choice quizzes, examples, and best practices used in the implementation of an ISMS.
- The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
- The exercises are based on a case study.
- The structure of the quizzes is similar to that of the certification exam.
Learning objectives
This training course will help you:
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of an ISMS
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks
- Understand the operation of an information security management system and its processes based on ISO/IEC 27001
- Learn how to interpret and implement the requirements of ISO/IEC 27001 in the specific context of an organization
- Acquire the necessary knowledge to support an organization in effectively planning, implementing, managing, monitoring, and maintaining an ISMS
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 are globally recognised standards for Quality Management Systems (QMS) and Information Security Management Systems (ISMS), respectively.
This instructor-led live training, available both online and onsite, is designed for intermediate-level professionals aiming to interpret ISO 9001 and ISO 27001 standards and execute internal audits with effectiveness.
Upon completion of this training, participants will be capable of:
- Grasping the core principles and requirements of ISO 9001 and ISO 27001.
- Interpreting clauses and controls within real-world business contexts.
- Planning and carrying out internal audits in alignment with ISO standards.
- Identifying nonconformities and recommending appropriate corrective actions.
Course Format
- Interactive lectures and group discussions.
- Simulated auditing exercises and case study analyses.
- Practical examination of quality and security scenarios.
Customization Options
- To request bespoke training for this course, kindly contact us to arrange.
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This course is designed for all staff members who need a practical grasp of Compliance and effective Risk Management.
Course Format
The training employs a blended learning approach that includes:
- Guided discussions
- Slide-driven presentations
- Case studies
- Real-world examples
Course Objectives
Upon completing the course, participants will be able to:
Gain a robust understanding of the fundamental aspects of Compliance, alongside national and international initiatives geared towards managing related risks.
Articulate how organizations and their teams can build an effective Compliance Risk Management Framework.
Outline the duties of the Compliance Officer and the Money Laundering Reporting Officer, and comprehend how these roles fit into the broader business structure.
Pinpoint critical risk areas within Financial Crime, especially concerning international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursManaging Open Source Software (OSS) involves overseeing the entire lifecycle of open-source components within an organization to ensure they are used securely, compliantly, and efficiently.
This instructor-led, live training (available online or onsite) is designed for intermediate-level IT professionals who want to implement best practices for managing open-source software in enterprise and government settings.
By the end of this training, participants will be able to:
- Establish effective OSS policies and governance frameworks.
- Use SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks associated with licensing and security vulnerabilities.
- Streamline OSS adoption while maximizing innovation and cost savings.
Course Format
- Interactive lecture and discussion.
- Case studies and scenario-based exercises.
- Hands-on demonstrations with OSS management tools.
Customization Options
- This course can be tailored to specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Nigeria (online or onsite) provides an individual qualification for industry practitioners who wish to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
By the end of this training, participants will be able to:
- Understand the payment process and the PCI standards designed to protect it.
- Understand the roles and responsibilities for entities involved in the payment industry.
- Have deep insight into, and understanding of, the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and how it applies to organizations that are involved in the transaction process.