Skip to content
AfriScienceGroup home
Cybersecurity and IT

Implementing an Information Security Management System to ISO/IEC 27001

Certification to the information security standard is increasingly demanded by customers and lenders, and organisations commonly pursue it by writing policies that describe an organisation they do not have. This course covers building the real thing. Delegates work through scope definition and why an overly broad scope sinks a first certification, the risk assessment and treatment process that drives every control decision, and the statement of applicability that records it. Control selection is covered against the annex, with the justification each inclusion and exclusion requires. Documented information, competence and awareness follow. Internal audit, management review and corrective action are addressed. The course closes on the certification audit and on operating the system afterwards.

Course objectives

  • Define a scope that can actually be certified
  • Run risk assessment and treatment to drive control decisions
  • Produce a statement of applicability with defensible justification
  • Select and implement controls proportionate to the risk
  • Maintain documented information, competence and awareness
  • Run internal audit, management review and corrective action
  • Prepare for the certification audit and operate the system afterwards

Who should attend

  • Information security managers and officers
  • IT managers and system owners
  • Compliance, risk and quality staff
  • Internal auditors covering information security
  • Consultants implementing management systems

Course outline

  1. 01Policies describing an organisation you do not have
  2. 02Scope definition and its consequences
  3. 03Risk assessment and treatment
  4. 04The statement of applicability
  5. 05Control selection and justification
  6. 06Documented information, competence and awareness
  7. 07Internal audit and management review
  8. 08Certification audit and ongoing operation

Scheduled sessions

Scheduled sessions for Implementing an Information Security Management System to ISO/IEC 27001
DatesVenueFormatPriceRegister
9 to 13 November 2026Kampala, UgandaClassroomUSD 1,325 per delegateRegister Now
7 to 11 December 2026Cape Town, South AfricaClassroomR19,950 per delegateRegister Now
18 to 22 January 2027Lagos, NigeriaClassroomUSD 1,325 per delegateRegister Now
1 to 5 February 2027OnlineOnlineR8,500 per delegateRegister Now

Implementing an Information Security Management System to ISO/IEC 27001

From R8,500

AskRegister