Standard

ISO 27001 Training

ISO 27001 training covers auditing and implementing an information security management system to ISO/IEC 27001. MEGADEMİ delivers 4 ISO/IEC 27001 courses across auditor, implementer and specialist levels, online, in-person and blended.

About ISO/IEC 27001

ISO/IEC 27001 is the international standard for information security management systems. It requires risk assessment and risk treatment, a statement of applicability against the Annex A control set, security objectives, competence and awareness, monitoring, internal audit and improvement.

The 2022 edition restructured the Annex A controls into four themes — organisational, people, physical and technological — which changed statements of applicability and audit checklists across the industry.

Because the standard sits close to technical practice, MEGADEMİ's information security catalogue extends beyond auditor and implementer training into specialist manager and examiner programmes covering areas such as network, application, cloud and privacy controls.

Where it applies

  • Software, SaaS and technology services
  • Financial services and insurance
  • Healthcare and health data processors
  • Public sector and critical infrastructure
  • Any supplier answering customer security questionnaires or contractual security clauses

ISO/IEC 27001 courses by level

Choosing a level

The training discipline decides what you will be able to do afterwards. Read the discipline pages if you are not sure which level fits your role.

Corporate and in-house delivery

ISO/IEC 27001 training can be delivered for one organisation only, online, in person or blended, using your own scope and documents as the working material.

Provider status

MEGADEMI-EUROTECH LLC is a Certified Training Provider of Exemplar Global and is listed in the Exemplar Global Client Register. Online, in-person and blended delivery, worldwide.

Corporate ISO training

Frequently asked questions

Which ISO 27001 course is right for me?+

Internal auditor to audit your own ISMS, lead auditor to lead audits or audit other organisations, lead implementer to build the ISMS and its risk treatment. Specialist manager programmes suit people who own a specific control domain.

Do I need a technical background?+

Auditor and implementer courses are management system courses and are taken successfully by non-technical delegates. The specialist manager and examiner programmes assume relevant technical experience.

Do the courses cover the 2022 Annex A structure?+

Each course title shows the edition it covers. Check the course page before booking if the Annex A structure matters to your project.

Talk to us about ISO/IEC 27001 training

Tell us the standard, the level and how many people need training, and the training team will come back with the options that fit.