
ISO/IEC 27002 Manager
Course Overview
Information security controls are essential for protecting organizational information assets and mitigating cybersecurity risks. The ISO/IEC 27002 Manager course provides participants with a practical understanding of how to select, implement, manage, and evaluate information security controls in accordance with ISO/IEC 27002.
Through instructor-led sessions, practical exercises, and real-world case studies, participants will gain the competencies needed to manage organizational, people, physical, and technological controls, monitor their effectiveness, and support continual improvement within an Information Security Management System (ISMS).
Target Audience
This course is intended for:
- Information Security Managers
- Information Security Officers
- ISMS team members
- IT Managers and System Administrators
- Cybersecurity Professionals
- Risk Management Professionals
- Compliance and Governance Professionals
- Internal Auditors
- Security Consultants
- Professionals responsible for implementing and managing information security controls
Learning Objectives
Upon successful completion of this course, participants will be able to:
- Understand the purpose and structure of ISO/IEC 27002.
- Explain the relationship between ISO/IEC 27002 and ISO/IEC 27001.
- Select and implement information security controls using a risk-based approach.
- Manage organizational, people, physical, and technological controls.
- Monitor and evaluate the effectiveness of implemented controls.
- Support the implementation and maintenance of an ISMS.
- Identify opportunities for continual improvement.
- Prepare for the PECB ISO/IEC 27002 Manager certification examination.
Duration
4 Days (Three days of instructor-led training followed by the certification examination on Day 4.)
Classroom
Participants attend instructor-led classroom sessions featuring lectures, interactive discussions, practical workshops, case studies, and implementation exercises focused on managing information security controls.
Certification
After successfully passing the examination and meeting the applicable certification requirements, participants may apply for the:
PECB Certified ISO/IEC 27002 Manager
The certification validates the candidate’s competence in managing information security controls based on ISO/IEC 27002 and supporting the implementation of an effective ISMS.
Course Agenda
Day 1: Introduction to ISO/IEC 27002 and Information Security Controls
- Training course objectives and structure
- Overview of ISO/IEC 27002
- Relationship between ISO/IEC 27002 and ISO/IEC 27001
- Information security concepts and principles
- Organizational controls
- People controls
Day 2: Implementing Information Security Controls
- Physical controls
- Technological controls
- Risk-based control selection
- Access control
- Cryptography
- Operational security
Day 3: Monitoring and Improving Information Security Controls
- Monitoring control effectiveness
- Performance evaluation
- Internal audits
- Corrective actions
- Continual improvement
- Course review and examination preparation
Day 4: Certification Examination
- PECB ISO/IEC 27002 Manager Certification Examination
Exam Duration
- Exam Duration: 2 hours
- Exam Format: Closed-book examination consisting of multiple-choice and scenario-based questions.
- Passing Score: Determined by PECB in accordance with its certification policies.
Successful candidates who meet PECB’s certification requirements may apply for the PECB Certified ISO/IEC 27002 Manager credential.
