PECB ISO 27001:2022 Transition Training Course
ISO 27001:2022 is a standard for information security management systems, offering a set of criteria for compliance certification for organizations and professionals. This standard aids in the creation, implementation, upkeep, and enhancement of an information security management system (ISMS).
This instructor-led, live training (online or onsite) is aimed at intermediate to expert-level IT professionals who wish to enhance their skills and qualifications in information security or related fields.
By the end of this training, participants will be able to:
- Understand the differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022.
- Gain the knowledge and skills to plan and implement the transition from the 2013 to the 2022 version of the standard efficiently.
- Apply the knowledge in real-world scenarios, facilitating a smooth transition in their respective organizations.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Introduction
- Brief review of ISO/IEC 27001:2013
- Overview of ISO/IEC 27001:2022
- Importance of Information Security Management Systems (ISMS)
Understanding the Changes
- ISO/IEC 27001:2013 vs. ISO/IEC 27001:2022
- Major changes in Annex A
- Updates to the clauses
- Implications of the title change
New Concepts and Elements in ISO/IEC 27001:2022
- Introduction to new concepts
- Risk management enhancements
- Enhanced focus on leadership and commitment
- Compliance and continuous improvement aspects
Transitioning to ISO/IEC 27001:2022
- Key steps for transitioning to the new standard
- Identifying areas of change
- Planning and implementing changes
- Transition timeline and deadlines
Auditing and Certification Process
- Changes in the auditing process for the 2022 standard
- Certification requirements and procedures
- Transition exam overview
- Compliance with PECB's code of ethics standards ISO/IEC 17024
Taking the Examination
- Registration procedures
- Tips and tricks for passing the exam
Summary and Next Steps
Requirements
- Basic understanding of the principles and concepts of the ISO/IEC 27001:2013 standard
Audience
- Information security managers
- ISO/IEC 27001 auditors
- IT professionals
Need help picking the right course?
macao@nobleprog.com or +852 81990613
PECB ISO 27001:2022 Transition Training Course - Enquiry
PECB ISO 27001:2022 Transition - Consultancy Enquiry
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
The way to receive the information from the trainer
Mohamed Romdhani - Shams Power
Course - CISM - Certified Information Security Manager
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in Macao (online or onsite) is aimed at intermediate-level IT auditors who wish to effectively incorporate AI tools in their audit practices.
By the end of this training, participants will be able to:
- Grasp the core concepts of artificial intelligence and how it is applied in the context of IT auditing.
- Utilize AI technologies such as machine learning, NLP, and RPA to improve audit efficiency, accuracy, and scope.
- Perform risk assessments using AI tools, enabling continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, enhancing the overall effectiveness of IT audits.
Micro Focus ArcSight ESM Advanced
35 HoursThis instructor-led, live training in Macao (online or onsite) is aimed at advanced-level security analysts who wish to elevate their skills in utilizing advanced Micro Focus ArcSight ESM content to improve an organization's ability to detect, respond, and mitigate cyber threats with greater precision and speed.
By the end of this training, participants will be able to:
- Optimize the use of Micro Focus ArcSight ESM to enhance monitoring and threat detection capabilities.
- Construct and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules for effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
CCTV Security
14 HoursThis instructor-led, live training in Macao (online or onsite) is aimed at security managers who wish to learn basic to intermediate-level CCTV security surveillance and management skills.
By the end of this training, participants will be able to:
- Familiarize the types of CCTV systems and know their benefits and features.
- Understand cabling and CCTV systems setup requirements.
- Install, configure, and manage CCTV systems.
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in Macao (online or onsite) is aimed at advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
By the end of this training, participants will be able to:
- Gain comprehensive knowledge of fraud examination principles and the fraud examination process.
- Learn to identify, investigate, and prevent various types of financial fraud schemes.
- Understand the legal environment related to fraud, including the legal elements of fraud, relevant laws, and regulations.
- Acquire practical skills in conducting fraud investigations, including evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Gain confidence and knowledge to successfully pass the Certified Fraud Examiner (CFE) exam.
CISM - Certified Information Security Manager
28 HoursDescription:
Disclaimer: Please be advised that this updated CISM exam content outline is applicable to exams starting 1 June 2022.
CISM® is the most prestigious and demanding qualification for Information Security Managers around the globe today. This qualification provides you with a platform to become part of an elite peer network who have the ability to constantly learn and relearn the growing opportunities/ challenges in Information Security Management.
Our CISM training methodology provides an in-depth coverage of contents across the Four CISM domains with a clear focus on building concepts and solving ISACA released CISM exam questions. The course is an intense training and hard-core exam preparation for ISACA’s Certified Information Security Manager (CISM®) Examination.
Our instructors encourage all attending delegates to go through the ISACA released CISM QA&E (Questions, Answers and Explanations) as exam preparation. The QA&E is exceptional in helping delegates understand the ISACA style of questions, approach to solving these questions and it helps rapid memory assimilation of the CISM concepts during live classroom sessions.
All our trainers have extensive experience in delivering CISM training. We will thoroughly prepare you for the CISM examination.
Goal:
The ultimate goal is to pass your CISM examination first time.
Objectives:
- Use the knowledge gained in a practical manner beneficial to your organisation
- Establish and maintain an Information security governance framework to achieve your organization goals and objectives
- Manage Information risk to an acceptable level to meet the business and compliance requirements
- Establish and maintain information security architectures (people, process, technology)
- Integrate information security requirements into contracts and activities of third parties/ suppliers
- Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimize business impact
Target Audience:
- Security professionals with 3-5 years of front-line experience
- Information security managers or those with management responsibilities
- Information security staff, information security assurance providers who require an in-depth understanding of information security management including: CISO’s, CIO’s, CSO’s, privacy officers, risk managers, security auditors and compliance personnel, BCP / DR personnel, executive and operational managers responsible for assurance functions
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Macao (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Cybersecurity Fundamentals
28 HoursDescription:
Cybersecurity skills are in high demand, as threats continue to plague enterprises around the world. An overwhelming majority of professionals surveyed by ISACA recognise this and plan to work in a position that requires cybersecurity knowledge.
To fill this gap, ISACA has developed the Cybersecurity Fundamentals Certificate, which provides education and verification of skills in this area.
Objectives:
With cybersecurity threats continuing to rise and the shortage of appropriately-equipped security professionals growing worldwide, ISACA's Cybersecurity Fundamentals Certificate programme is the perfect way to quickly train entry-level employees and ensure they have the skills and knowledge they need to successfully operate in the Cyber arena.
Target Audience:
The certificate program is also one of the best ways to gain foundational knowledge in cybersecurity and begin to build your skills and knowledge in this crucial area.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course provides an expert introduction to the newly enacted Accessibility Law and equips developers with the practical skills to design, develop, and maintain fully accessible applications. Starting with a contextual discussion on the law's importance and implications, the course quickly shifts to hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
ISO 27001:2023 Internal Auditor of the Information Security Management System
35 HoursObjectives
- Gaining knowledge of ISO 27001:2023
- Gaining knowledge on how to audit in accordance with the standard
- Getting to know good practices
ISO 27001 Lead Auditor
35 HoursObjectives
- Gaining knowledge of ISO 27001:2023
- Gaining knowledge on how to audit in accordance with the standard
- Getting to know good practices
ISO 27001:2023 Requirements
14 HoursObjectives
- Gaining knowledge about changes to ISO 27001 2023 edition
- Gaining knowledge on how to audit in accordance with the standard
- Getting to know good practices
ISO 9001 and ISO 27001 – Interpretation and Internal Auditor
21 HoursISO 9001 and ISO 27001 are internationally recognized standards for quality and information security management systems, respectively.
This instructor-led, live training (online or onsite) is aimed at intermediate-level professionals who wish to interpret ISO 9001 and ISO 27001 standards and perform internal audits effectively.
By the end of this training, participants will be able to:
- Understand the principles and requirements of ISO 9001 and ISO 27001.
- Interpret the clauses and controls in real-world contexts.
- Plan and conduct internal audits aligned with ISO standards.
- Identify nonconformities and recommend corrective actions.
Format of the Course
- Interactive lecture and discussion.
- Simulated auditing exercises and case studies.
- Hands-on analysis of quality and security scenarios.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Compliance and the Management of Compliance Risk
21 HoursAudience
This course is intended for all employees who require a practical understanding of Compliance and effective Risk Management.
Format of the course
The training is delivered through a blended approach that includes:
- Facilitated discussions
- Slide-based presentations
- Case studies
- Real-world examples
Course Objectives
By the end of the course, participants will be able to:
Develop a solid understanding of the key aspects of Compliance, along with national and international initiatives aimed at managing associated risks.
Explain how organizations and their teams can establish an effective Compliance Risk Management Framework.
Describe the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles integrate within a business structure.
Identify critical risk areas in Financial Crime, particularly in the context of international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management is the practice of overseeing the lifecycle of open-source components within an organization, ensuring secure, compliant, and efficient use.
This instructor-led, live training (online or onsite) is aimed at intermediate-level IT professionals who wish to implement best practices for managing open-source software in enterprise and government environments.
By the end of this training, participants will be able to:
- Establish effective OSS policies and governance frameworks.
- Use SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks associated with licensing and security vulnerabilities.
- Streamline OSS adoption while maximizing innovation and cost savings.
Format of the Course
- Interactive lecture and discussion.
- Case studies and scenario-based exercises.
- Hands-on demonstrations with OSS management tools.
Course Customization Options
- This course can be tailored to specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Macao (online or onsite) provides an individual qualification for industry practitioners who wish to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
By the end of this training, participants will be able to:
- Understand the payment process and the PCI standards designed to protect it.
- Understand the roles and responsibilities for entities involved in the payment industry.
- Have deep insight into, and understanding of, the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and how it applies to organizations that are involved in the transaction process.