About this course
Information Security Management (ISO 27001) gives delegates a structured, practical understanding of ISO 27001 structure and requirements and information security risk assessment, then builds the skills to apply annex A controls, implementing an ISMS and internal audit and certification in real work. AI, data and cybersecurity courses for professionals and leaders, the most requested future skills in our 2030 demand plan.
Sessions are led by practitioners with at least 15 years in the field, and mix short input with exercises, case studies and group work, so delegates return with methods they can use straight away.
Who should attend
Managers, analysts, IT and OT professionals, and anyone leading or adopting digital and AI initiatives. No specialist prerequisites are required for the Practitioner level; Foundation, Advanced and Executive versions are available on request.
What you will learn
- ISO 27001 structure and requirements
- Information security risk assessment
- Annex A controls
- Implementing an ISMS
- Internal audit and certification
5-day course outline
- Day 1
ISO 27001 structure and requirements
Concepts, standards and terminology, with a diagnostic exercise to baseline the group.
- Day 2
Information security risk assessment
Methods and tools explained step by step, with worked examples from real operations.
- Day 3
Annex A controls
Hands-on practice in small groups using realistic data, cases and templates.
- Day 4
Implementing an ISMS
Case studies of successes and failures, and how to apply the lessons in your organisation.
- Day 5
Internal audit and certification
Integration exercise, final knowledge check and a personal action plan.
10-day extended programme
The extended programme includes the full 5-day outline above, plus a second week of applied work.
- Day 6
Applied workshop: ISO 27001 structure and requirements
Deeper practice with your own data or site examples.
- Day 7
Applied workshop: Information security risk assessment and annex A controls
Group exercises that combine methods from week one.
- Day 8
Field case study: Implementing an ISMS
A detailed industry case worked through from start to finish.
- Day 9
Advanced practice: Internal audit and certification
Tools, templates and checklists to take back to work.
- Day 10
Assessed project and presentation
Each delegate presents an improvement plan and completes the final assessment.
Upcoming classroom dates
| Dates | City | Length | Fee |
|---|---|---|---|
| 8 Nov 2026 to 12 Nov 2026 | Cairo | 5 days | $2,450 |
| 21 Dec 2026 to 25 Dec 2026 | London | 5 days | $3,450 |
| 11 Jan 2027 to 15 Jan 2027 | Dubai | 5 days | $2,450 |
| 1 Feb 2027 to 12 Feb 2027 | Istanbul | 10 days | $4,450 |
| 7 Mar 2027 to 18 Mar 2027 | Riyadh | 10 days | $4,450 |
| 11 Apr 2027 to 15 Apr 2027 | Cairo | 5 days | $2,450 |
| 10 May 2027 to 14 May 2027 | Barcelona | 5 days | $3,450 |
| 14 Jun 2027 to 18 Jun 2027 | Istanbul | 5 days | $2,450 |
| 12 Jul 2027 to 16 Jul 2027 | Kuala Lumpur | 5 days | $2,450 |
| 2 Aug 2027 to 13 Aug 2027 | London | 10 days | $6,250 |
Live online sessions run every month in GCC, Europe and Asia time slots. Other dates and cities on request.
Customise this course
Change the level, language, length and format, combine it with topics from other courses or ask for topics that are not in our catalogue, and add your own case studies, site visits or exam preparation. Open this course in the customiser to see the day-by-day outline and an instant indicative fee.
Frequently asked questions
How long is the Information Security Management (ISO 27001) course?
It runs as a 5-day core programme or a 10-day extended programme. The 10-day version adds a second week of workshops, case studies and an assessed project.
Where is the Information Security Management (ISO 27001) course held?
Classroom sessions run in Dubai, Istanbul, London, Kuala Lumpur and Cairo, with more cities opening to 2030. It is also available live online and in-house at your site.
Can the Information Security Management (ISO 27001) course be customised?
Yes. You can change the level, language, length from 1 to 20 days and format, add topics from other courses or new topics, and include your own case studies. Use the online customiser for an instant indicative fee.
How much does the Information Security Management (ISO 27001) course cost?
From $2,450 for 5 days in Dubai, Istanbul, Cairo or Kuala Lumpur, $3,450 in London, and $1,450 live online. In-house delivery for up to 15 delegates starts at $12,900.