Skip to main content
iso-frameworks

ISO27002 Foundation

ISO27002 Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants seeking to understand ISO/IEC 27002 information security controls
  • Professionals engaged in or responsible for information security management activities
  • Individuals looking to build foundational knowledge of ISMS processes and associated controls
  • Those considering a career in information security who want a structured entry point

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced information security professionals seeking advanced implementation or audit methodology training, as this is a foundational-level course
  • Individuals looking for deep technical hands-on security training such as penetration testing or security engineering
  • Those already holding PECB or equivalent ISO/IEC 27002 credentials who need continuing education at a higher level

What you'll be able to do

  • 1Explain the fundamental concepts of information security, cybersecurity, and privacy as described in ISO/IEC 27002
  • 2Describe the relationship between ISO/IEC 27001, ISO/IEC 27002, and other relevant standards and regulatory frameworks
  • 3Interpret ISO/IEC 27002 organisational controls and explain their application in an organisational context
  • 4Interpret ISO/IEC 27002 people controls and describe how they address human-related security risks
  • 5Interpret ISO/IEC 27002 physical controls and their role in protecting information assets
  • 6Interpret ISO/IEC 27002 technological controls and relate them to common information security scenarios

Day by day

Day 1Introduction to ISO/IEC 27002 and Organisational Controls
  • Fundamental Concepts of Information Security, Cybersecurity, and Privacy

    Core definitions and relationships among information security, cybersecurity, and privacy are introduced using the conceptual framework of ISO/IEC 27002.

  • ISO/IEC 27002 in Context: Standards and Regulatory Relationships

    The connection between ISO/IEC 27002, ISO/IEC 27001, and other standards and regulatory frameworks is explained to help participants understand where the standard fits.

  • Organisational Controls Overview

    The organisational controls category of ISO/IEC 27002 is examined, covering governance, policy, roles, and responsibilities for information security.

By end of day

  • Distinguish between information security, cybersecurity, and privacy in line with ISO/IEC 27002
  • Explain how ISO/IEC 27002 supports and complements ISO/IEC 27001
Day 2People, Physical, and Technological Controls
  • People Controls

    Controls addressing human behaviour, screening, terms of employment, security awareness, and disciplinary processes are reviewed in the context of ISO/IEC 27002.

  • Physical Controls

    Controls designed to protect physical environments, equipment, and media from security threats are examined using ISO/IEC 27002 guidance.

  • Technological Controls

    Technology-focused controls covering access management, cryptography, network security, and monitoring are introduced and contextualised within an organisational setting.

By end of day

  • Classify information security controls across the four ISO/IEC 27002 categories
  • Relate specific controls to practical organisational security scenarios

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security, cybersecurity, and privacy
  • Domain 2: Information security controls based on ISO/IEC 27002
  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational Approach

  • This training course contains lecture sessions that are illustrated with practical questions and examples.
  • The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
  • The structure of quizzes is similar to that of the certificate exam.

Prerequisites

What is the ISO/IEC 27002 Foundation course?

The ISO/IEC 27002 Foundation course is an introductory training designed to provide a clear, structured understanding of the best practices for information security controls as outlined in the ISO/IEC 27002:2022 standard. It helps participants grasp the purpose and application of these controls within the broader framework of an Information Security Management System (ISMS). While ISO/IEC 27001 defines the requirements for information security, ISO/IEC 27002 serves as a detailed guideline for the selection, implementation, and management of security controls. This course offers a practical entry point into the world of ISO-based information security, especially for those seeking to understand the "how" behind effective cybersecurity governance.

Who should take the ISO/IEC 27002 Foundation course?

The course is intended for a broad audience, including IT professionals, compliance officers, junior security analysts, and anyone interested in acquiring a baseline understanding of ISO-standardized security controls. It is especially useful for individuals who are new to information security, supporting ISO/IEC 27001 implementation projects, or working in environments where data protection and risk management are priorities. Whether you're part of a security team or supporting one from another department, this course will help you understand how the controls contribute to an organization’s overall security posture.

What will I learn in the ISO/IEC 27002 Foundation course?

Participants will learn the foundational concepts of ISO/IEC 27002:2022, including the structure of the 93 controls grouped into four main domains: organizational, people, physical, and technological. The course explains how these controls are applied in practice, and how they can be selected and tailored based on the results of a risk assessment. It also covers the new classification attributes introduced in the 2022 version, such as control types, cybersecurity concepts, and operational capabilities. By the end of the training, learners will understand how ISO/IEC 27002 supports the implementation of ISO/IEC 27001 Annex A controls and how it can be used to guide the development of a security control framework.

How long is the ISO/IEC 27002 Foundation course?

The course runs for two days. It combines engaging lectures, interactive discussions, and sometimes practical exercises to help participants relate the content to real-world security scenarios. The concise duration makes it ideal for professionals looking to gain valuable knowledge without needing deep technical expertise or prior ISO experience.

Is there a certification exam included in the course?

Yes, the course includes a certification exam at the end. Participants who successfully pass the exam receive the ISO/IEC 27002 Foundation Certificate, which validates their basic understanding of information security controls and their ability to support ISO/IEC 27001-aligned projects. This credential is a great starting point for those looking to build a career in cybersecurity, compliance, or risk management.

Buyers always ask

What is the difference between ISO/IEC 27001 and ISO/IEC 27002, and which should I study first?+

ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS and is the standard against which organisations seek certification. ISO/IEC 27002 provides guidance on selecting and implementing the information security controls referenced in ISO/IEC 27001's Annex A.

For someone new to the field, this ISO/IEC 27002 Foundation course is a practical starting point because it builds control literacy that is directly useful when later engaging with ISO/IEC 27001 implementation or audit courses.

Is any prior security knowledge required to attend this course?+

No prior formal qualifications or certifications are required. The course is designed to be accessible to individuals at the beginning of their information security learning journey as well as to managers and non-technical professionals who need structured control knowledge.

What does completing this training course provide, and what is separate from it?+

Completing the two-day Cyber Academy training course means you have attended and engaged with the curriculum covering ISO/IEC 27002 Foundation content.

The PECB Foundation exam and the resulting PECB Certificate Holder credential are separate from the training itself. Exam registration, sitting, and any associated fees are governed by PECB independently of Cyber Academy's course offering.

How does the ISO/IEC 27002 Foundation course relate to the ISO/IEC 27002 Lead Manager course?+

The Foundation course provides an introductory understanding of what the four control categories in ISO/IEC 27002 cover and how they relate to an ISMS. It is suitable for those needing awareness-level knowledge.

The Lead Manager course is a five-day advanced programme designed for professionals who need to determine, implement, and manage those controls within an organisation. Completing Foundation first is a logical progression for those planning to pursue Lead Manager in the future.

What control categories does ISO/IEC 27002 cover, and are all of them addressed in this course?+

ISO/IEC 27002 organises its guidance into four control categories: organisational, people, physical, and technological. All four categories are addressed across the two days of this course, with Day 1 focusing on organisational controls and Day 2 covering the remaining three categories.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.