- Domain 1: Fundamental principles and concepts of information security, cybersecurity, and privacy
- Domain 2: Information security controls based on ISO/IEC 27002
- Certificate and examination fees are included in the price of the training course.
- Training material containing over 200 pages of information and practical examples will be distributed.
- An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
- In case of exam failure, you can retake the exam within 12 months for free.
Educational Approach
- This training course contains lecture sessions that are illustrated with practical questions and examples.
- The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
- The structure of quizzes is similar to that of the certificate exam.
Prerequisites
What is the ISO/IEC 27002 Foundation course?
The ISO/IEC 27002 Foundation course is an introductory training designed to provide a clear, structured understanding of the best practices for information security controls as outlined in the ISO/IEC 27002:2022 standard. It helps participants grasp the purpose and application of these controls within the broader framework of an Information Security Management System (ISMS). While ISO/IEC 27001 defines the requirements for information security, ISO/IEC 27002 serves as a detailed guideline for the selection, implementation, and management of security controls. This course offers a practical entry point into the world of ISO-based information security, especially for those seeking to understand the "how" behind effective cybersecurity governance.
Who should take the ISO/IEC 27002 Foundation course?
The course is intended for a broad audience, including IT professionals, compliance officers, junior security analysts, and anyone interested in acquiring a baseline understanding of ISO-standardized security controls. It is especially useful for individuals who are new to information security, supporting ISO/IEC 27001 implementation projects, or working in environments where data protection and risk management are priorities. Whether you're part of a security team or supporting one from another department, this course will help you understand how the controls contribute to an organization’s overall security posture.
What will I learn in the ISO/IEC 27002 Foundation course?
Participants will learn the foundational concepts of ISO/IEC 27002:2022, including the structure of the 93 controls grouped into four main domains: organizational, people, physical, and technological. The course explains how these controls are applied in practice, and how they can be selected and tailored based on the results of a risk assessment. It also covers the new classification attributes introduced in the 2022 version, such as control types, cybersecurity concepts, and operational capabilities. By the end of the training, learners will understand how ISO/IEC 27002 supports the implementation of ISO/IEC 27001 Annex A controls and how it can be used to guide the development of a security control framework.
How long is the ISO/IEC 27002 Foundation course?
The course runs for two days. It combines engaging lectures, interactive discussions, and sometimes practical exercises to help participants relate the content to real-world security scenarios. The concise duration makes it ideal for professionals looking to gain valuable knowledge without needing deep technical expertise or prior ISO experience.
Is there a certification exam included in the course?
Yes, the course includes a certification exam at the end. Participants who successfully pass the exam receive the ISO/IEC 27002 Foundation Certificate, which validates their basic understanding of information security controls and their ability to support ISO/IEC 27001-aligned projects. This credential is a great starting point for those looking to build a career in cybersecurity, compliance, or risk management.
