Skip to main content
ISO 27001

ISO27001 - Foundation

ISO27001 - Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants seeking an introductory understanding of information security management
  • Professionals wanting to become familiar with the requirements of ISO/IEC 27001:2022 for an ISMS
  • Individuals engaged in or responsible for information security activities within their organisation
  • People considering a career in information security who want a recognised foundation-level starting point

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced information security professionals who already design or operate ISMS programmes and need advanced or practitioner-level training
  • Professionals looking for hands-on implementation or audit methodology, as this course covers foundational awareness only
  • Those seeking a lead implementer or lead auditor credential, which require separate, longer programmes

What you'll be able to do

  • 1Describe the main information security management concepts, principles, and definitions relevant to an ISMS
  • 2Explain the core requirements of ISO/IEC 27001:2022 for establishing and maintaining an information security management system
  • 3Identify approaches, methods, and techniques used in the implementation and management of an ISMS
  • 4Distinguish between the two competency domains assessed in the PECB ISO/IEC 27001 Foundation examination
  • 5Recognise the scope and structure of ISO/IEC 27001:2022 as the basis for further study or professional development in information security

Day by day

Day 1Introduction to ISMS concepts as required by ISO/IEC 27001:2022
  • Information security management fundamentals

    Participants explore the core concepts, terminology, and principles that underpin information security management and the ISO/IEC 27001:2022 standard.

  • Structure and purpose of an ISMS

    This module explains what an information security management system is, why organisations implement one, and how ISO/IEC 27001:2022 provides the governing framework.

By end of day

  • Articulate the key concepts and terminology of information security management
  • Explain the purpose and scope of ISO/IEC 27001:2022 as a framework for an ISMS
Day 2ISMS requirements and preparation for the certificate examination
  • ISO/IEC 27001:2022 requirements in practice

    Participants examine the specific ISMS requirements across the clauses of ISO/IEC 27001:2022, including context, leadership, planning, support, operation, evaluation, and improvement.

  • ISMS implementation and management approaches

    This module introduces methods and techniques organisations use to implement and sustain an ISMS, providing practical context for the standard's requirements.

  • Examination preparation and domain review

    A structured review of both competency domains helps participants consolidate knowledge before sitting the PECB ISO/IEC 27001 Foundation examination.

By end of day

  • Summarise the ISO/IEC 27001:2022 clause requirements and how they interrelate within an ISMS
  • Identify practical approaches used to implement and manage an ISMS
  • Recognise the two competency domains assessed in the foundation examination

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

The exam fully meets the requirements of the PECB Examination and Certificate Programme. It covers the following competency domains:

  • Domain 1: Fundamental principles and concepts of an Information Security Management System (ISMS)
  • Domain 2: Information Security Management System (ISMS)

First, a candidate needs to complete the PECB ISO/IEC 27001 Foundation training course. Then, they need to take the exam and after successfully passing the exam, candidates will be able to apply for the “PECB Certificate Holder in ISO/IEC 27001 Foundation” certificate. This is an entry-level credential.

There are no prerequisites on professional or management system project experience required. Thus, following the training course, passing the exam and applying for the certificate are the only certificate program requisites that certificate holders shall meet before obtaining the certificate.

The certificate requirements for theISO/IEC 27001 Foundation are:

  • Certificate and examination fees are included in the price of the training course
  • Training material containing over 200 pages of information and practical examples will be distributed
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course
  • In case of exam failure, you can retake the exam within 12 months for free

Why should you attend?

ISO/IEC 27001

Educational approach

  • Lecture sessions are illustrated with practical questions and examples
  • Practical exercises include examples and discussions
  • Practice tests are similar to the Certificate Exam

Prerequisites

None

What is the ISO27001 Foundation course?

The ISO27001 Foundation course provides a comprehensive introduction to the ISO27001 standard, its requirements, and the key elements of an Information Security Management System (ISMS). It is designed to help individuals understand the principles of data security and the steps necessary to protect information assets.

Who should take the ISO27001 Foundation course?

This course is ideal for anyone new to information security who needs a clear understanding of the concepts and practices around ISO27001. It's particularly beneficial for IT professionals, security officers, or anyone involved in data protection or compliance within their organization.

What will I learn in the ISO27001 Foundation course?

Participants will learn the basics of ISO27001, including the framework and processes necessary to build, implement, and manage an effective ISMS. The course covers risk management, security controls, and compliance with legal and regulatory requirements.

How long is the ISO27001 Foundation course?

The course typically lasts two days and includes a mix of lectures, interactive discussions, and practical exercises to ensure that participants can apply what they have learned in a real-world context.

Is there a certification exam included in the course?

Yes, the ISO27001 Foundation course concludes with an exam. Successfully passing the exam will award participants with a certificate, demonstrating their foundational knowledge of ISO27001 and their ability to support the implementation of an effective ISMS in their organization.

Buyers always ask

What is the difference between completing the training course and obtaining the PECB certificate?+

Completing the two-day training means you have attended all sessions and received the course materials. Completion alone does not award a certificate.

To obtain the 'PECB Certificate Holder in ISO/IEC 27001:2022 Foundation' credential, you must separately sit and pass the PECB examination, then submit a certificate application to PECB. Training completion, passing the exam, and applying for the certificate are three distinct steps.

What topics does the PECB ISO/IEC 27001 Foundation examination cover?+

The examination is structured around two competency domains: Domain 1 addresses fundamental principles and concepts of an ISMS, and Domain 2 covers the ISMS requirements of ISO/IEC 27001:2022.

For details on exam format, available languages, and scheduling, refer to the PECB List of Exams and the Examination Rules and Policies on the PECB website.

Do I need prior information security experience to attend this course?+

No prior professional experience or management system project experience is required. The course is designed as an entry-level introduction suitable for anyone wanting to understand ISO/IEC 27001:2022 and information security management fundamentals.

Is this course appropriate if I already work in an information security role?+

This foundation course is aimed at building awareness and introductory understanding rather than developing practitioner skills. If you already design, implement, or audit ISMS programmes, you are likely to find the ISO/IEC 27001 Lead Implementer or Lead Auditor programmes more relevant to your professional development.

What study materials are provided during the course?+

According to PECB, participants receive training materials containing over 200 pages of information and practical examples to support learning throughout and after the course.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.