Cybersecurity Management with ISO/IEC 27001
What you'll learn
- Principles and concepts in cybersecurity
- Threats and vulnerabilities
- Risks and controls
- Best practices for a succesful cybersecurity program
- How ISO/IEC 27001 requirements apply to cybersecurity
- Common attacks, how they work and how they can be prevented
Requirements
- Familiarity with information security concepts
- A general understanding of IT
Description
This course teaches the foundations of cybersecurity management through the lens of ISO/IEC 27001, the leading international standard for information security. You will learn the concepts, principles and controls an organization needs to design and run a cybersecurity program: the typical security threats facing different activities and processes, and the recommended controls to protect against them.
Course structure
Foundations — cyberspace and cybersecurity defined; confidentiality, integrity, authentication and non-repudiation as critical elements of any security system
Information classification — schemes, levels and labelling
Risk management — threats, vulnerabilities, risk assessment (quantitative and qualitative methods), and the options for treating security risks
Organizing security — top management support, segregation of duties, and human resources security from screening and contractual requirements through the disciplinary process to termination and change of employment
Devices and media — mobile device policies including BYOD (bring your own device) and COPE (company owned, personally enabled), and the rules for removable media
Access control and authentication — managing access rights and privileges so they don't become security breaches; password management, common password attacks and their controls
Cryptography — core concepts, digital signatures and public key infrastructure (PKI), plus the most common cryptographic attacks (brute force, rainbow tables, birthday attacks) and how to defend against them
Attacks and malware — viruses, worms, trojans, logic bombs, spyware and adware, with a detailed presentation of ransomware; denial-of-service attacks; social engineering and phishing
Operational security — physical and equipment security, backups, change management, capacity management, email security, network security principles and controls, wireless attacks and their prevention, and security in development processes
Suppliers and third parties — the risks associated with suppliers' access to your information assets
Incident management and continuity — managing cybersecurity incidents from detection to closure and root cause analysis; business continuity and preparing for crisis situations
Compliance — the compliance requirements every organization must respect
Learning from real cases
The concepts are illustrated with easy-to-follow explanations, examples and case studies — including the Barings Bank collapse, the Target security breach and Edward Snowden — plus a quiz at the end to test what you've learned.
Who this course is for
IT professionals moving into cybersecurity or security management roles
Managers and business owners who need to understand how to protect their organization
Professionals supporting an ISO/IEC 27001 information security management system from the technical side
Students and career-changers building cybersecurity fundamentals
Anyone who wants to understand threats — from ransomware to phishing — and the controls that stop them
Get the knowledge you need to design, coordinate and improve a cybersecurity program — or to understand security the way ISO/IEC 27001 approaches it.
Who this course is for:
- Cybersecurity managers
- Information security officers
- ISO/IEC 27001 auditors and consultants
- Security professionals
- Professionals tasked with implementing or administrating a management system as per ISO 27001
- Security practitioners interested in the ISO 27001 framework
- People looking for a career in cyber security
- IT professionals looking to enhance their knowledge
Instructor
Who am I?
I’ve been working in the field of standards, auditing, and certification since the early 2000s. Over the years, I’ve contributed to hundreds of projects across various industries and disciplines. Today, I work with RIGCERT, an accredited certification body based in Europe.
What do I do?
I translate the knowledge and best practices from international standards and recognized compliance frameworks into clear, practical language — to help individuals and organizations improve.
How do I teach?
I design and record every course myself. You will be learning from a human instructor with real-world auditing experience — not from AI-generated content. Since launching my first course in 2016, my focus has always been on extracting the core ideas from complex subjects and delivering them in a clear, concise format. I only build and publish courses that I myself would take.
What are my interests?
My work spans quality management, information security, data protection and privacy, artificial intelligence governance, risk management, business continuity, occupational health and safety, environmental management, energy management, compliance, food safety, and others.
