Skip to Main
ICO ISMS 27001:2022 FND

ICO ISMS 27001:2022 FND

A two-day introduction to information security management under ISO/IEC 27001:2022. You learn the structure of an ISMS, the requirements clause by clause, and what the 93 Annex A controls are for. Prepares you for the ICO ISMS 27001:2022 FND exam. No prior standards experience needed.

Duration
12 hours
Format
Online
Price
100 credits
Certification exam
Optional add-on
Next date
Nov 2, 2026 – Nov 3, 2026

Next dates

Sign up for training

About this course

Customers ask for it, insurers price it, and more and more contracts simply require it. ISO/IEC 27001 has become the language organisations use to prove that information security is managed rather than hoped for. The 2022 revision reshaped Annex A into 93 controls across four themes, and anyone working near security is now expected to know their way around it.

This foundation course walks through the standard over two instructor led days. You learn what an information security management system is, what each clause of the standard actually requires, and how the Annex A controls answer the risks you identify. You leave able to read the standard with confidence, take part in a certification project and understand what an auditor is looking at.

Who this course is for

  • IT, security and operations staff whose organisation is heading towards certification
  • Quality and compliance managers adding information security to their remit
  • Project managers and consultants joining an ISMS implementation
  • Anyone who has to answer security questionnaires from customers and wants to understand what is being asked
  • Future ISMS Security Officers and ISMS Auditors, for whom this is the first step

What you will learn

  • Use the vocabulary of the standard correctly: confidentiality, integrity, availability, risk, control, conformity, corrective action
  • Explain what an information security management system is and how the Plan, Do, Check, Act cycle keeps it running
  • Work through the requirements clause by clause, from the context of the organisation to continual improvement
  • Read Annex A: how the 93 controls are grouped and how they follow from a risk assessment
  • Recognise how the wider ISO/IEC 27000 family, and topics such as business continuity and data protection, connect to the standard
  • Understand what happens in a certification audit and what evidence it rests on

Course outline

Day one, the management system

  • How the course and the exam are structured
  • Terms and definitions
  • Information security management systems, what they are and why they work
  • Context of the organisation, interested parties and scope
  • Leadership, policy and roles
  • Planning, risk assessment and risk treatment

Day two, running it and proving it

  • Support: competence, awareness, communication and documented information
  • Operation, the part where the system meets daily work
  • Performance evaluation, monitoring, internal audit and management review
  • Improvement, nonconformity and corrective action
  • Annex A, the reference control objectives across all four themes
  • Related topics and how the standards family fits together
  • Exam preparation and sample questions

Prerequisites

None. Participants should bring a general understanding of how organisations work and an interest in IT security. No technical or audit background is assumed.

Exam and certification

The course prepares you for the ICO ISMS 27001:2022 FND examination, awarded by ICO International Certification Organization GmbH. It is an accredited certification exam, not a certificate of attendance.

  • 30 multiple choice questions, where one, several or all options may be correct
  • 45 minutes, closed book
  • Pass mark of 60 percent
  • Taken online, at a time and place you choose

The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.

What is included

  • Two days, 12 hours, of instructor led classroom training in English
  • Groups of up to 40 participants
  • Complete course materials, exercises and sample exam questions
  • Worked examples from European organisations in every block
  • Certificate of attendance, with the ICO ISMS 27001:2022 FND exam as an optional add on

Curriculum

Chapters follow the official ICO syllabus. The percentage is the share of the exam each chapter accounts for.

Accreditations & certifications

This course prepares you for the following certification schemes.

Upcoming events

Have a question about this course?
Ask about dates, team delivery, or anything else — we reply within one business day.

Professional training in AI, AIMS (Artificial Intelligence Management Systems according to ISO 42001), ISMS (Information Security Management Systems according to ISO 27001) and IT Penetration Testing, designed for teams that take outcomes seriously.

© 2026 Professional Training Organisation Serbia. All rights reserved.

v1.1.3 · 2026-10-02 21:39 UTC