
ICO ISMS 27001:2022 Security Officer
Three days of practical ISMS work for the person who will run it. You implement ISO/IEC 27001:2022 clause by clause, apply the 93 Annex A controls and prepare for audit under ISO 19011. Prepares you for the ICO ISMS 27001:2022 PRO exam and the Security Officer role.
About this course
An information security management system is only worth the certificate if someone runs it. That person writes the risk methodology, argues the Statement of Applicability, keeps the evidence in order and faces the auditor. In this scheme that person is the Information Security Officer.
This professional course prepares you for that role over three instructor led days. Nearly forty percent of the exam sits on Annex A alone, and the course weights the time accordingly: you spend a full day on the controls themselves, then close with audit programme management under ISO 19011. You leave able to implement the standard rather than only describe it.
Who this course is for
- Future Information Security Officers, the people who will own the ISMS
- IT and security managers implementing ISO/IEC 27001:2022
- Consultants advising clients through certification
- Internal auditors preparing to audit an ISMS
- Anyone holding the foundation certificate who now needs to do the work
What you will learn
- Set a defensible scope and build the management system around the organisation you actually have
- Design a risk methodology, run the assessment and turn the results into a treatment plan
- Apply the 93 Annex A controls, select what belongs and justify what does not, in a Statement of Applicability that holds up
- Place the standard inside the wider ISO/IEC 27000 family and use the guidance in 27002 and beyond
- Run monitoring, internal audit and management review so improvement is evidenced rather than asserted
- Plan and manage an audit programme according to DIN EN ISO 19011
Course outline
Day one, the system in depth
- How the course and the exam are structured, terms at professional depth
- Information security management systems and the ISMS family of standards
- Context of the organisation, scope and interested parties
- Leadership and policy
- Planning, risk assessment and risk treatment
Day two, operation and the controls
- Support, operation, performance evaluation and improvement
- Annex A in full, the four themes and the 93 controls, applied to real cases
Day three, audit
- Audit programme and audit management according to DIN EN ISO 19011
- Exam preparation and sample questions
Prerequisites
None that are formally required. We recommend the ICO ISMS 27001 foundation certificate or equivalent knowledge, because this course starts where the foundation level ends.
Exam and certification
The course prepares you for the ICO ISMS 27001:2022 PRO examination, awarded by ICO International Certification Organization GmbH. Passing both the foundation and the professional exam leads to the ICO ISMS Security Officer role certificate, issued without a further exam.
- 50 multiple choice questions, where one, several or all options may be correct
- 100 minutes, closed book
- Pass mark of 60 percent
- Taken online, at a time and place you choose
The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.
What is included
- Three days, 18 hours, of instructor led training in English, delivered online or on site
- Small groups, never more than 16 participants
- Complete course materials, exercises and sample exam questions
- Practical work on a case organisation running through all three days
- Certificate of attendance, with the ICO ISMS 27001:2022 PRO exam as an optional add on
Curriculum
Chapters follow the official ICO syllabus. The percentage is the share of the exam each chapter accounts for.
Accreditations & certifications
This course prepares you for the following certification schemes.
Upcoming events
No scheduled cohorts yet — get in touch to arrange a session.
