Skip to Main

ICO 27001 ISMS Security Officer & Auditor

Information Security Management Systems (ISMS) based on ISO/IEC 27001, preparing professionals for Security Officer and Auditor roles.

Browse all topics
ICO ISMS 27001:2022 FND

ICO ISMS 27001:2022 FND

A two-day introduction to information security management under ISO/IEC 27001:2022. You learn the structure of an ISMS, the requirements clause by clause, and what the 93 Annex A controls are for. Prepares you for the ICO ISMS 27001:2022 FND exam. No prior standards experience needed.

Duration
12 hours
Price
100 credits
Certification exam
Optional add-on
Next date

About this course

Customers ask for it, insurers price it, and more and more contracts simply require it. ISO/IEC 27001 has become the language organisations use to prove that information security is managed rather than hoped for. The 2022 revision reshaped Annex A into 93 controls across four themes, and anyone working near security is now expected to know their way around it.

This foundation course walks through the standard over two instructor led days. You learn what an information security management system is, what each clause of the standard actually requires, and how the Annex A controls answer the risks you identify. You leave able to read the standard with confidence, take part in a certification project and understand what an auditor is looking at.

Who this course is for

  • IT, security and operations staff whose organisation is heading towards certification
  • Quality and compliance managers adding information security to their remit
  • Project managers and consultants joining an ISMS implementation
  • Anyone who has to answer security questionnaires from customers and wants to understand what is being asked
  • Future ISMS Security Officers and ISMS Auditors, for whom this is the first step

What you will learn

  • Use the vocabulary of the standard correctly: confidentiality, integrity, availability, risk, control, conformity, corrective action
  • Explain what an information security management system is and how the Plan, Do, Check, Act cycle keeps it running
  • Work through the requirements clause by clause, from the context of the organisation to continual improvement
  • Read Annex A: how the 93 controls are grouped and how they follow from a risk assessment
  • Recognise how the wider ISO/IEC 27000 family, and topics such as business continuity and data protection, connect to the standard
  • Understand what happens in a certification audit and what evidence it rests on

Course outline

Day one, the management system

  • How the course and the exam are structured
  • Terms and definitions
  • Information security management systems, what they are and why they work
  • Context of the organisation, interested parties and scope
  • Leadership, policy and roles
  • Planning, risk assessment and risk treatment

Day two, running it and proving it

  • Support: competence, awareness, communication and documented information
  • Operation, the part where the system meets daily work
  • Performance evaluation, monitoring, internal audit and management review
  • Improvement, nonconformity and corrective action
  • Annex A, the reference control objectives across all four themes
  • Related topics and how the standards family fits together
  • Exam preparation and sample questions

Prerequisites

None. Participants should bring a general understanding of how organisations work and an interest in IT security. No technical or audit background is assumed.

Exam and certification

The course prepares you for the ICO ISMS 27001:2022 FND examination, awarded by ICO International Certification Organization GmbH. It is an accredited certification exam, not a certificate of attendance.

  • 30 multiple choice questions, where one, several or all options may be correct
  • 45 minutes, closed book
  • Pass mark of 60 percent
  • Taken online, at a time and place you choose

The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.

What is included

  • Two days, 12 hours, of instructor led classroom training in English
  • Groups of up to 40 participants
  • Complete course materials, exercises and sample exam questions
  • Worked examples from European organisations in every block
  • Certificate of attendance, with the ICO ISMS 27001:2022 FND exam as an optional add on
Read more
ICO ISMS 27001:2022 Security Officer

ICO ISMS 27001:2022 Security Officer

Three days of practical ISMS work for the person who will run it. You implement ISO/IEC 27001:2022 clause by clause, apply the 93 Annex A controls and prepare for audit under ISO 19011. Prepares you for the ICO ISMS 27001:2022 PRO exam and the Security Officer role.

Duration
18 hours
Price
100 credits
Certification exam
Optional add-on
Next date

About this course

An information security management system is only worth the certificate if someone runs it. That person writes the risk methodology, argues the Statement of Applicability, keeps the evidence in order and faces the auditor. In this scheme that person is the Information Security Officer.

This professional course prepares you for that role over three instructor led days. Nearly forty percent of the exam sits on Annex A alone, and the course weights the time accordingly: you spend a full day on the controls themselves, then close with audit programme management under ISO 19011. You leave able to implement the standard rather than only describe it.

Who this course is for

  • Future Information Security Officers, the people who will own the ISMS
  • IT and security managers implementing ISO/IEC 27001:2022
  • Consultants advising clients through certification
  • Internal auditors preparing to audit an ISMS
  • Anyone holding the foundation certificate who now needs to do the work

What you will learn

  • Set a defensible scope and build the management system around the organisation you actually have
  • Design a risk methodology, run the assessment and turn the results into a treatment plan
  • Apply the 93 Annex A controls, select what belongs and justify what does not, in a Statement of Applicability that holds up
  • Place the standard inside the wider ISO/IEC 27000 family and use the guidance in 27002 and beyond
  • Run monitoring, internal audit and management review so improvement is evidenced rather than asserted
  • Plan and manage an audit programme according to DIN EN ISO 19011

Course outline

Day one, the system in depth

  • How the course and the exam are structured, terms at professional depth
  • Information security management systems and the ISMS family of standards
  • Context of the organisation, scope and interested parties
  • Leadership and policy
  • Planning, risk assessment and risk treatment

Day two, operation and the controls

  • Support, operation, performance evaluation and improvement
  • Annex A in full, the four themes and the 93 controls, applied to real cases

Day three, audit

  • Audit programme and audit management according to DIN EN ISO 19011
  • Exam preparation and sample questions

Prerequisites

None that are formally required. We recommend the ICO ISMS 27001 foundation certificate or equivalent knowledge, because this course starts where the foundation level ends.

Exam and certification

The course prepares you for the ICO ISMS 27001:2022 PRO examination, awarded by ICO International Certification Organization GmbH. Passing both the foundation and the professional exam leads to the ICO ISMS Security Officer role certificate, issued without a further exam.

  • 50 multiple choice questions, where one, several or all options may be correct
  • 100 minutes, closed book
  • Pass mark of 60 percent
  • Taken online, at a time and place you choose

The exam is available as an optional add on to the course. Full details are published by the awarding body at ico-cert.org.

What is included

  • Three days, 18 hours, of instructor led training in English, delivered online or on site
  • Small groups, never more than 16 participants
  • Complete course materials, exercises and sample exam questions
  • Practical work on a case organisation running through all three days
  • Certificate of attendance, with the ICO ISMS 27001:2022 PRO exam as an optional add on
Read more

ICO ISMS 27001:2022 Auditor

Professional auditor training according to ISO/IEC 27001:2022, preparing participants for the ICO ISMS 27001:2022 Auditor certification.

Duration
24 hours
Price
0 credits
Certification exam
Optional add-on
Next date

About this course

Learn how to plan, conduct, and report Information Security Management System audits according to ISO/IEC 27001:2022 and auditing best practices. This course prepares participants for the ICO ISMS 27001:2022 Auditor certification.

Professional training in AI, AIMS (Artificial Intelligence Management Systems according to ISO 42001), ISMS (Information Security Management Systems according to ISO 27001) and IT Penetration Testing, designed for teams that take outcomes seriously.

© 2026 Professional Training Organisation Serbia. All rights reserved.

v1.1.3 · 2026-10-02 21:39 UTC