On October 12, 2020, the Institute for Internal Audit Austria will host the seminar “ISO/IEC 27001 — Structure and Audit of an ISMS” in Vienna. The seminar will be led by SEC4YOU Managing Director Manfred Scholz.
ISO 27001 defines the requirements for an Information Security Management System (ISMS) and describes a continuous improvement process (CIP), which enables the company to implement and continuously improve the necessary security measures in a risk-oriented approach.
ISO 27001 gives companies in the IT security and information security sector the opportunity to establish a structured procedure that is comparable to a quality management system according to ISO 9001, which has been used successfully in industry for a long time.
Certification according to ISO/IEC 27001 has been increasingly demanded by customers since the DSGVO came into force. Companies should therefore deal with the requirements of ISO 27001 at an early stage.
The target group
The seminar is aimed at employees of the audit department, the IT department, but also at managers and directors who want to be informed about the requirements of ISO 27001. It is also suitable for candidates for the CISA or CISM exam as a supplement to exam preparation.
Basics of ISO/IEC 27001 taught:
- Introduction to the ISO/IEC 27000 series of standards.
- Specific standards (27018, 27019, 27033, etc.)
- The three pillars of information security
- Differences between information security and data protection
- ISMS versus ICS
- The continuous improvement process (CIP / PDCA)
- Essential components of the standard
- Overview of the reference control objectives (Appendix A)
- Necessary documents for certification
- Risk management / hazard analysis (e.g. according to IT-Grundschutz)
- Certification procedure
- Importance of management support
- Business requirements and interested parties
- Measurement of the effectiveness of the ISMS through KPIs
- Internal audits and reporting to management
- Planning of improvement actions
- Approach to planning and implementation
- Audit approaches for internal auditing
- Importance of ISO 27001 for operators of essential services (NIS‑G)
- ISO 27001 and TISAX for suppliers to the automotive industry
- Outlook on future developments
To the registration: