Course detail
Back to courses

Information Security & AI

ISO 27001:2022 Introduction Course

1 dayFoundationISO 27001CQIIRCA
Digital cybersecurity illustration with circuit board patterns

ISO 27001:2022 Introduction course requirements and overview

This ISO 27001:2022 Introduction course gives information security managers, IT teams and compliance officers a clear foundation in Information Security Management Systems. Delegates learn the purpose of ISO 27001, how information security risk is managed, what Annex A controls are for, and how the Statement of Applicability supports certification.

Course outline

  1. Module 1: ISO 27001 and the ISMS

    Understand why ISO 27001 exists and how an Information Security Management System protects confidentiality, integrity and availability.

  2. Module 2: Information security risk

    Explore risk identification, assessment, treatment and ownership in a practical business context.

  3. Module 3: Annex A controls

    Review the purpose of Annex A controls and how they connect to risk treatment decisions.

  4. Module 4: Statement of Applicability

    Understand why the Statement of Applicability matters and how it records selected, excluded and justified controls.

  5. Module 5: Certification readiness

    Learn the basic evidence, roles and activities needed before moving toward ISO 27001 certification.

Delivery methods

1 day · Foundation level · available through onsite, hybrid and online delivery. Pricing starts from £35, with options for individuals, teams and workplace delivery where available.

Onsite
£895

Delivered for up to 10 delegates

Online
£35

Remote delivery for individuals

What you will learn in this ISO 27001:2022 Introduction

Understand the purpose and structure of ISO 27001:2022Explain how an Information Security Management System worksRecognise information security risks, controls and responsibilitiesUnderstand Annex A controls and the Statement of ApplicabilityPrepare for further ISO 27001 audit or implementation training

Who should attend

This course is suited to infosec managers, it staff and compliance officers working across IT, technology, professional services, manufacturing and regulated organisations. It is built for delegates who need clear, practical guidance on Information Security Management Systems, information security risk, Annex A controls and audit readiness without unnecessary jargon.

InfoSec ManagersIT StaffCompliance Officers

Accreditation and certification

The course is aligned with CQI / IRCA expectations where applicable. Delegates receive confirmation of completion and can use the learning to support internal competence, audit readiness and management system improvement.

Frequently asked questions

Who should attend the ISO 27001 Introduction course?

It is suitable for information security managers, IT staff, compliance officers, risk teams and anyone new to ISO 27001.

Do I need technical cybersecurity knowledge?

No. Technical knowledge helps, but the course focuses on the management system, risk and control structure behind ISO 27001.

What is an ISMS?

An ISMS is an Information Security Management System. It is the framework an organisation uses to manage information security risks, controls and responsibilities.

Does the course cover Annex A?

Yes. Delegates receive an overview of Annex A controls and how they support risk treatment and the Statement of Applicability.

How long is the ISO 27001 Introduction course?

The course runs for one day and is available online, hybrid or onsite.

Can this course help before ISO 27001 certification?

Yes. It gives delegates the foundation needed before implementation, internal audit or certification preparation.