ISO/IEC 27001:2022. Information Security Management System

所在平台: Udemy

课程主页: https://www.udemy.com/course/isoiec-27001-information-security-management-system/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:ISO/IEC 27001:2022 信息安全管理体系 概述:ISO/IEC 27001 是全球最受欢迎的信息安全管理标准,获得这一认证表明组织具备强大的安全控制措施以保护信息,确保信任和可靠性。许多全球领先企业,如谷歌、苹果、Adobe 和 Oracle 等,都已根据 ISO/IEC 27001 实施并认证信息安全管理体系(ISMS),展示了其对信息保密性、完整性和可用性的保护承诺。 课程概述:本课程探讨 ISO/IEC 27001:2022 的管理体系要求及标准附录(附录 A)中的信息安全控制。课程帮助你理解如何实施 ISMS、满足必要要求并实现合规。 课程结构:本课程分为六个部分: 1. 介绍信息安全的概念以及 ISO/IEC 27001 标准,解释信息安全管理体系(ISMS)、标准目的及结构,以及 ISO/IEC 27000 系列其他相关标准。 2. 管理体系要求,包括组织的背景、ISMS 范围、信息安全风险评估与处理、信息安全目标、ISMS 文档、内部审核、管理评审、信息安全政策及不合规管理等。 3. 至第六部分聚焦于 ISO/IEC 27001:2022 附录 A 中的信息安全控制,共有93个控制措施,分为四个主题: - 组织控制(第三部分) - 人员控制(第四部分) - 物理控制(第五部分) - 技术控制(第六部分) 控制措施涉及事件管理、供应商关系、网络安全、业务连续性、信息安全意识与培训等多个主题。 若对 ISO/IEC 27001 认证感兴趣,课程末尾有专门视频介绍。通过本课程后,你将对信息安全管理体系的要求有深入理解,并能帮助组织实施符合 ISO/IEC 27001:2022 的体系。 课程适合以下领域的人士: - 担任咨询师,帮助组织实施标准和管理体系; - 参与 ISO/IEC 27001:2022 的内部或外部审核; - 在实施或计划实施信息安全管理体系的公司工作; - 对信息安全管理有兴趣; - 希望在信息安全领域建立职业生涯。 即使上述选项不符合你的背景,你也可以通过本课程提升信息安全意识,了解众多组织所采用的标准要求。课程长达 7 小时,信息凝练,可以随时复习,完成后还可获得 Udemy 发放的证书以证明你在信息安全管理领域的知识。 *本课程已更新,考虑到 2024 年针对 ISO/IEC 27001:2022 的气候变化修订。

课程评论(0条)

课程详情

What is ISO/IEC 27001 and why it matters?ISO/IEC 27001 is the world's most popular standard for information security management. Certification to this standard is highly sought after as it demonstrates an organization's ability to safeguard information with robust security controls, ensuring trust and reliability.Global leaders like Google, Apple, Adobe, Oracle, and countless other tech corporations, financial institutions, healthcare providers, insurance companies, educational institutions, manufacturers, service companies, government agencies, and businesses of all sizes have implemented and certified Information Security Management Systems (ISMS) according to ISO/IEC 27001. This showcases their commitment to protecting the confidentiality, integrity, and availability of the information they handle.Course OverviewMy course delves into the management system requirements of ISO/IEC 27001:2022, along with the information security controls from the standard's annex (Annex A). This comprehensive guide will help you understand how to implement an ISMS, meet the necessary requirements and achieve compliance.The course is structured into 6 sections:- the first section is an introduction to the concept of information security and to this standard, ISO/IEC 27001. Among other aspects the introductive part addresses the following subjects: what represents an ISMS (Information Security Management System), what is the purpose of ISO/IEC 27001 and what is the structure of this standard or what are other standards in the ISO/IEC 27000 family that can be of interest for an information security professional.- the second section of the course is about the management system requirements of ISO/IEC 27001:2022. The course follows the structure of the standard, covering all the requirements in each clause and sub-clause. The context of the organization, the scope of the ISMS, information security risk assessment and risk treatment, the information security objectives, the documentation of the ISMS, the internal audit of the ISMS, the management review, the information security policy or the management of nonconformities are among the subjects covered by this second section of the course.- the third, fourth, fifth and sixth sections are all about the information security controls from Annex A of ISO/IEC 27001:2022. There are 93 controls divided into 4 themes: Organizational controls (section 3 of the course), People controls (section 4), Physical controls (section 5) and Technological controls (section 6). The information security controls to be discussed cover, among others, subjects like incident management, supplier relationships, network security, business continuity and ICT readiness, equipment maintenance, storage media, the development of software and systems, the use of cryptography, authentication information, the screening of candidates for employment, the disciplinary process, change management, backup and redundancy, malware protection and technical vulnerability management, logging and monitoring, information security awareness and training, requirements for user end-point devices, capacity management, access privileges, protection against environmental threats, cabling security or secure coding.If you are interested in the certification to ISO/IEC 27001 for organizations and individuals, there is a video dedicated to this subject at the end of the course. After going through all the videos of this course you will have a good understanding of what are the requirements for an information security management system and how an organization can apply such a system and claim conformity to ISO/IEC 27001:2022.The information will be very useful to you if you:- work as a consultant helping organizations apply standards and implement management systems;- participate in audits (internal or external audits) in accordance with ISO/IEC 27001:2022;- work in a company that applies or intends to apply an information security management system;- have an interest in information security management in general;- are looking to build a career in information security.If none of the options above suits your profile you can use the information in my course for awareness on information security and you will have a good image of the requirements that many organizations around the world have decided to adopt.This course provides 7 hours of condensed information that you can revisit anytime you need and once you finish it you can prove your knowledge in the field of information security management with the certificate issued by Udemy.*The course is updated to account for the 2024 Amendment to ISO/IEC 27001:2022 about climate change.

课程标签

0人关注该课程

主题相关的课程