Information Security Policy
The training focuses on the practical aspects of developing an Information Security Policy in accordance with ISO/IEC 27001. The program covers a holistic approach to information security management, from identifying risks to creating documentation. Classes are conducted in the form of workshops using real-life examples and cases. Participants gain the qualifications necessary to be an Information Security Manager in their organization.
Issues
-
ISO/IEC 27001 Standard
-
Information classification methods
-
Risk management in the SMS
-
Information security documentation
-
Security policies and procedures
-
Access control mechanisms
-
Incident management
-
Business continuity
-
Auditing the SMS
-
Safety indicators
-
Employee training and awareness
-
Compliance with legal requirements
Benefits
- Gain practical skills in developing an Information Security Policy
- Risk assessment and information classification methodologies
- Design and implement an ISMS
- Competence in information security management
- Preparing to perform the role of Information Security Manager
- Creating and maintaining system documentation
Who is this training for?
Prerequisites
- Basic knowledge of information security issues
- Experience in managing an organization or part of an organization
- Knowledge of the organization's business processes
- Understand the basics of management systems
Training program
Information security model
- Terminology and industry standards
- Standards from the ISO 27000 family
Legal and regulatory basis
- Threat analysis and information classification
- Identification of security risks
- Information classification methods
- Criteria for valuing assets
- Determining levels of confidentiality
Risk management in information security
- Risk assessment methodology
- Risk identification and analysis
- Strategies for dealing with risk
- Documenting the risk management process
- Information Security Management System
Structure of the SMS
- ISO 27001 requirements
Security design
- Monitoring the effectiveness of the SMS
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Who is the Information Security Policy training for?
This training is designed for professionals looking to develop skills in information security policy. Required level: intermediate.
How long is the Information Security Policy training?
The training lasts 2. Available in online or on-site format.
Will I receive a certificate?
Yes — every participant receives a completion certificate confirming acquired competencies. EITT holds ISO 9001 accreditation.
Can this training be conducted for a closed group?
Yes — we offer dedicated closed trainings for companies. We customize the program to your team's needs. Contact us for an individual quote.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.