ISO 27001 Annex A
Master the essentials through 21 focused micro-lessons you can complete at your own pace.
What You’ll Learn
Course Modules
Overview of ISO 27001 Annex A Framework
An introduction to the structure and purpose of the security controls.
Developing the Statement of Applicability
Learning how to select and justify the inclusion of specific controls.
Establishing Information Security Policies
Creating high-level directives to guide the organization's security efforts.
Defining Security Roles and Responsibilities
Assigning clear ownership for security tasks within the organization.
Implementing Segregation of Duties
Dividing critical tasks among multiple people to reduce the risk of fraud.
Classifying Information and Asset Management
Identifying assets and labeling them according to sensitivity levels.
Managing Third Party Supplier Risks
Ensuring security requirements are met by external vendors and partners.
Handling Information Security Incidents
Establishing a formal process for reporting and responding to threats.
Screening and Vetting Personnel
Verifying the background of employees before granting system access.
Security Awareness and Training Programs
Educating staff on security threats and mandatory policy compliance.
Managing Disciplinary Processes for Breaches
Handling security violations through a formal and fair disciplinary framework.
Designing Physical Security Perimeters
Protecting the physical boundaries of the organization's facilities.
Securing Office and Clear Desk Policies
Preventing unauthorized access to physical documents and digital screens.
Protecting Equipment from Environmental Threats
Guarding hardware against fire, flood, and power failures.
Endpoint Device Security and Hardening
Securing laptops, mobiles, and workstations against external attacks.
Network Security and Perimeter Defense
Controlling traffic flow and protecting the network boundary.
Managing Secure Software Installation
Controlling which software is permitted for installation on corporate systems.
Implementing Cryptographic Key Management
Using encryption and managing the full lifecycle of cryptographic keys.
Logging and Monitoring System Events
Capturing audit logs to detect and analyze potential security events.
Vulnerability Scanning and Management
Identifying and remediating technical weaknesses in systems and software.
Backup and Data Recovery Procedures
Ensuring data availability through redundant backups and regular testing.
Ready to Start Learning?
Master ISO 27001 Annex A at your own pace. Begin with Module 1 and progress through all 21 modules.
