More and more public tenders and major clients require ISO 27001 as a condition for working with their suppliers.Without the standard in place, your company may not even reach the proposal stage.

Information Security and Compliance Training

ISO 27001 Training: Information Security

Learn how to translate the standard’s requirements into your company’s day-to-day operations, implement what it requires, and prepare for real-world audits. Includes a bonus module on using AI without compromising information security.

7.5H

of live online training with practical case studies

3+1

structured modules, including an exclusive bonus section

300€

per participant,

with discounts available for groups

+600

Strongstep client organisations

Reading the ISO 27001 standard is not enough

ISO 27001 is dense and technical. It tells you what needs to be done, but not how to do it. That is why so many companies obtain the standard, try to navigate it on their own and get stuck when they reach their first audit. This training is designed to bridge exactly that gap: taking what the standard requires and showing you how to put it into practice within your organisation.

What your company gains from ISO 27001

Opens the door to new contracts

Public tenders and major clients use ISO 27001 as a selection criterion. Without it, your proposal may not even be considered.

Move from reacting to preventing

Identify risks before they impact your business. ISO 27001 helps you set priorities and implement measures to reduce those risks in a structured way.

Builds trust with clients and partners

ISO 27001 shows clients and partners that your organisation takes information security seriously. It reduces friction in the sales process and can help clients make decisions faster.

Supports GDPR compliance and other legal requirements

A well-implemented information security management system helps address many legal data protection requirements without duplicating work.

Controls access to information

Client data, contracts, financial information and passwords. The standard requires you to know who has access to what and why that access is necessary.

Prepares your team to make informed decisions

The training equips those responsible for managing the system to make informed, well-founded decisions rather than constantly relying on an external consultant.

This Training Is for You If...

Manages or implements information security

You will be responsible for managing the system. You need to know how to set it up and maintain it, not just understand the theory behind the standard.

Prepares for audits or certification

You have an audit coming up and need to know what the auditor will ask for, what evidence to gather and which mistakes could lead to non-conformities.

Works in compliance, risk or data protection

You need to understand how ISO 27001 aligns with the GDPR and your other obligations, without creating unnecessary additional work.

Leads a team or an organisation

The standard places responsibility on top management. You need to know what you are expected to approve, what you should require and what you cannot afford to overlook.

Wants to move into a career in cybersecurity

ISO 27001 provides a foundation for many areas of information security. It is a solid and widely recognised entry point into the industry.

Has already tried to implement the standard alone and got stuck

You obtained the standard, started working through it and realised it does not explain how to put the requirements into practice. This training provides exactly the bridge you were missing.

Full Programme

3 modules + 1 exclusive bonus

7.5 hours of live online training of live online training
Certificate of participation
Follow-up Support Q&A session after the training
1

Introduction to ISO/IEC 27001:2022: What changed and why it matters

The starting point for understanding where the standard fits within your organisation.

60 min
+
  • What changed in the 2022 version compared with the previous version, and what this means in practice
  • The current market context and why ISO 27001 is particularly relevant today
  • How an Information Security Management System fits into a real-world organisation
✔ By the end of this module, you will understand what the standard is, what has changed and why it matters to your organisation.
2

Understanding the Standard’s Requirements: What ISO 27001 Requires

The seven pillars that underpin the system, translated from the language of the standard into practical business terms.

2h 45min
+
  • Context of the organisation (Clause 4): how to align the system with what the organisation actually wants to achieve
  • Leadership (Clause 5): what top management needs to take responsibility for and how this affects the organisation’s security culture
  • Planning (Clause 6): how to identify risks, set objectives and decide where to act first
  • Support (Clause 7): the resources, competencies, communication and documentation needed to support the system
  • Operation (Clause 8): how to implement and maintain information security in day-to-day operations, not just on paper
  • Performance evaluation (Clause 9): how to monitor, analyse and audit the system to determine whether it is working effectively
  • Improvement (Clause 10): how to correct, adapt and continuously improve the system over time
✔ By the end of this module, you will know what each requirement of the standard expects from you and how to meet it in practice.
3

Understanding Annex A Controls: The Practical Measures You Will Implement

The standard’s four groups of controls, explained by what they do rather than by their reference numbers.

2h 45min
+
  • Organisational controls: the policies, roles and processes that structure information security at management level
  • People controls: access, training and responsibilities for those who handle information on a daily basis
  • Physical controls: protecting premises, equipment and physical access to information
  • Technological controls: the measures that support digital security, from firewalls to backups and encryption
✔ By the end of this module, you will know which controls to select, why to select them and how to demonstrate their implementation during an audit.

Using AI in the Workplace Without Compromising Information Security BONUS

If you use AI tools in your work, such as ChatGPT, Copilot or Claude, this section is particularly important.

30 min
+
  • Where AI can create information security risks without your team realising it
  • What should never, under any circumstances, be entered into an AI tool
  • How to use AI in day-to-day work without compromising the information that ISO 27001 is designed to protect
  • Simple principles to give your team before a problem arises
✔ By the end of this module, you will have clear rules for your team to use AI without opening a security gap that the standard is designed to prevent.

NEXT SESSION

The next course starts soon

To ensure a highly interactive learning experience and dedicated attention for every participant, we run one cohort at a time.

Coming Soon

Date to be announced

09:30–18:00

Live Online Training 

The Strongstep approach to professional training

Small cohorts, maximum engagement We deliberately keep our training groups small, giving every participant the opportunity to ask questions, discuss their organisation's specific challenges, and leave with practical, actionable guidance.
Real Implementation Case Studies Our examples come from real-world DORA implementation projects, not academic scenarios. They reflect the same operational and regulatory challenges faced by organisations like yours.
Practitioners Who Implement, Not Just Teach Our trainers actively work on ISO 27001 projects across different organisations and business environments. What they teach is what they put into practice every day.
Post-Training Support The most important questions often arise once you return to work. That's why you'll have 30 days of access to your trainer, ensuring you receive practical guidance on the challenges you encounter in your day-to-day role.
What Our Participants Say
“It is important to raise awareness of this training and the process involved. Understanding how to improve day-to-day procedures can help minimise the risk of attacks and non-compliance.”
Filipe R.
Chief Operating Officer
Training Investment

VAT at the prevailing legal rate applies. For payment terms or any questions regarding registration, please contact us at geral@strongstep.pt

The 5 truths no one tells you about ISO 27001 training

Before investing in ISO 27001 training, watch this video.
We reveal the most common mistakes organisations make and what you can do to avoid them, with practical, effective training aligned with the latest version of the standard.

Frequently Asked Questions

Do I need any prior knowledge to attend?
No. The training is designed to take you from no prior knowledge to a practical understanding of the standard. We translate technical terminology into clear business language, so you do not need a background in information security to get the most out of the session.
 
Will this training certify my company to ISO 27001?

No. ISO 27001 certification is a process that involves implementing the management system and undergoing an audit by a certification body. This training gives you the knowledge and methodology to manage that process with far fewer mistakes and much less reliance on external support.

We already have someone managing ISO 27001. Is this training still relevant?

Yes, for two reasons. First, it helps align the wider team and top management, whose involvement is required by the standard and is essential to keeping the project moving forward. Second, it provides an external, practical perspective that can often help resolve issues where the internal implementation process has stalled.

What if I need support with implementation after the training?

Strongstep supports organisations with ISO 27001 implementation and certification preparation projects. You can indicate that you are interested in this support on the registration form, and we can discuss it separately with no obligation.

Registration

Other Trainings

ISO 27001 Foundation

Duration: 16h

Make your registration

LEARN MORE

ISO 27001 Lead Auditor

Duration: 16h

Make your registration

LEARN MORE

Accelerate RGPD with ISO 27001

Duration: 16h

Make your registration

LEARN MORE

GDPR

Duration: 4 hours

Make your registration

LEARN MORE