ISO/IEC 27001:2022 revised the Annex A control set, reorganised the control categories and brought modern cybersecurity concerns such as cloud security and threat intelligence into the standard. Organisations certified to the 2013 version, and the auditors who assess them, have to work to the revised requirements.
This course gives in-depth knowledge of the information security, cyber security and privacy protection requirements needed to establish an Information Security Management System under ISO/IEC 27001:2022. It covers what has changed, what it means in audit, and how a systematic framework protects the confidentiality, integrity and availability of your information and that of your interested parties.
Learning Outcomes
2013 to 2022
The control set revised for how organisations operate today.
Controls regrouped, which changes how the Statement of Applicability reads.
Explicit attention to services that sit outside your own estate.
Modern cybersecurity concepts brought inside the standard.
Improved guidance on how risk is treated and evidenced.
A stronger focus on protecting information across its life.
Note: the revised Annex A is where most of the work sits for an already certified organisation. The course covers the control changes and what an auditor will now expect to see as evidence.
Who Should Attend
Before You Begin
Note: this is a conversion programme rather than an introduction. Participants new to ISO 27001 are recommended to complete an ISO 27001 Requirements or Internal Auditor programme before attending.
Course Details
A focused one-day programme available as a virtual session, a public classroom batch or an in-house delivery at your own site, structured so that a qualified auditor can update without a week away from client work.
The revised requirements are worked through from an auditor's point of view, covering audit methodology and the evidence a 2022 assessment will call for.
Why Choose Us
Chosen by auditors, consultants and information security teams.
Trainers who audit information security management systems in the field.
The Annex A changes worked through, not summarised.
Built to fit around live audit and certification commitments.
Part of the Quality Austria group network with international reach.
FAQ
The ISMS Conversion Training & Certification Course is designed to help professionals understand the changes introduced in ISO/IEC 27001:2022 and transition from earlier ISMS standards to the updated requirements for Information Security Management Systems.
This course is suitable for existing ISO 27001 auditors, lead auditors, ISMS consultants, information security managers, compliance professionals and individuals responsible for implementing or maintaining Information Security Management Systems within organisations.
The training covers ISO/IEC 27001:2022 requirements, updated Annex A controls, risk management concepts, ISMS implementation strategies, audit methodologies, security governance and key differences between previous and revised ISO 27001 standards.
ISO/IEC 27001:2022 helps organisations strengthen information security governance, protect sensitive data, manage cybersecurity risks, improve business resilience and align with global information security and privacy protection best practices.
ISO 27001:2022 introduces updated Annex A security controls, revised control categories, modern cybersecurity concepts, improved risk treatment guidance and a stronger focus on cloud security, threat intelligence and information protection practices.
Yes, participants are generally expected to have prior knowledge of ISO 27001, ISMS concepts or auditing practices, especially if they have previously completed an ISO 27001:2013 Lead Auditor or related management system course.
ISMS Conversion Training helps cybersecurity professionals stay updated with the latest ISO 27001 requirements, strengthen auditing and implementation capabilities, improve compliance expertise and enhance career opportunities in information security, governance and risk management roles.
Talk to our team about the next available batch or in-house delivery for your organisation.