Information Security Governance under ISO 27001
Course overview
This course prepares delegates to establish and govern an information security management system aligned with ISO 27001. Participants cover risk assessment, the Annex A controls, statements of applicability, and the governance and audit activities that keep the system alive. The programme balances the management system requirements with the practical selection of security controls.
What you will gain
- Establish the scope and context of an ISMS
- Conduct information security risk assessment and treatment
- Select and justify Annex A controls
- Prepare a statement of applicability
- Govern and audit the security management system
- Prepare for certification and surveillance audits
Who should attend
- Information security managers
- IT governance and risk staff
- Compliance officers
- ISMS project teams
Upcoming sessions
| Date | City | Duration | Fees | |
|---|---|---|---|---|
| 14 to 18 Dec 2026 | Durban | 5 Days | R18,000 | Book |
| 12 to 16 Apr 2027 | Pretoria | 5 Days | R18,000 | Book |
| 9 to 13 Aug 2027 | Cape Town | 5 Days | R18,000 | Book |
Fees are per delegate and exclude VAT. Dates run in the second week of each month. We also deliver this course on your own schedule, in-house or live online.
More in Governance, Risk & Compliance
Corporate Governance Principles and the Board
This course gives directors and senior managers a firm grasp of the duties, structures, and behaviours that underpin sound corporate governance. Delegates examine board composition, committee mandates, director accountability, and the balance between oversight and management. The programme draws on recognised governance codes and real board dilemmas to sharpen judgement.
Enterprise Risk Management under ISO 31000
Delegates learn to build and run an enterprise risk management framework aligned with the principles and process of ISO 31000. The course covers risk appetite, identification, analysis, evaluation, and treatment, together with the governance and reporting that hold it all together. Practical sessions include building a risk register and calibrating a risk matrix for a real organisation.
Anti-Money Laundering and Financial Crime Compliance
This course equips compliance staff to detect, prevent, and report money laundering and related financial crime. Delegates study customer due diligence, sanctions screening, transaction monitoring, and suspicious activity reporting within a risk-based framework. The programme reflects the recommendations of the Financial Action Task Force and regional regulatory expectations.