← Back to the course page

ISO 27001 & Information Security Governance

Module 1 · Module 1 — Overview of ISO 27001 · Lesson 1 of 1

What ISO 27001 covers (and doesn't cover)

ISO 27001 sets the ISMS requirements, ISO 27002 details the controls, ISO 27005 provides the risk assessment methodology.
ISO 27001 sets the ISMS requirements, ISO 27002 details the controls, ISO 27005 provides the risk assessment methodology.

Welcome to this course on the ISO 27001 standard and information security governance. This course concretely prepares you for the Lead Implementer professional certification, while giving you the skills to structure a real information security management system inside a real organization. Let's start with the central acronym of this course: ISO. ISO stands for the International Organization for Standardization — an organization based in Switzerland that publishes standards recognized worldwide, standardizing practices across a wide range of fields. Standard number twenty-seven thousand one, pronounced "ISO two seven oh oh one," specifically concerns information security. It sets out the requirements an organization must meet to establish, maintain, and continuously improve the protection of its sensitive information. One essential point to grasp from this first module: ISO 27001 is not a checklist of technical measures, like installing antivirus software or a firewall. It is, above all, a management standard — meaning a standard that structures an organizational approach — how an organization identifies its risks, decides what measures to take, implements them, verifies they work, and improves them over time. Technical measures are part of it, but they are a consequence of this approach, not its starting point. ISO 27001 doesn't work alone: it fits within an ecosystem of complementary standards. Standard twenty-seven thousand two, ISO 27002, provides a detailed catalog of good practices and concrete security controls — we'll come back to it in Module 4, with Annex A. Standard twenty-seven thousand five, ISO 27005, offers a detailed methodology for conducting an information security risk assessment — we'll come back to it in Module 3. Understanding that these three standards work together, each with a different role, avoids a common beginner confusion: thinking ISO 27001 already contains all the practical detail it actually needs the other two standards to supply in order to be applied concretely. Finally, a word on certification itself. An organization can have its information security management system certified by an independent certification body, following an external audit. That's different from the Lead Implementer professional certification this course prepares you for, which certifies an individual skill — yours — to guide an organization through this process, not the organization itself.

Free preview, no account needed — the rest of this module and the following modules unlock after enrolling.

Convinced? Enroll to unlock the full course.

See pricing