ISO 27001 Information Security Management System Training Course

Master the essentials of Information Security Management Systems with our engaging course designed around ISO 27001 standards. Gain expertise in implementing robust security controls, managing risks effectively and ensuring continual improvement of information security practices. Enroll now to secure your knowledge in aligning with industry best practices.

Face-to-Face May 25-27, 2026 9:00 AM - 5:00 PM Dr. Esther Suria Kala
updated
beginner
ISO 27001
We price match

Public Pricing

MYR 5250

Corporate Pricing

Pax:

Training Fees: MYR 6500/day
Total Fees: MYR 19500 ++

Training Provider Pricing

Pax:

Training Fees: MYR 2400/day
Material Fees: MYR 400
Total Fees: MYR 7600 ++

Features

3 days
24 modules
3 intakes
English
Technical: 25 pax

Target Audience

students
engineers
managers
executives

Methodologies

lecture
slides
labs
case studies
group discussion
q&A

Subsidies

HRDC Claimable logo

What you'll learn

  • Design metrics and performance indicators according to ISO 27004.
  • Understand the legal framework and principles of information security.
  • Learn about the ISO 27001 certification process including audit stages.
  • Explore clauses 4 to 8 of ISO 27001 in detail.
  • Develop competencies in risk management following ISO 27005.
  • Create effective information security policies and manage external relationships.
  • Implement information security controls based on ISO 27002 guidelines.
  • Cultivate skills for incident management and operational handling of an ISMS.

Why should you attend?

This course provides a deep dive into the Information Security Management System (ISMS) as delineated by ISO 27001. It begins with an exploration of the normative, regulatory, and legal framework that underpins information security, alongside the fundamental principles that guide its practice. As participants progress, they will become familiar with the ISO 27001 certification process, including initial and full audits, and gain insights into the detailed presentation of ISO 27001 clauses 4 to 8. The course further delves into related standards such as ISO 27002 for implementing controls and ISO 27005 for risk management in information security. Emphasis is placed on key roles and responsibilities within ISMS, understanding threats and vulnerabilities, risk analysis, policy creation, and third-party relationships. Additionally, students will learn about information architecture, data flows, document management frameworks, incident management based on ISO 27035 guidance, and operations management of an ISMS. Finally, the course covers the development of metrics and performance indicators in line with ISO 27004.

Course Syllabus

Day 1 - ISMS Fundamentals and Framework
Module 1
Module 2
Short Break
15 mins
Module 3
Module 4
Recap and Q&A
15 mins
Lunch
1 hour
Module 5
Module 6
Short Break
15 mins
Module 7
Module 8
Recap and Q&A
15 mins
End of Day 1
Day 2 - ISO 27002 Controls Implementation
Module 9
Module 10
Short Break
15 mins
Module 11
Module 12
Recap and Q&A
15 mins
Lunch
1 hour
Module 13
Module 14
Short Break
15 mins
Module 15
Module 16
Recap and Q&A
15 mins
End of Day 2
Day 3 - Risk Management and Metrics
Module 17
Module 18
Short Break
15 mins
Module 19
Module 20
Recap and Q&A
15 mins
Lunch
1 hour
Module 21
Module 22
Short Break
15 mins
Module 23
Module 24
Recap and Q&A
15 mins
End of Day 3

Instructor

Loading...
Dr. Esther Suria Kala ICT & Cybersecurity Training Expert
Trainer Profile
Trainer Profile
TTT Certificate
TTT Certificate

Dr. Esther Suria Kala is a highly accomplished ICT consultant and corporate trainer with nearly 30 years of extensive experience in information technology, project management, and organizational development. As the founder of Angel Software Solutions, she has established herself as a versatile and dedicated professional who delivers cutting-edge training solutions across Malaysia and internationally.

Her academic credentials are exceptional, including a PhD in Psychology with a focus on Human Behaviour and Human Resources, an MBA in Finance, and degrees in both Computer Science and Human Resources. Currently pursuing a second PhD in IT Information Security, Dr. Esther demonstrates an unwavering commitment to continuous learning and staying at the forefront of technological advancement. Her educational foundation is complemented by an impressive array of professional certifications, including Microsoft Certified Trainer (MCT), CISSP, ITIL, SAP Certified Associate, Certified Cyber Security Professional, Data Scientist, AI Engineering, and ECBA certifications.

Dr. Esther's technical expertise spans an extensive range of domains, from traditional programming languages like Java, C++, and PHP to modern technologies including Python, AI coding, machine learning, RPA, and IR 4.0 microservices. She is proficient in database management systems including Microsoft SQL Server and Oracle, web development frameworks, and enterprise solutions like SAP Crystal Reports and SharePoint Server. Her knowledge extends to cybersecurity, ethical hacking, network administration, and data analytics, making her uniquely qualified to address both technical and strategic business challenges.

As a trainer, Dr. Esther excels in bridging the gap between technical complexity and practical application. She delivers comprehensive training programs for both IT and non-IT professionals, covering everything from software development and cloud computing to soft skills such as digital marketing, business analysis, customer service, and project management. Her ability to communicate effectively in both English and Bahasa Malaysia enables her to connect with diverse audiences across different organizational levels.

Her impressive client portfolio includes leading organizations such as Maybank, Telekom Malaysia, Malaysian Airlines, Tenaga Nasional Berhad, Bank Negara, Ministry of Education, Ministry of Finance, and numerous multinational corporations. This extensive experience across banking, telecommunications, government, aviation, and technology sectors demonstrates her adaptability and deep understanding of varied industry requirements. Recognized with the Outstanding Achievement Award in Information Technology from University Malaya in 2013, Dr. Esther continues to empower organizations through innovative training solutions that drive digital transformation and professional excellence.

225 Courses
English, Malay, Hindi, German, Tamil
30 Years

Course Reviews

"Thank you very much for easy explanation of new version of ISO 27001.This has given me a boot in confidence for understanding the requirement of new controls."

"Easy to understand and precise course. Explains hard to understand concepts in simple and interesting way."

"Very well designed course, made it easy to understand each control and the overall standard."

FAQ

Frequently Asked Questions About This Course

Why should you attend?

This course provides a deep dive into the Information Security Management System (ISMS) as delineated by ISO 27001. It begins with an exploration of the normative, regulatory, and legal framework that underpins information security, alongside the fundamental principles that guide its practice. As participants progress, they will become familiar with the ISO 27001 certification process, including initial and full audits, and gain insights into the detailed presentation of ISO 27001 clauses 4 to 8. The course further delves into related standards such as ISO 27002 for implementing controls and ISO 27005 for risk management in information security. Emphasis is placed on key roles and responsibilities within ISMS, understanding threats and vulnerabilities, risk analysis, policy creation, and third-party relationships. Additionally, students will learn about information architecture, data flows, document management frameworks, incident management based on ISO 27035 guidance, and operations management of an ISMS. Finally, the course covers the development of metrics and performance indicators in line with ISO 27004.


What you'll learn

  • Design metrics and performance indicators according to ISO 27004.
  • Understand the legal framework and principles of information security.
  • Learn about the ISO 27001 certification process including audit stages.
  • Explore clauses 4 to 8 of ISO 27001 in detail.
  • Develop competencies in risk management following ISO 27005.
  • Create effective information security policies and manage external relationships.
  • Implement information security controls based on ISO 27002 guidelines.
  • Cultivate skills for incident management and operational handling of an ISMS.

Course Syllabus

Day 1 - ISMS Fundamentals and Framework
Module 1
Module 2
Short Break
15 mins
Module 3
Module 4
Recap and Q&A
15 mins
Lunch
1 hour
Module 5
Module 6
Short Break
15 mins
Module 7
Module 8
Recap and Q&A
15 mins
End of Day 1
Day 2 - ISO 27002 Controls Implementation
Module 9
Module 10
Short Break
15 mins
Module 11
Module 12
Recap and Q&A
15 mins
Lunch
1 hour
Module 13
Module 14
Short Break
15 mins
Module 15
Module 16
Recap and Q&A
15 mins
End of Day 2
Day 3 - Risk Management and Metrics
Module 17
Module 18
Short Break
15 mins
Module 19
Module 20
Recap and Q&A
15 mins
Lunch
1 hour
Module 21
Module 22
Short Break
15 mins
Module 23
Module 24
Recap and Q&A
15 mins
End of Day 3

Course Reviews

"Thank you very much for easy explanation of new version of ISO 27001.This has given me a boot in confidence for understanding the requirement of new controls."

"Easy to understand and precise course. Explains hard to understand concepts in simple and interesting way."

"Very well designed course, made it easy to understand each control and the overall standard."

We price match

Public Pricing

MYR 5250

Corporate Pricing

Pax:

Training Fees: MYR 6500/day
Total Fees: MYR 19500 ++

Training Provider Pricing

Pax:

Training Fees: MYR 2400/day
Material Fees: MYR 400
Total Fees: MYR 7600 ++

Features

3 days
24 modules
3 intakes
English
Technical: 25 pax

Target Audience

students
engineers
managers
executives

Methodologies

lecture
slides
labs
case studies
group discussion
q&A

Subsidies

HRDC Claimable logo

Instructor

Loading...
Dr. Esther Suria Kala ICT & Cybersecurity Training Expert
Trainer Profile
Trainer Profile
TTT Certificate
TTT Certificate

Dr. Esther Suria Kala is a highly accomplished ICT consultant and corporate trainer with nearly 30 years of extensive experience in information technology, project management, and organizational development. As the founder of Angel Software Solutions, she has established herself as a versatile and dedicated professional who delivers cutting-edge training solutions across Malaysia and internationally.

Her academic credentials are exceptional, including a PhD in Psychology with a focus on Human Behaviour and Human Resources, an MBA in Finance, and degrees in both Computer Science and Human Resources. Currently pursuing a second PhD in IT Information Security, Dr. Esther demonstrates an unwavering commitment to continuous learning and staying at the forefront of technological advancement. Her educational foundation is complemented by an impressive array of professional certifications, including Microsoft Certified Trainer (MCT), CISSP, ITIL, SAP Certified Associate, Certified Cyber Security Professional, Data Scientist, AI Engineering, and ECBA certifications.

Dr. Esther's technical expertise spans an extensive range of domains, from traditional programming languages like Java, C++, and PHP to modern technologies including Python, AI coding, machine learning, RPA, and IR 4.0 microservices. She is proficient in database management systems including Microsoft SQL Server and Oracle, web development frameworks, and enterprise solutions like SAP Crystal Reports and SharePoint Server. Her knowledge extends to cybersecurity, ethical hacking, network administration, and data analytics, making her uniquely qualified to address both technical and strategic business challenges.

As a trainer, Dr. Esther excels in bridging the gap between technical complexity and practical application. She delivers comprehensive training programs for both IT and non-IT professionals, covering everything from software development and cloud computing to soft skills such as digital marketing, business analysis, customer service, and project management. Her ability to communicate effectively in both English and Bahasa Malaysia enables her to connect with diverse audiences across different organizational levels.

Her impressive client portfolio includes leading organizations such as Maybank, Telekom Malaysia, Malaysian Airlines, Tenaga Nasional Berhad, Bank Negara, Ministry of Education, Ministry of Finance, and numerous multinational corporations. This extensive experience across banking, telecommunications, government, aviation, and technology sectors demonstrates her adaptability and deep understanding of varied industry requirements. Recognized with the Outstanding Achievement Award in Information Technology from University Malaya in 2013, Dr. Esther continues to empower organizations through innovative training solutions that drive digital transformation and professional excellence.

225 Courses
English, Malay, Hindi, German, Tamil
30 Years

FAQ

Frequently Asked Questions About This Course

Close menu