Course duration:
2 days, 9am – 5pm
We offer flexible learning options (online, instructor-led, hybrid) to fit your learning style
The APMG International ISO/IEC 27001 and swirl device logo is a trade mark of the APM Group Limited, used under permission of The APM Group Limited. All rights reserved.
APMG ISO/IEC27001 Practitioner
Synopsis
This course is a two-day classroom training relevant for professionals who play a role in establishing the ISO/IEC 27000 standard. This course is designed for IT professionals, consultants who play a role in the ISO/IEC 27000 implementation or in providing support around ISO/IEC 27000 certification.
Practical examples and case studies are used to guide you through the implementation route and prepare you to conduct a ISO/IEC 27000 assessment or audit. At the end of the two-day classroom training the APMG certification exam can be taken. This training does not cover audit techniques or the issues involved in preparing an organisation for an audit.
Outlines
- Introduction to and background of ISO/lEC 27000.
- The certification scheme.
- ISO/IEC 27000 Standards family overview
- ISO/IEC 27001 and Annex A in detail.
- The use and application of ISO/lEC 27000.
- The implementation of ISO/IEC 27000.
- Preparing for a formal audit.
- ISO/IEC 27000 scoping and applicability.
- Exam practice and preparations.
Objectives
The purpose of the practitioner qualification is to confirm whether the candidate has achieved sufficient understanding of ISO/IEC 27001 and its application in a given situation.
On completion of this training course, delegates will be able to:
- Apply the principles of ISMS policy and its information security scope, objectives, and processes within an organisational context.
- Apply the principles of risk management including risk identification, analysis and evaluation and propose appropriate treatments and controls to reduce information security risk, support business objectives and improve information security.
- Analyse and evaluate deployed risk treatments and controls to assess their effectiveness and opportunities for continual improvement.
- Analyse and evaluate the effectiveness of the ISMS through the use of internal audit and management review to continually improve the suitability, adequacy and effectiveness of the ISMS.
- Understand, create, apply and evaluate the suitability, adequacy and effectiveness of documented information and records required by ISO/IEC 27001.
- Identify and apply appropriate corrective actions to maintain ISMS conformity with ISO/IEC 27001.
Audiences
This qualification is aimed at those who are:
- Internal managers and personnel working to implement, maintain and operate an ISMS within an organisation
- External consultants supporting an organisation’s implementation, maintenance and operation of an ISMS.
- Internal auditors who are required to have an applied knowledge of the standard
Certification and Exam Info
Delegates who successfully completed the course and pass the exam will be recognised as “Practitioner – Information Security Officer” under the APMG certification scheme.
For those delegates who do not meet the requirements stipulated in pre-requisites stated above or fail the exam would be awarded a course attendance certificate only.
Exam Format
- Objective Testing
- 4 questions per paper with 20 marks available per question
- 40 marks or more required to pass (out of 80 available) – 50%
- 2½ hour duration
- Open book.
Pre-requisites
- APMG ISO/IEC 27001 Foundation certificate
- TÜV SÜD ISO27001 Foundation certificate
- ICO-CERT ISMS 27001 Foundation certificate.
Schedule
APMG ISO/IEC27001 Practitioner – Information Security Officer
APMG ISO/IEC27001 Practitioner – Information Security Officer
As Principal Consultant, Lionel Seaw offers extensive technical and managerial depth across government, pharmaceutical, and financial sectors. A trusted advisor, he combines real-world experience with a strategic helicopter-view to manage complex changes. Lionel is dedicated to building high-performance teams through effective methodologies and best practices, achieving mission-critical objectives with perseverance and focus.
Feisal Ismail is an experienced technology and management leader who has supported organisations across government, pharmaceutical, technology, and financial services sectors. An ITIL and DevOps Institute Ambassador, he helps organisations align digital and technology strategies with broader business objectives through pragmatic, results-oriented guidance grounded in globally recognised best practices and real-world operational constraints. Meticulously organised and highly collaborative, Feisal is recognised for delivering effective and sustainable outcomes in complex engagements.
Tan Hoon Wee is an accomplished IT professional with extensive international experience in managing shared services and complex project delivery. Expert in both Waterfall and Agile methodologies, he holds prestigious certifications including PMP, PRINCE2, and CSM. He specialises in advising on organisational change and process optimisation, leveraging exceptional communication skills to maintain outstanding client relationships.
Huang Yi-Jen is a specialist consultant in IT Governance and Management Frameworks. With a portfolio spanning Service Management, Agile, and Risk Management, she is recognised for achieving sustainable results through an organised, proactive delivery model. Yi-Jen is a natural communicator who excels at managing diverse stakeholders and solving complex challenges with an innovative, value-driven and professional mindset.
Luqman Haniff is an IT security specialist with over a decade of experience advising SMEs on infrastructure and information security management. A meticulous problem solver, Haniff utilises a balanced macro-and-micro approach to tackle organisational vulnerabilities. He specialises in creating targeted, custom solutions that bridge the gap between technical necessity and cost-effective business strategy for robust protection.
Why Us?
Participants can attend a complimentary refresher if they wish (1-year validity and subject to approval)
Should you have questions after the course, you may contact the trainer for assistance regarding course material
1 year access to our E-learning portal. Including:
– E-books available for download
– Official sample exam
– Randomised quiz formulated by Sapience Trainers based on past examinations