Skip to main content
iso-frameworks

ISO27002 Lead Manager

ISO27002 Lead Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBManager5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers or consultants seeking to deepen their knowledge of implementing information security controls within an ISMS
  • Individuals responsible for information security, compliance, risk, or governance functions in an organisation
  • IT professionals or consultants aiming to strengthen their practical information security expertise
  • Members of an ISMS implementation team with responsibility for control selection and management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals new to information security or ISO/IEC 27002 with no prior control knowledge, as the course builds on foundational understanding
  • Those seeking awareness-level introductory training rather than in-depth implementation and management skills
  • Professionals whose focus is exclusively on ISMS auditing rather than control implementation and governance
  • Participants without any professional context for applying information security controls, as practical application is central to the programme

What you'll be able to do

  • 1Explain the fundamental concepts of information security, cybersecurity, and privacy in the context of ISO/IEC 27002
  • 2Describe the relationship between ISO/IEC 27001, ISO/IEC 27002, and relevant external standards and regulatory frameworks
  • 3Interpret ISO/IEC 27002 information security controls within the specific operational context of an organisation
  • 4Determine appropriate information security controls for an organisation based on ISO/IEC 27002 guidance
  • 5Implement and manage organisational and people controls in line with ISO/IEC 27002
  • 6Implement and manage physical and technological controls in line with ISO/IEC 27002
  • 7Measure, test, and monitor the performance and effectiveness of information security controls

Day by day

Day 1Introduction to ISO/IEC 27002
  • Information Security, Cybersecurity, and Privacy Concepts

    The key principles of information security, cybersecurity, and privacy are reviewed as defined in ISO/IEC 27002 to establish a shared framework for the week.

  • ISO/IEC 27002 in Relation to ISO/IEC 27001 and Other Frameworks

    The positioning of ISO/IEC 27002 alongside ISO/IEC 27001 and other standards and regulatory frameworks is examined to clarify how controls guidance supports ISMS requirements.

  • Initiating ISO/IEC 27002 Controls Implementation

    Participants explore how to determine which controls are applicable to an organisation and how to initiate a structured controls implementation project.

By end of day

  • Explain where ISO/IEC 27002 sits within the broader information security standards landscape
  • Identify the steps needed to initiate a controls implementation initiative within an organisation
Day 2Roles and Responsibilities, Assets, Policies, and People Controls
  • Organisational Roles and Information Security Responsibilities

    The assignment and management of information security roles, responsibilities, and accountabilities under ISO/IEC 27002 are examined.

  • Asset Management and Information Classification

    Controls relating to the identification, classification, and handling of information assets are reviewed and applied to organisational scenarios.

  • People Controls Implementation

    Controls addressing personnel security across the employment lifecycle, including screening, awareness, and disciplinary processes, are explored in depth.

By end of day

  • Assign information security roles and responsibilities aligned with ISO/IEC 27002 organisational controls
  • Design people controls that address security risks across the full employment lifecycle
Day 3Physical Controls and Protection of Information Systems and Networks
  • Physical Security Controls Implementation

    Controls protecting physical environments, secure areas, equipment, and utilities from security threats are examined and applied practically.

  • Information Systems Security Controls

    Technological controls covering secure system design, access management, cryptography, and vulnerability management are explored in detail.

  • Network Security Controls

    Controls relating to network segmentation, monitoring, and the secure management of network services are reviewed within the ISO/IEC 27002 framework.

By end of day

  • Select and implement physical controls appropriate to the organisation's risk environment
  • Apply technological controls to protect information systems and network infrastructure
Day 4Information Security Incident Management and Testing and Monitoring of Controls
  • Information Security Incident Management

    The planning, execution, and improvement of incident management processes are covered using the ISO/IEC 27002 controls as a reference.

  • Testing Information Security Controls

    Approaches for testing control effectiveness, including technical testing and review activities, are examined in the context of continuous assurance.

  • Monitoring and Performance Measurement of Controls

    Participants learn how to establish metrics, conduct reviews, and use monitoring outputs to maintain and improve control effectiveness over time.

By end of day

  • Design an incident management process supported by relevant ISO/IEC 27002 controls
  • Build a monitoring and testing framework that generates actionable evidence of control performance
Day 5Exam Preparation and Review
  • Competency Domain Consolidation

    The five competency domains covered across the week are revisited to reinforce understanding and address knowledge gaps before the certification exam.

  • Applied Scenario Practice

    Participants work through realistic ISO/IEC 27002 control implementation and management scenarios to consolidate applied skills.

By end of day

  • Confirm readiness across all five exam competency domains before sitting the PECB certification exam
  • Apply the week's learning to end-to-end control implementation and management scenarios

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security, cybersecurity, and privacy
  • Domain 2: Information security management system (ISMS) and initiation of ISO/IEC 27002 information security controls implementation
  • Domain 3: Implementation and management of organizational and people controls based on ISO/IEC 27002
  • Domain 4: Implementation and management of physical and technological controls based on ISO/IEC 27002
  • Domain 5: Performance measurement, testing, and monitoring of ISO/IEC 27002 information security controls

The requirements for PECB ISO/IEC 27002 Lead Manager certifications are as follows:

  1. Drafting an ISMS implementation plan
  2. Managing an information security implementation project
  3. Implementing information security processes
  4. Selecting information security processes
  5. Implementing information security controls

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational Approach

  • The training course integrates both theory and practice by guidance and practical examples for the implementation and management of information security controls.
  • The training course contains essay-type exercises and multiple-choice quizzes, some of which are scenario-based.
  • Participants are encouraged to communicate and discuss with each other while partaking in exercises and quizzes.
  • The structure of quizzes is similar to that of the certification exam.

Buyers always ask

How does the ISO/IEC 27002 Lead Manager course differ from the ISO/IEC 27001 Lead Implementer course?+

The ISO/IEC 27001 Lead Implementer course focuses on building, operating, and improving an ISMS as a complete management system, using ISO/IEC 27001 as its primary framework. The ISO/IEC 27002 Lead Manager course concentrates specifically on the selection, implementation, and management of information security controls, using ISO/IEC 27002 as detailed guidance alongside ISO/IEC 27001.

Professionals whose work centres on control governance, compliance, or risk management may find the Lead Manager course more directly relevant, while those responsible for the full ISMS lifecycle may benefit more from the Lead Implementer programme.

What are the five competency domains assessed in the PECB ISO/IEC 27002 Lead Manager exam?+

According to PECB, the exam covers: fundamental principles and concepts of information security, cybersecurity, and privacy; ISMS and initiation of ISO/IEC 27002 controls implementation; implementation and management of organisational and people controls; implementation and management of physical and technological controls; and performance measurement, testing, and monitoring of controls.

The training course is structured across four content days to address all five domains, with the fifth day focused on review and exam preparation.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Does this course address how to draft an ISMS implementation plan?+

Yes. PECB notes that information security activities in this context should include drafting an ISMS implementation plan and managing an information security implementation project. These activities are covered within the course as practical components of implementing and managing ISO/IEC 27002 controls effectively.

Is the ISO/IEC 27002 Foundation course a recommended starting point before attending Lead Manager?+

Participants are expected to arrive with a foundational understanding of ISO/IEC 27002 and comprehensive knowledge of information security controls. Completing the ISO/IEC 27002 Foundation course beforehand is a logical way to build that baseline if you do not already have it through professional experience or prior study.

If you already work with information security controls regularly and have studied ISO/IEC 27002 independently, you may be adequately prepared without attending Foundation first.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.