Skip to main content
iso-frameworks

ISO27002 Manager

ISO27002 Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBManager3 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers involved in implementing or overseeing an ISMS based on ISO/IEC 27001
  • IT professionals and consultants seeking deeper knowledge of information security controls
  • Members of an ISMS implementation or information security team
  • Individuals who hold organizational responsibility for information security

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no prior exposure to information security frameworks who may find the pace too advanced
  • Professionals seeking an introductory overview of ISO/IEC 27001 auditing rather than control implementation
  • Those looking for a technical, hands-on security engineering course rather than a management-focused programme

What you'll be able to do

  • 1Explain core concepts of information security, cybersecurity, and privacy as defined in ISO/IEC 27002
  • 2Describe the relationship between ISO/IEC 27001, ISO/IEC 27002, and relevant regulatory frameworks
  • 3Classify information security controls across organizational, people, physical, and technological categories
  • 4Apply ISO/IEC 27002 guidelines to select and implement controls appropriate to an organization's context
  • 5Support the drafting of an ISMS implementation plan aligned with ISO/IEC 27002 guidance
  • 6Manage information security implementation projects using structured control selection processes
  • 7Assess and monitor information security controls to verify ongoing effectiveness
  • 8Coordinate information security incident management activities within an ISMS environment

Day by day

Day 1Introduction to ISO/IEC 27002
  • Fundamental concepts of information security, cybersecurity, and privacy

    Participants explore the core terminology and principles underpinning information security, cybersecurity, and privacy as framed by ISO/IEC 27002.

  • Relationship between ISO/IEC 27001, ISO/IEC 27002, and other frameworks

    This module examines how ISO/IEC 27002 serves as a reference set of controls that complements the ISMS requirements established in ISO/IEC 27001 and aligns with other regulatory frameworks.

  • Structure and attributes of ISO/IEC 27002 controls

    Learners review how the standard organises controls using themes and attributes, enabling flexible and context-driven selection.

By end of day

  • Articulate the purpose and scope of ISO/IEC 27002 within the broader information security standards landscape
  • Distinguish between the requirements of ISO/IEC 27001 and the implementation guidance offered by ISO/IEC 27002
Day 2Information assets, people controls, physical controls, and operational security controls
  • Organizational and information asset controls

    This module covers controls related to policies, roles, asset management, and the classification and handling of information.

  • People controls

    Participants examine controls addressing personnel security before, during, and after employment, including screening, training, and disciplinary processes.

  • Physical and environmental controls

    This module addresses controls that protect physical premises, equipment, and supporting utilities from unauthorized access or damage.

  • Operational security controls

    Learners explore controls governing day-to-day operations, including capacity management, malware protection, logging, and vulnerability management.

By end of day

  • Map specific ISO/IEC 27002 controls to organizational, people, physical, and operational security domains
  • Apply control selection criteria to realistic organizational scenarios
  • Identify gaps between current practices and ISO/IEC 27002 guidance across multiple control themes
Day 3Information security incident management, monitoring of controls, and certification exam
  • Information security incident management

    This module covers the processes for detecting, reporting, assessing, and responding to information security incidents in line with ISO/IEC 27002 guidance.

  • Monitoring and review of information security controls

    Participants learn how to measure control performance, conduct reviews, and use findings to drive continual improvement of the information security programme.

  • ISMS implementation planning and project management

    This module consolidates learning by examining how to draft an ISMS implementation plan and manage an information security project, including process implementation and control selection.

By end of day

  • Design an incident management workflow consistent with ISO/IEC 27002 recommendations
  • Establish monitoring indicators to evaluate the effectiveness of implemented controls
  • Outline an ISMS implementation project plan that integrates people, physical, and operational controls

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of information security, cybersecurity, and privacy
  • Domain 2: Information security controls based on ISO/IEC 27002
  1. Drafting an ISMS implementation plan
  2. Managing an information security implementation project
  3. Implementing information security processes
  4. Selecting and implementing information security controls

Certification Rules and Policies

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 350 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 21 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational approach

  • This training is based on both theory and best practices used in the implementation and management of information security controls.
  • Participants are encouraged to communicate and discuss with each other while partaking in exercises and quizzes.
  • The structure of quizzes is similar to that of the certification exam.

Buyers always ask

What is the difference between completing this training and obtaining an ISO/IEC 27002 Manager credential?+

Completing this training course provides you with the knowledge and skills covered in the programme. To earn a PECB credential, you must separately pass the PECB Certified ISO/IEC 27002 Manager exam and satisfy any additional professional-experience requirements set by PECB.

Cyber Academy delivers the training content; exam registration and certification applications are handled directly through PECB in accordance with their Examination and Certification Program rules.

How does ISO/IEC 27002 differ from ISO/IEC 27001, and why does that matter for managers?+

ISO/IEC 27001 specifies the requirements an organisation must meet to establish and certify an ISMS, whereas ISO/IEC 27002 provides detailed implementation guidance for the security controls referenced in Annex A of ISO/IEC 27001.

For managers, understanding both standards is essential: ISO/IEC 27001 defines what must be achieved, and ISO/IEC 27002 explains how controls can be selected, implemented, and managed to meet those requirements in practice.

Which competency domains does the PECB ISO/IEC 27002 Manager exam assess?+

According to PECB, the exam covers two domains: Domain 1 addresses fundamental principles and concepts of information security, cybersecurity, and privacy, while Domain 2 focuses on information security controls based on ISO/IEC 27002.

For the most current information on exam format, available languages, and duration, consult the official PECB List of Exams and Examination Rules and Policies directly.

Is prior ISO/IEC 27001 implementation experience necessary to benefit from this course?+

PECB indicates that participants should have a fundamental understanding of ISO/IEC 27002 and comprehensive knowledge of information security. Direct experience implementing ISO/IEC 27001 is not listed as a formal requirement, though familiarity with ISMS concepts will help you engage more deeply with the material.

Individuals who are entirely new to information security standards may find it worthwhile to review introductory resources on ISO/IEC 27001 and ISO/IEC 27002 before attending.

What types of information security controls are addressed across the three days?+

The programme covers controls across all four themes defined in ISO/IEC 27002: organizational controls, people controls, physical controls, and technological controls. Day two concentrates on people, physical, and operational security controls, while Day three extends to incident management and the monitoring of controls.

This breadth ensures that managers leave with the ability to support control selection and implementation across the full range of an organisation's security activities.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.