|
via Udemy |
Go to Course: https://www.udemy.com/course/iso-27001-fur-startups-und-kmu/
Certainly! Here's an English review and recommendation for the Coursera course based on the provided details: --- **Course Review and Recommendation: ISO/IEC 27001 and Information Security Management** If you’re looking to understand and implement a robust information security management system, this Coursera course offers a comprehensive yet accessible introduction to ISO/IEC 27001, the globally recognized standard for information security. The course is designed to guide both beginners and experienced professionals through the complexities of ISO 27001 and related standards. **What the Course Offers:** This course provides a clear and practical overview of the ISO/IEC 27001 standard, including its measures, risk management practices, asset management, security objectives, and how to prepare for certification audits. It covers the full scope of the ISO 27001 family, along with detailed insights into the implementation guidelines (ISO 27002, ISO 27003, ISO 27004, ISO 27005). Special emphasis is given to critical areas such as personnel security, supplier management, business continuity, communication security, and incident management—key components for establishing a resilient security posture. The instructor skillfully simplifies the complexity surrounding this extensive and often dense standard, offering an approach that balances theoretical foundations with pragmatic advice. Whether you are preparing for a certification audit as a lead auditor or seeking to develop a practical security program for your organization, this course caters to both perspectives. **Best suited for:** - Information security officers, CISOs, or anyone responsible for security management - Professionals planning to work with or implement ISO/IEC 27001 in their organization - Beginners seeking an easy-to-understand yet thorough introduction - Experienced personnel looking to deepen their practical knowledge **Course Features:** - Engaging tasks, including multiple-choice and free-response questions, with personalized feedback - Real-world insights drawn from extensive experience in the field - A focus on practical implementation and management strategies - A detailed module on the steps towards ISO certification and continuous improvement practices **Pros:** - Well-structured, with a clear progression through essential topics - Offers both theoretical knowledge and practical guidance - Suitable for beginners and professionals alike - Provides valuable insights from an experienced instructor **Cons:** - Advanced, in-depth technical details are not the primary focus - A basic understanding of organizational and IT concepts is helpful but not mandatory **Verdict:** This course is highly recommended for anyone interested in gaining a solid foundation in ISO/IEC 27001 and information security management. Its practical approach, combined with expert insights, makes it a valuable investment for professionals aiming to enhance their understanding or implement effective security measures within their organization. --- If you want, I can help craft a shorter summary or tailor the review to specific audiences!
In Unternehmen muss Informationssicherheit strukturiert angegangen werden, wenn sie effektiv umgesetzt werden soll. Die ISO/IEC 27001 ist die bekannteste und sowohl deutschland- als auch weltweit verbreitetste Norm, die einen bewährten Ansatz dafür bereitstellt.Da die Norm für alle Branchen und Organisationsgrößen geschrieben ist und eine formale Prüfgrundlage darstellt, ist der Inhalt nicht immer leicht zu lesen und zu verstehen.Ich werde Dir einen Einstieg in dieses umfangreiche und komplexe Thema etwas einfacher gestalten und gebe Dir im Kurs einen kommentierten Überblick über die ISO 27001 Maßnahmen, ergänzt durch bewährte Vorgehensweisen zum Risikomanagement, Asset-Management, zu Informationssicherheitszielen und der Management-Bewertung. Mein Blickwinkel ist dabei sowohl der des Lead Auditors, der entscheidet, ob das Ganze erfolgreich zertifiziert werden kann als auch der des Start-up-Beraters, der den Fokus auf pragmatische Herangehensweise und Umsetzung hat.Durch Aufgaben, die sowohl per Multiple Choice als auch Freitext-Antworten mit Feedback von mir beinhalten, wird der Kurs zur vielseitig anwendbaren Weiterbildung im Bereich Informationssicherheitsmanagement.Themen des Kurses sind:Die ISO27001 NormenfamilieDie Leitfäden zur Implementierung (ISO 27002, ISO 27003,ISO 27004,ISO 27005)Asset ManagementInformationsklassifizierungRisikomanagementInformationssicherheits-ZieleManagementbewertungProjektmanagement für Zertifizierungs-ProjekteDie Maßnahmen des Anhang A der ISO/IEC 27001PersonalsicherheitLieferanten-ManagementManagement von Informationssicherheits-VorfällenBusiness-Continuity-ManagementKommunikationssicherheitInformations-KlassifikationDas ZertifizierungsauditDie kontinuierliche Verbesserung des ManagementsystemsAusblick auf die ISO 27002:2022Der Kurs ist für Personen (Informationssicherheitsbeauftragte, CISO,...) geeignet, die sich in die Materie (ISMS, BSI) einarbeiten möchten oder aus beruflichen Gründen einarbeiten müssen.Je nach Kenntnisstand sind einige Inhalte vielleicht bereits bekannt, jedoch beruhen die praktischen Hinweise auf jahrelanger Erfahrung in diesem Bereich. So wird der Kurs für erfahrene Mitarbeiter genauso interessant, wie für Berufsanfänger.Detaillierte Fachkompetenz ist nicht notwendig. Es ist jedoch hilfreich, wenn man ein grundlegendes Verständnis für Organisation, IT und IT-Sicherheit mitbringt.