Information Security
Information security certification centres on ISO/IEC 27001, the international standard for information security management systems, and the family of supporting standards around it — controls guidance, risk assessment methodology, incident management, privacy in the cloud, and industrial control system security. This is the most widely recognized security credential family in the world, and the one most often named in customer security questionnaires and tender requirements.
Courses
21
Standards
7
Languages
14
From
€299
Who this is for
- Security managers and ISMS owners preparing for ISO/IEC 27001 certification
- Auditors assessing information security management systems
- Risk professionals responsible for information security risk assessment
- IT and security staff moving into a governance or compliance role
Standards in this category
Credential levels available
Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →
All information security courses€299–€850
ISO/IEC 27400
Lead Manager
EN
2 exam attempts includedISO/IEC 27400
Foundation
EN
2 exam attempts includedISO/IEC 27035
Lead Incident Manager
EN, ES, FR
2 exam attempts includedISO/IEC 27035
Foundation
EN
2 exam attempts includedISO/IEC 27005
Risk Manager
EN, UA, ES +3 more
2 exam attempts includedISO/IEC 27005
Risk Manager
EN, FR
2 exam attempts includedISO/IEC 27005
Lead Risk Manager
EN, UA, DE +1 more
2 exam attempts includedISO/IEC 27005
Foundation
EN, DE, CZ
2 exam attempts includedISO/IEC 27002
Manager
EN, CZ
2 exam attempts includedISO/IEC 27002
Lead Manager
EN, UA, ES +1 more
2 exam attempts includedISO/IEC 27002
Foundation
EN, FR, CZ
2 exam attempts includedISO/IEC 27001:2022
Transition
EN, UA, ES +2 more
2 exam attempts includedISO/IEC 27001
Lead Implementer
EN, UA, TR +11 more
2 exam attempts includedISO/IEC 27001
Lead Implementer
EN, ES, FR
2 exam attempts includedISO/IEC 27001
Lead Auditor
EN, UA, TR +10 more
2 exam attempts includedISO/IEC 27001
Lead Auditor
EN, ES, FR
2 exam attempts includedISO/IEC 27001
Foundation
EN, UA, TR +11 more
2 exam attempts includedISO/IEC 27001
Foundation
EN, FR
2 exam attempts includedISA/IEC 62443
Lead Implementer
EN
2 exam attempts includedInformation Security
Chief Information Security Officer (CISO)
EN, UA, ES +1 more
2 exam attempts includedEBIOS
Risk Manager
EN, FR
2 exam attempts includedFrequently asked questions
Which standard in this category should I start with?
ISO/IEC 27001 is the usual entry point — it is the certifiable management system standard and the one customers and tenders ask about by name. The others in this category extend it: ISO/IEC 27002 for control implementation guidance, ISO/IEC 27005 for risk methodology, ISO/IEC 27035 for incident management, and ISO/IEC 27400 for security and privacy in IoT.
What is the difference between a Lead Implementer and a Lead Auditor course?
Lead Implementer teaches you to build, run and improve a management system inside an organization. Lead Auditor teaches you to assess someone else’s against the standard, whether as an internal auditor, a consultant, or on behalf of a certification body. Neither is a prerequisite for the other, and many security professionals eventually hold both.
Which courses cover information security risk assessment?
Two approaches are available here. ISO/IEC 27005 provides the international methodology for identifying, analysing, evaluating and treating information security risk. EBIOS Risk Manager teaches the French ANSSI method, which is widely used across Europe and takes a scenario-driven approach. Both suit anyone who owns the risk assessment process.
Is there training for industrial or operational technology environments?
Yes. ISA/IEC 62443 addresses security for industrial automation and control systems, where safety and availability constraints make conventional IT security approaches unsuitable. It is the relevant path for manufacturing, utilities and critical infrastructure rather than the general-purpose ISMS standards.
What experience do the senior credentials require?
Foundation levels assume no prior experience. The Lead designations and the Chief Information Security Officer credential assume working familiarity with security governance, risk and operations, and PECB’s certification criteria require documented professional experience for the senior designations. See our certification pathways page for the requirements by level.