Information Security

Information security certification centres on ISO/IEC 27001, the international standard for information security management systems, and the family of supporting standards around it — controls guidance, risk assessment methodology, incident management, privacy in the cloud, and industrial control system security. This is the most widely recognized security credential family in the world, and the one most often named in customer security questionnaires and tender requirements.

Courses

21

Standards

7

Languages

14

From

€299

Who this is for

  • Security managers and ISMS owners preparing for ISO/IEC 27001 certification
  • Auditors assessing information security management systems
  • Risk professionals responsible for information security risk assessment
  • IT and security staff moving into a governance or compliance role

Standards in this category

EBIOSISA/IEC 62443ISO/IEC 27001ISO/IEC 27002ISO/IEC 27005ISO/IEC 27035ISO/IEC 27400

Credential levels available

Chief Information Security Officer (CISO)FoundationLead AuditorLead ImplementerLead Incident ManagerLead ManagerLead Risk ManagerManagerRisk ManagerTransition

Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →

All information security courses€299€850

Self-study

ISO/IEC 27400

Lead Manager

EN

2 exam attempts included
€950€750View course →
Self-study

ISO/IEC 27400

Foundation

EN

2 exam attempts included
€550€390View course →
Self-study

ISO/IEC 27035

Lead Incident Manager

EN, ES, FR

2 exam attempts included
€950€750View course →
Self-study

ISO/IEC 27035

Foundation

EN

2 exam attempts included
€550€390View course →
Self-study

ISO/IEC 27005

Risk Manager

EN, UA, ES +3 more

2 exam attempts included
€790€590View course →
eLearning

ISO/IEC 27005

Risk Manager

EN, FR

2 exam attempts included
€850€650View course →
Self-study

ISO/IEC 27005

Lead Risk Manager

EN, UA, DE +1 more

2 exam attempts included
€950€750View course →
Self-study

ISO/IEC 27005

Foundation

EN, DE, CZ

2 exam attempts included
€550€390View course →
Self-study

ISO/IEC 27002

Manager

EN, CZ

2 exam attempts included
€790€590View course →
Self-study

ISO/IEC 27002

Lead Manager

EN, UA, ES +1 more

2 exam attempts included
€950€750View course →
Self-study

ISO/IEC 27002

Foundation

EN, FR, CZ

2 exam attempts included
€550€390View course →
Self-study

ISO/IEC 27001:2022

Transition

EN, UA, ES +2 more

2 exam attempts included
€390€299View course →
Self-study

ISO/IEC 27001

Lead Implementer

EN, UA, TR +11 more

2 exam attempts included
€950€750View course →
eLearning

ISO/IEC 27001

Lead Implementer

EN, ES, FR

2 exam attempts included
€1,050€850View course →
Self-study

ISO/IEC 27001

Lead Auditor

EN, UA, TR +10 more

2 exam attempts included
€950€750View course →
eLearning

ISO/IEC 27001

Lead Auditor

EN, ES, FR

2 exam attempts included
€1,050€850View course →
Self-study

ISO/IEC 27001

Foundation

EN, UA, TR +11 more

2 exam attempts included
€550€390View course →
eLearning

ISO/IEC 27001

Foundation

EN, FR

2 exam attempts included
€590€450View course →
Self-study

ISA/IEC 62443

Lead Implementer

EN

2 exam attempts included
€950€750View course →
Self-study

Information Security

Chief Information Security Officer (CISO)

EN, UA, ES +1 more

2 exam attempts included
€950€750View course →
Self-study

EBIOS

Risk Manager

EN, FR

2 exam attempts included
€790€590View course →

Frequently asked questions

Which standard in this category should I start with?

ISO/IEC 27001 is the usual entry point — it is the certifiable management system standard and the one customers and tenders ask about by name. The others in this category extend it: ISO/IEC 27002 for control implementation guidance, ISO/IEC 27005 for risk methodology, ISO/IEC 27035 for incident management, and ISO/IEC 27400 for security and privacy in IoT.

What is the difference between a Lead Implementer and a Lead Auditor course?

Lead Implementer teaches you to build, run and improve a management system inside an organization. Lead Auditor teaches you to assess someone else’s against the standard, whether as an internal auditor, a consultant, or on behalf of a certification body. Neither is a prerequisite for the other, and many security professionals eventually hold both.

Which courses cover information security risk assessment?

Two approaches are available here. ISO/IEC 27005 provides the international methodology for identifying, analysing, evaluating and treating information security risk. EBIOS Risk Manager teaches the French ANSSI method, which is widely used across Europe and takes a scenario-driven approach. Both suit anyone who owns the risk assessment process.

Is there training for industrial or operational technology environments?

Yes. ISA/IEC 62443 addresses security for industrial automation and control systems, where safety and availability constraints make conventional IT security approaches unsuitable. It is the relevant path for manufacturing, utilities and critical infrastructure rather than the general-purpose ISMS standards.

What experience do the senior credentials require?

Foundation levels assume no prior experience. The Lead designations and the Chief Information Security Officer credential assume working familiarity with security governance, risk and operations, and PECB’s certification criteria require documented professional experience for the senior designations. See our certification pathways page for the requirements by level.