Live webinars on information security
Karnesav
Karnesav
Compliance and Governance Intermediate, managers and security officers

Security Compliance: GDPR, ISO 27001, and Risk Documentation

8 weeks, 3 hours per week
Security Compliance: GDPR, ISO 27001, and Risk Documentation

Compliance work is often misunderstood as purely administrative. In practice, it requires translating technical realities into documented controls, justifying decisions to auditors, and keeping records that hold up under scrutiny. This course covers that translation work.

Frameworks covered

The course focuses on ISO/IEC 27001 and GDPR, with references to NIST CSF where relevant. You will not become a certified auditor by the end — that requires formal examination — but you will understand what auditors look for and how to prepare documentation that reflects actual practice.

ISO 27001 in practice

You will work through the structure of an Information Security Management System — scope definition, risk assessment, statement of applicability, and control implementation. Real examples of documentation are used throughout, including gap analysis templates.

GDPR obligations for security teams

The course covers data mapping, lawful basis for processing, breach notification timelines, and the technical measures GDPR requires. This is not a legal course — it addresses the security team's role in compliance, not legal interpretation.

Each module includes a documentation exercise. By the end, you will have a set of draft documents — risk register, asset inventory, and a sample ISMS policy — that you can adapt for your organization.

An audit does not measure how secure you are. It measures how well you can demonstrate what you have done and why.
This course is relevant for those preparing for ISO 27001 Lead Implementer or Lead Auditor exams as background study.
Program
  1. Compliance Frameworks Overview

    ISO 27001, NIST CSF, and GDPR — structure, purpose, and differences.

  2. Information Security Management Systems

    ISMS scope, policies, and governance structure.

  3. Asset Inventory and Classification

    Identifying information assets and assigning ownership.

  4. Risk Assessment and Treatment

    Risk identification, likelihood/impact matrices, and treatment options.

  5. ISO 27001 Controls (Annex A)

    Reviewing the control set, selecting applicable controls, and writing the Statement of Applicability.

  6. GDPR Technical Requirements

    Data mapping, privacy by design, breach notification, and DPO responsibilities.

  7. Internal Audit Preparation

    Audit checklists, evidence collection, and nonconformity handling.

  8. Documentation Workshop

    Building a draft risk register, asset inventory, and ISMS policy set.