Project Management

Embedding ISO/IEC 27001 Information Security Controls in Project Delivery

Shows project managers how to build ISO/IEC 27001 information security controls into project processes, from supplier onboarding to secure design and closure.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Information security is usually treated as something the security function checks at the end of a project, which is precisely why so many findings only surface after go-live, when fixing them costs far more than designing them in would have. This course teaches project managers and project office staff to embed the controls of ISO/IEC 27001:2022 directly into the way a project is planned, resourced and delivered, rather than treating certification as a separate audit exercise bolted onto the schedule. Participants learn how a project intersects with an organisation's information security management system, how to classify project data and assets so the right controls apply, and how to assess supplier and contractor access against the same Annex A control set the organisation is certified against. The course covers embedding security requirements into statements of work, running security risk assessments alongside conventional risk registers, and building secure-by-design reviews into stage gates instead of a late penetration test. A running case follows a system implementation from initiation to closure. It closes on what a project must leave behind to support the organisation's ongoing certification and audit cycle.

Expected Learning Outcomes

01

Explain how a project's information assets and processes fall within the organisation's ISMS scope.

02

Classify project data and assets to apply proportionate security controls from the outset of planning.

03

Assess supplier and contractor access against the organisation's Annex A control requirements before onboarding.

04

Embed security requirements into procurement documents and statements of work for third-party delivery.

05

Run security risk assessments alongside conventional project risk management rather than as a separate exercise.

06

Build secure-by-design reviews into project stage gates instead of relying on late-stage penetration testing.

07

Compile the security evidence a project must leave behind to support the organisation's certification audit.

Who Should Attend

01

Project managers delivering systems or services within an ISO/IEC 27001-certified organisation

02

PMO staff defining stage-gate criteria that must include information security sign-off

03

IT project managers overseeing system implementations that process sensitive or regulated data

04

Procurement and contract managers embedding security requirements into supplier agreements

05

Information security officers working with project teams to apply controls proportionately

06

Programme managers accountable for audit readiness across a portfolio of technology projects

Course Modules

Select any module to see its sessions and points.

01

Positioning Security Within the Project Life Cycle

2 sessions · 8 points

Session 1Understanding the Project's Place in the ISMS

  • Identify which of the project's assets, processes and data fall within the organisation's certified ISMS scope.
  • Map project stage gates against the points where information security sign-off should be required.
  • Distinguish the security manager's advisory role from the project manager's accountability for applying controls.
  • Confirm reporting lines between the project and the organisation's information security governance structure.

Session 2Classifying Project Data and Assets

  • Classify project data by sensitivity and regulatory relevance before deciding which controls apply to it.
  • Maintain an asset inventory for the project that records ownership, classification and handling requirements.
  • Apply proportionate controls so low-sensitivity project information is not burdened with excessive process.
  • Review classification decisions as the project's scope and data holdings evolve during delivery.
02

Managing Third-Party and Supplier Security

2 sessions · 8 points

Session 1Assessing Supplier and Contractor Access

  • Assess a supplier's security posture against relevant Annex A controls before granting access to project systems.
  • Scope supplier and contractor access to the minimum required for their role in the project.
  • Verify that subcontractors engaged by a primary supplier meet the same security expectations as the prime.
  • Review and revoke supplier access promptly at contract end or role change rather than leaving it open.

Session 2Embedding Security into Procurement and Contracts

  • Write security requirements into statements of work so they are contractually enforceable, not just requested.
  • Include audit rights and evidence requirements in supplier contracts to verify claimed security controls.
  • Define incident notification obligations for suppliers who experience a security event affecting the project.
  • Assess security requirements alongside cost and schedule when evaluating competing supplier proposals.
03

Security Risk and Secure-by-Design Delivery

2 sessions · 8 points

Session 1Running Security Risk Assessments Within Project Risk Management

  • Identify information security risks using the same risk register the project already uses for other risk types.
  • Assess likelihood and impact of security risks in terms the project board can weigh against other project risks.
  • Assign risk owners for security risks who have the authority to implement the required mitigation.
  • Review security risks at the same cadence as other project risks rather than as an annual separate exercise.

Session 2Building Secure-by-Design Reviews into Stage Gates

  • Require a security design review before a stage gate is passed rather than after development is complete.
  • Use a checklist derived from Annex A controls to structure design reviews consistently across projects.
  • Feed design review findings back into the project plan as tracked actions with owners and deadlines.
  • Escalate unresolved high-severity security findings to the project board before allowing progression.
04

Evidence, Closure and Continuous Certification

2 sessions · 8 points

Session 1Compiling Evidence for Ongoing Certification

  • Identify which project artefacts, such as risk assessments and access reviews, an ISO/IEC 27001 auditor will expect to see.
  • Maintain evidence throughout delivery rather than reconstructing it retrospectively for an audit.
  • Align project documentation formats with the organisation's existing ISMS document control requirements.
  • Hand over live security records to operations so certification evidence continues after project closure.

Session 2Closing the Project with Security Assurance

  • Confirm all supplier and temporary access has been removed before formally closing the project.
  • Capture unresolved security risks in the operational risk register rather than letting them close silently with the project.
  • Record lessons learned on where security decisions were made too late for use on future projects.
  • Obtain formal security sign-off as part of project closure alongside conventional acceptance criteria.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course