IT professionals and managers participating in an Information Security Management training program

Information Security Management (ISMS)

A practical program on establishing, operating, and improving an Information Security Management System: policies, risks, controls, incidents, continuity, and compliance.

Course Contents

1Course Overview

Information Security Management (ISMS) plays a critical role in modern organizations. ISMS, or Information Security Management System, is a comprehensive management system designed to protect important organizational information from security and cybersecurity threats. As digitalization increases, protecting data not only reduces the risk of information loss but also helps ensure confidentiality, integrity, and availability. An ISMS enables organizations to establish, implement, maintain, and continually improve information security measures, strengthening trust among customers and partners.

Implementing an ISMS also helps organizations comply with legal requirements and international standards such as ISO/IEC 27001, contributing to a secure and sustainable business environment.

Infochief Academy’s “Information Security Management” course provides foundational knowledge of information security management based on international standards such as ISO/IEC 27001. The course develops practical skills to identify, assess, and manage enterprise information security risks. Learners are guided through establishing and implementing an ISMS, from policies and procedures to monitoring and evaluating system effectiveness.

Duration2 days / 4 sessions
Delivery FormatPublic / In-house
LevelISMS Management
CertificationInformation Security Management (ISMS)

2Training Objectives

  1. Understand how to establish an Information Security Management System for an organization.
  2. Develop an ISO/IEC 27001 awareness training program for employees.
  3. Establish documentation required by ISO/IEC 27001.
  4. Define information security policies, objectives, and scope.
  5. Analyze and assess information security risks within the ISMS scope.
  6. Establish risk controls.
  7. Select control objectives and controls.
  8. Operate the established ISMS.
  9. Conduct reviews and continual improvement activities to strengthen system effectiveness.

3Target Participants

i. IT Directors / IT Managers / Deputy IT Managers
ii. Information Security personnel
iii. IT Consultants
iv. IT Administrators
v. System operations managers and compliance managers
vi. Professionals seeking to strengthen information security management capabilities.

4Course Content

Part 1.Information Security Policies
  • Enterprise-wide Policy
  • Policy for IT System Users
  • Policy for System Administrators
  • Guidelines for Developing IT Policies
  • Policy Implementation Guidelines
Part 2.Human Resource Security
  • Employee Screening Process
  • Guidelines for Employment Contract Clauses
  • Employee Disciplinary Process
  • Employee Screening Checklist
  • New Starter Checklist
  • Employee Termination and Job Change Checklist
Part 3.IT Asset Management
  • Information Asset Inventory
  • Information Classification Process
  • Information Labeling Procedure
  • Asset Handling Process
  • Removable Media Management Process
Part 4.Access Control
  • Access Control Policy
  • User Access Management Process
Part 5.Physical and Environmental Security
  • Physical Security Policy
  • Physical Security Design Standard
  • Procedure for Working in Secure Areas
  • Data Center Access Procedure
  • Procedure for Removing Assets from the Office
  • Equipment Maintenance Schedule and Plan
Part 6.Operations Security
  • Operating Procedures
  • Change Management Process
  • IT System Capacity Plan
  • Anti-malware Policy
  • Backup Policy
  • IT System Usage Monitoring Process
  • Software Policy
  • Technical Vulnerability Management Policy
  • Technical Vulnerability Assessment Process
  • Information Systems Testing Plan
Part 7.Communications Security
  • Network Security Policy
  • Network Service Agreement
  • Information Transfer Agreement
  • Information Transfer Procedure
  • Confidentiality Agreement Plan
  • Non-disclosure Agreement
Part 8.System Acquisition, Development & Maintenance
  • Principles for Secure Engineering Systems
  • Principles for Secure Development Environments
  • Acceptance Testing Checklist
Part 9.Supplier Relationship Management
  • Supplier Information Security Policies
  • Supplier Information Security Agreement
Part 10.Information Security Incident Management
  • Information Security Incident Assessment Process
  • Information Security Incident Response Process
Part 11.Business Continuity Management
  • Business Continuity Incident Response Process
  • Business Continuity Plan
  • Business Continuity Testing Plan
  • Business Continuity Test Report
Part 12.Information Security Compliance
  • Legal, Regulatory, and Contractual Requirements Procedure
  • Copyright Compliance Policy
  • Records Protection and Retention Policy
  • Personal Data Protection and Privacy Policy.

5Training Methodology

30% theory – 70% practice. The instructor presents the knowledge framework concisely, followed by discussions, case studies, self-assessments, scenario-based exercises, and action planning to strengthen workplace application.

6Class Information & Enrollment

Upcoming Public Training Schedule

Expected Start DateScheduleClass HoursLocationTuition FeeEarly-bird FeeEnroll
--/--/----Saturday – Sunday08:30 – 16:30Ho Chi Minh City7.500.000 VND6.500.000 VNDEnroll
--/--/----Monday – Friday18:00 – 21:30Hanoi7.500.000 VND6.500.000 VNDEnroll
Note: The early-bird fee applies when tuition is paid at least 15 days before the course start date. Learners may register to attend the first session on a trial basis; Infochief will confirm the official schedule with registered learners before the course begins.
Total Training Duration: 2 days / 4 sessions.

In-house Training

DurationTuition FeeClass Size
2 days / 4 sessionsVND 48,500,000 per classUp to 35 learners per class.

Additional Costs (if applicable): Depending on the training location, instructor travel and accommodation costs may be charged separately.

Completion Requirement: Learners must complete a final course project to demonstrate their ability to apply the learning in a real enterprise environment.

Request In-house Consultation →

7Learning Materials & Certification

Infochief Course Materials

Vietnamese course materials for each module, English reference materials, and sample practical exercises.

IT Templates & Toolkits

Forms, Checklists, Templates, Scorecards, Procedures, Flowcharts, Guidance, Samples, Rules, Policies, Questionnaires, Assessments, and Comparison Charts.

Explore the Toolkits →
Sample Information Security Management (ISMS) certificate issued by Infochief Academy

Information Security Management (ISMS)

Learners who complete the full program and all end-of-course requirements will receive an “Information Security Management (ISMS)” certificate from Infochief Academy.

Learners must complete a final project to demonstrate their understanding and ability to apply the course content in a real enterprise environment.

Certification Information →

8Learner Testimonials

Nguyễn Thanh Hiền - Infochief Academy learner
Nguyễn Thanh HiềnIT Manager · VNPT Long An

The program provides a comprehensive view of IT management, from planning and implementation to evaluation and development of an investment roadmap for the organization.”

Lương Khánh - Infochief Academy learner
Lương KhánhIT Deputy Manager · OCB

The modules closely reflect the needs of IT managers; discussions, real-world scenarios, and the final project strengthen practical application.”

Lê Nguyễn Thanh Hai - Infochief Academy learner
Lê Nguyễn Thanh HaiIT Manager · PV Trans

The systematic management content, together with toolkits, processes, and templates, gives learners a stronger foundation for implementing IT plans professionally.”

Võ Thanh Uy - Infochief Academy learner
Võ Thanh UyIT Manager · PNJ

The course materials combine international standards with the Vietnamese business context; the instructor’s experience and supporting toolkits help improve practical management effectiveness.”

View More Learner Testimonials →

9Featured Clients