The program provides a comprehensive view of IT management, from planning and implementation to evaluation and development of an investment roadmap for the organization.”
Information Security Management (ISMS)
A practical program on establishing, operating, and improving an Information Security Management System: policies, risks, controls, incidents, continuity, and compliance.
Course Contents
1Course Overview
Information Security Management (ISMS) plays a critical role in modern organizations. ISMS, or Information Security Management System, is a comprehensive management system designed to protect important organizational information from security and cybersecurity threats. As digitalization increases, protecting data not only reduces the risk of information loss but also helps ensure confidentiality, integrity, and availability. An ISMS enables organizations to establish, implement, maintain, and continually improve information security measures, strengthening trust among customers and partners.
Implementing an ISMS also helps organizations comply with legal requirements and international standards such as ISO/IEC 27001, contributing to a secure and sustainable business environment.
Infochief Academy’s “Information Security Management” course provides foundational knowledge of information security management based on international standards such as ISO/IEC 27001. The course develops practical skills to identify, assess, and manage enterprise information security risks. Learners are guided through establishing and implementing an ISMS, from policies and procedures to monitoring and evaluating system effectiveness.
2Training Objectives
- Understand how to establish an Information Security Management System for an organization.
- Develop an ISO/IEC 27001 awareness training program for employees.
- Establish documentation required by ISO/IEC 27001.
- Define information security policies, objectives, and scope.
- Analyze and assess information security risks within the ISMS scope.
- Establish risk controls.
- Select control objectives and controls.
- Operate the established ISMS.
- Conduct reviews and continual improvement activities to strengthen system effectiveness.
3Target Participants
4Course Content
Part 1.Information Security Policies
- Enterprise-wide Policy
- Policy for IT System Users
- Policy for System Administrators
- Guidelines for Developing IT Policies
- Policy Implementation Guidelines
Part 2.Human Resource Security
- Employee Screening Process
- Guidelines for Employment Contract Clauses
- Employee Disciplinary Process
- Employee Screening Checklist
- New Starter Checklist
- Employee Termination and Job Change Checklist
Part 3.IT Asset Management
- Information Asset Inventory
- Information Classification Process
- Information Labeling Procedure
- Asset Handling Process
- Removable Media Management Process
Part 4.Access Control
- Access Control Policy
- User Access Management Process
Part 5.Physical and Environmental Security
- Physical Security Policy
- Physical Security Design Standard
- Procedure for Working in Secure Areas
- Data Center Access Procedure
- Procedure for Removing Assets from the Office
- Equipment Maintenance Schedule and Plan
Part 6.Operations Security
- Operating Procedures
- Change Management Process
- IT System Capacity Plan
- Anti-malware Policy
- Backup Policy
- IT System Usage Monitoring Process
- Software Policy
- Technical Vulnerability Management Policy
- Technical Vulnerability Assessment Process
- Information Systems Testing Plan
Part 7.Communications Security
- Network Security Policy
- Network Service Agreement
- Information Transfer Agreement
- Information Transfer Procedure
- Confidentiality Agreement Plan
- Non-disclosure Agreement
Part 8.System Acquisition, Development & Maintenance
- Principles for Secure Engineering Systems
- Principles for Secure Development Environments
- Acceptance Testing Checklist
Part 9.Supplier Relationship Management
- Supplier Information Security Policies
- Supplier Information Security Agreement
Part 10.Information Security Incident Management
- Information Security Incident Assessment Process
- Information Security Incident Response Process
Part 11.Business Continuity Management
- Business Continuity Incident Response Process
- Business Continuity Plan
- Business Continuity Testing Plan
- Business Continuity Test Report
Part 12.Information Security Compliance
- Legal, Regulatory, and Contractual Requirements Procedure
- Copyright Compliance Policy
- Records Protection and Retention Policy
- Personal Data Protection and Privacy Policy.
5Training Methodology
30% theory – 70% practice. The instructor presents the knowledge framework concisely, followed by discussions, case studies, self-assessments, scenario-based exercises, and action planning to strengthen workplace application.








6Class Information & Enrollment
Upcoming Public Training Schedule
| Expected Start Date | Schedule | Class Hours | Location | Tuition Fee | Early-bird Fee | Enroll |
|---|---|---|---|---|---|---|
| --/--/---- | Saturday – Sunday | 08:30 – 16:30 | Ho Chi Minh City | 7.500.000 VND | 6.500.000 VND | Enroll |
| --/--/---- | Monday – Friday | 18:00 – 21:30 | Hanoi | 7.500.000 VND | 6.500.000 VND | Enroll |
Total Training Duration: 2 days / 4 sessions.
In-house Training
| Duration | Tuition Fee | Class Size |
|---|---|---|
| 2 days / 4 sessions | VND 48,500,000 per class | Up to 35 learners per class. |
Additional Costs (if applicable): Depending on the training location, instructor travel and accommodation costs may be charged separately.
Completion Requirement: Learners must complete a final course project to demonstrate their ability to apply the learning in a real enterprise environment.
Request In-house Consultation →7Learning Materials & Certification
Vietnamese course materials for each module, English reference materials, and sample practical exercises.
Forms, Checklists, Templates, Scorecards, Procedures, Flowcharts, Guidance, Samples, Rules, Policies, Questionnaires, Assessments, and Comparison Charts.
Explore the Toolkits →
Information Security Management (ISMS)
Learners who complete the full program and all end-of-course requirements will receive an “Information Security Management (ISMS)” certificate from Infochief Academy.
Learners must complete a final project to demonstrate their understanding and ability to apply the course content in a real enterprise environment.
Certification Information →8Learner Testimonials
The modules closely reflect the needs of IT managers; discussions, real-world scenarios, and the final project strengthen practical application.”
The systematic management content, together with toolkits, processes, and templates, gives learners a stronger foundation for implementing IT plans professionally.”
The course materials combine international standards with the Vietnamese business context; the instructor’s experience and supporting toolkits help improve practical management effectiveness.”
9Featured Clients
Completion of the Information Security Management course delivered at Axis Vietnam, Ho Chi Minh City.
Completion of the Internal IT Audit course delivered at MobiFone Corporation, Hanoi.
Internal IT Audit training delivered for Bao Viet Securities Company (BVSC).
Completion of the IT Incident Management and RCA course at Techcombank, Hanoi.
Completion of the ITIL 4 Foundation course delivered at BVIS International School, Hanoi.
IT Service Management training for the IT Department of an international school in Ho Chi Minh City.