IT-Shaped Information Security Foundation ISO/IEC 27001/2:2022 – T-ISF
Official IT-Shaped
- Duration: 60 hours
- Portuguese and English
Corporate training clients
About the course
About the Course
In this course you will learn every change in the new ISO/IEC 27001/27002 standard, updated for 2022, with everything that has changed since the old 2013 version, now outdated.
You will also learn the principles of Information Security, Risk Management and Control, Information Security Management, Compliance, Network Security and the various information security controls covered by the standard.
By the end of the course you will be able to develop and apply an effective Information Security strategy that fits the ISO/IEC 27001 and 27002:2022 standard.
Who should attend
Target Audience
Number of questions: 40 questions
Test duration: 1 hour
Passing grade: 65% (26/40)
Difficulty level: Easy
Prerequisites: IT-Shaped strongly recommends the T-ISF preparatory course
Open-book exam: No
Exam format: Online
Certification & exam
Exam and Certification
This course prepares you for the official IT-Shaped T-ISF certification exam.
- Exam language
- Portuguese and English
- Number of questions
- 40 questions
- Test duration
- 1 hour
- Passing grade
- 65% (26/40)
- Difficulty level
- Easy
- Prerequisites
- IT-Shaped strongly recommends the T-ISF preparatory course
- Open-book exam
- No
- Exam format
- Online
- 99
Pass rate among PMG Academy students
Our students consistently outperform global averages. The content is developed by the official translator of the PeopleCert exam itself.
- 1y
Exam voucher validity
Your included PeopleCert exam voucher is valid for 12 months, giving you full flexibility to schedule when you’re ready.
- T2
Take2 re-sit option available
Optional Take2 re-sit and PeopleCert Plus Membership are available at checkout for complete peace of mind.
About the instructor
About the Instructor
15 years of training excellence with over 71,000 students who have passed.
Adriano is an ITIL Master, consultant and author of 6 books, bringing 25 years of experience and more than 50 certifications in IT Management, Security and Governance. As the leader of the largest ITSM and DPSM community (over 220,000 YouTube subscribers), he combines his MBA from FGV — one of the world's leading business schools — with a specialization in Neuroscience to guide a global network of more than 71,000 students. His mission is clear: to demystify complex management and turn technical knowledge into tangible value and market impact.
Official translator of the ITIL Foundation Guide (Version 5)
- 71k+
- Students trained
- 220k
- YouTube subscribers
- 25y
- Years of experience
Curriculum
What you will learn
-
00 Module 1 - Principles of Information Security 22 lessons
- Data and Information
- Information Analysis
- Operational Processes and Information
- Information Architecture
- Information Architecture and Information Security
- TOGAF
- Information Management
- Information Management Activities
- Distributed Computing
- Availability, Integrity, and Confidentiality
- Confidentiality
- Example of Confidentiality Measures
- Integrity
- Example of Integrity Measures
- Availability
- Characteristics of Availability
- Example of Availability Measures
- Parkerian Hexagram
- Possession or Control
- Authenticity
- Utility
- Class Exercise – Principles of Information Security
-
01 Module 2 - The Importance of Information Security 18 lessons
- Information as a Production Factor
- Information
- Security
- Information System
- Information and Security Relationship
- Value of Information
- Importance of Protection
- Overview of Information Security
- Information Security
- Starting from the Beginning
- ISO/IEC 27000 Standards
- Code of Practice for Information Security
- Information Security Requirements
- Countermeasures
- Control Selection
- Information Life Cycle
- Information Security Management System
- Class Exercise – The Importance of Information Security
-
02 Module 3 - Risk Management 23 lessons
- Risk Management
- Objectives and Purpose of Risk Analysis
- Cost-Benefit Analysis
- In Practice
- Threat
- Human Threats
- Non-Human Threats
- Vulnerability
- Exposure
- Risk
- Other Terms Relating to Risks
- Relationship between Threat and Risk
- Examples of Risks
- Countermeasure or Safeguard
- Risk Assessment Mathematics
- Risk Assessment
- Risk Assessment in Practice
- Risk Assessment Process
- Risk Analysis
- Types of Risk Analysis
- Risk Analysis Type: Quantitative
- Risk Analysis Type: Qualitative
- Class Exercise – Risk Management
-
03 Module 4 - Risk Control 17 lessons
- Controls
- Control Attributes in ISO 27002:2022
- Considerations in Risk Treatment
- Applying the Controls
- Types of Risk Strategy
- Risk Mitigation Measures
- Categories of Security Measures
- Types of Security Measures
- Prevention
- Detection
- Repression
- Correction
- Insurance
- Acceptance
- Types of Damages
- SLE, ALE, EF, and ARO
- Class Exercise – Risk Control
-
04 Module 5 - Organisational Controls 23 lessons
- Information Security Focus
- Information Security Management
- Organizational Security Measures
- PDCA Model
- Information Security Policy Considerations
- Control: Information Security Policy
- Examples of Information Security Policies
- Hierarchical Content of a Policy
- Publishing a Policy
- Control: Information Security Roles and Responsibilities
- The Information Security Organization
- Roles
- The Information Security Manager
- Control: Segregation of Duties
- Segregating Duties
- Consideration in the Segregation of Duties
- Control: Management Responsibilities
- Control: Contact with Authorities
- Control: Contact with Special Interest Groups
- Control: Threat Intelligence
- Threat Intelligence Considerations
- Control: Information Security in Project Management
- Class Exercise – Organizational Controls
-
05 Module 6 - Information Security in Assets 19 lessons
- Control: Inventory of Information and Other Associated Assets
- Asset Management
- Business Assets
- Business Asset Management
- Handling and Using Business Assets
- Control: Acceptable Use of Information and Other Associated Assets
- Acceptable Use Policy for Assets and Information
- Media Handling
- Control: Return of Assets
- Return of Assets
- BYOD
- Information Classification
- Control: Information Classification
- Classification
- Control: Information Labeling
- Labeling
- Examples of Classification and Labels
- Control: Information Transfer
- Class Exercise – Information Security in Assets
-
06 Module 7 - Access Control Security 13 lessons
- Control: Access Control
- Organization Requirements for Access Control
- Logical Access Control
- Activities in Access Management
- Processo de Concessão de Acesso ao Usuário
- Control: Identity Management
- Control: Authentication Information
- User Responsibilities
- Password Management System
- Control: Access Rights
- Accessing an Environment
- Access Control Type
- Class Exercise – Security in Access Control
-
07 Module 8 - Security in Supplier Relationships 11 lessons
- Relationship with Suppliers
- Control: Information Security in the Relationship with Suppliers
- Control: Approach to Information Security in Supplier Contracts
- Requirements in Contracts with Suppliers
- ICT Supply Chains
- Control: Managing Information Security in the ICT Supply Chain
- Examples of ICT Supply Chains
- Management of Service Provision by Suppliers
- Control: Monitoring, Review and Change Management of Supplier Services
- Control: Information Security for the Use of Cloud Services
- Class Exercise – Security in Supplier Relationships
-
08 Module 9 - Incident Management and Information Security 23 lessons
- Incident Definitions
- Macro Steps of the Incident Management Process
- Control: Planning and Preparation for Information Security Incident Management
- Incident Management Procedures and Responsibilities
- Incident Management Procedures
- Reporting Security Incidents
- Reporting Security Incidents
- Examples of Security Incidents
- Instructions
- Reporting Security Weaknesses
- Incident Life Cycle Measures
- Control: Assessment and Decision on Information Security Events
- Control: Assessment and Decision on Information Security Events
- Control: Information Security Incident Response
- Control: Learning from Information Security Incidents
- Control: Evidence Collection
- Continuity and Disasters
- Business Continuity Management
- DRP and BCP
- Redundancies and Alternative Locations
- Control: Information Security During Outage
- Control: ICT Readiness for Business Continuity
- Class Exercise – Information Security Incident Management
-
09 Module 10 - Compliance 18 lessons
- Compliance
- Control: Legal, Statutory, Regulatory and Contractual Requirements
- Intellectual Property Rights
- Control: Intellectual Property Rights
- Intellectual Property Rights Considerations
- Protection of Records
- Control: Record Protection
- Privacy and Data Protection
- Definition of Personal Data
- ISO/IEC 27001 and GDPR
- Control: Privacy and PII Protection
- Information Security Review
- Control: Independent Information Security Review
- Information Security Organizations and Standards
- Control: Compliance with Policies, Rules and
- Information Security Standards
- Control: Documented Operating Procedures
- Class Exercise – Conformity
-
10 Module 11 - Information Security in Human Resources 19 lessons
- Human Resources Security
- Personnel
- The Organization of Information Security
- Control: Triagem
- Screening Considerations
- Control: Terms and Conditions of Employment
- Code of Conduct
- Awareness, Education, and Training
- Control: Information Security Awareness, Education, and Training
- Precautions to Avoid Information Leaks
- Control: Disciplinary Process
- Considerations on the Disciplinary Process
- Control: Responsibilities After Termination or Change of Employment
- Considerations: Responsibilities After Termination or Change of Employment
- Control: Confidentiality or Non-Disclosure Agreements
- Control: Remote Work
- Remote Work Policy
- Control: Information Security Event Reports
- Class Exercise – Information Security in Human Resources
-
11 Module 12 - Physical Information Security Controls 15 lessons
- Physical Security
- Physical Security Measures
- Control: Physical Security Perimeters
- ISO 27001
- External Ring
- Buildings
- Physical Accesses
- Control: Physical Entry
- Access Management
- Control: Protecting Offices, Rooms, and Facilities
- Control: Physical Security Monitoring
- Alarm Monitoring
- Control: Protection Against Physical and Environmental Threats
- Control: Working in Secure Areas
- Class Exercise – Physical Information Security Controls
-
12 Module 13 - Physical Equipment Controls 15 lessons
- Control: Clean Desk, Clean Screen
- Purpose
- Control: Equipment Maintenance
- Control: Cabling Security
- Control: Support Utilities
- Intrusion Detection and Special Rooms
- Special Rooms
- Signage and Extinguishing Agents
- Control: Storage Media
- Storage Media
- Reuse or Secure Disposal
- Control: Equipment Location and Protection
- Control: Security of Assets Outside the Premises
- Control: Safe Disposal or Reuse of Equipment
- Class Exercise – Physical Equipment Controls
-
13 Module 14 - System and Endpoint Access Control 18 lessons
- Endpoint Devices
- Control: User Endpoint Devices
- Considerations regarding User Endpoint Devices
- User Endpoint Device Policy
- User Responsibilities with BYOD and Wireless Connections
- Control: Software Installation on Operating Systems
- Control: Privileged Access Rights
- Considerations regarding Privileged Access Rights
- Control: Restriction of Access to Information
- Brewer-Nash
- Dynamic Access Management Techniques
- Control: Source Code Access
- Preventing Access to Source Code
- Control: Secure Authentication
- Procedures and Technologies for Logins
- Utility Programs
- Control: Use of Privileged Utility Programs
- Class Exercise – System and Endpoint Access Control
-
14 Module 15 - Secure Development Controls 19 lessons
- Secure Development
- Security Architecture
- Control: Secure System Architecture and Engineering Principles
- Secure Systems Engineering
- “Zero Trust” Principles
- Control: Secure Development Lifecycle
- Control: Application Security Requirements
- Transactional Information between Organization and Partners
- Control: Secure Coding
- Control: Security Testing in Development and Acceptance
- Control: Outsourced Development
- Control: Separation of Development, Test, and Production Environments
- Control: Test Information
- Control: Data Masking
- Basic Data Masking Techniques
- Techniques: Data Masking
- Data Masking Considerations
- Anonymization or Pseudonymization
- Class Exercise – Secure Development Controls
-
15 Module 16 - Management Processes in Information Security 23 lessons
- Configuration Management
- Control: Configuration Management
- Change Management
- Control: Change Management
- Control: Technical Vulnerability Management
- Considerations on Technical Vulnerability Management
- Addressing Technical Vulnerabilities
- How to Manage Capacity
- Control: Capacity Management
- Redundancies
- Control: Redundancy of Information Processing Facilities
- Control: Information Backup
- Logging and Monitoring
- Control: Registro
- Event Logs
- Control: Monitoring Activities
- Monitoring Anomalies
- Control: Clock Synchronization
- Control: Data Leak Prevention
- Preventing Data Breaches
- Control: Information Deletion
- Control: Protection of Information Systems During Audit Tests
- Class Exercise – Information Security Management Processes
-
16 Module 17 - Network and Communications Security 25 lessons
- Phishing
- Spam
- Malware: Malicious Software
- Malware: Virus
- Malware: Worm
- Malware: Trojan Horse
- Malware: Hoax
- Malware: Logic Bomb
- Malware: Spyware
- Malware: Botnet / Storm Worm
- Malware: Rootkit
- Control: Malware Protection
- Control: Network Security
- Control: Network Services Security
- Control: Network Segregation
- Control: Web Filtering
- Encryption and Key Management
- Symmetric Encryption
- Asymmetric Encryption
- One-Way Encryption (Hash)
- PKI, Registration Authority and Certification Authority
- Digital Signatures
- Control: Use of Encryption
- Considerations about Cryptography
- Class Exercise – Network and Communications Security
-
17 Module 18 - Preparatory Practice Exams 4 lessons
- T-ISF Mock Exam 1: 40 questions
- T-ISF 2 Mock Exam: 40 questions
- T-ISF 3 Practice Test: 40 questions
- T-ISF 4 Practice Test: 40 questions
Student reviews
Trusted by professionals at leading organizations
-
Simplesmente sensacional!
3 de maio de 2026
-
5 de março de 2026 Deixe seu comeExcelente curso sobre a certificação ISO 27001 na PMG Academy. O conteúdo é completo, bem estruturado e aborda de forma clara os principais conceitos e práticas do Sistema de Gestão de Segurança da Informação. A didática utilizada facilita muito o entendimento, tornando o aprendizado dinâmico e aplicável ao dia a dia profissional. Destaco também a relevância dos temas abordados, que contribuem significativamente para o desenvolvimento de uma visão prática e estratégica sobre governança e segurança da informação. Recomendo fortemente para profissionais que desejam aprofundar conhecimentos e se preparar para os desafios da gestão de segurança da informação.ntário....
Join professionals from these organizations
Impact
Training teams of 5 or more?
PMG Academy offers corporate licensing, team dashboards, progress tracking, and dedicated support — built around your organization’s schedule and compliance requirements.