Talk to us: +49 30 86329721

ISO/IEC 27001 · Personnel certification

Personnel certification in Information Management

Independent proof of competence for specialists in information security and information management per ISO/IEC 27001 and ISO 24089.

Overview

What is it about?

Personnel certification in information management proves that a specialist confidently masters the requirements of an information security management system per ISO/IEC 27001 as well as the structured management of information and software updates. For example in the context of ISO 24089. What is assessed is risk assessment, the selection and effectiveness of controls, and the protection of the confidentiality, integrity and availability of information.

The certification is aimed at roles such as information security officers, ISMS managers and internal information security auditors. Their competence and qualifications are assessed and confirmed by an independent body.

Purpose & benefit

You make the competence of your information security officers robustly verifiable for customers, supervisory bodies and auditors.

What's included

  • Structure of an information security management system per ISO/IEC 27001
  • Information security risk assessment and risk treatment
  • Selection, implementation and effectiveness review of controls
  • Structured management of information and software updates (ISO 24089)
  • Legal, contractual and regulatory information security requirements
  • Planning and conducting internal ISMS audits

For whom

Is this right for you?

For information security officers (ISOs), ISMS managers, internal auditors and IT specialists and managers responsible for information security.

Your benefits

What it does for you

  • Objective proof of your own competence in a highly sought-after professional field
  • Recognition across sector and company boundaries
  • For employers: proven qualification in customer, supply chain and certification audits
  • Reduced risk of security incidents through demonstrably capable personnel

Certification profiles

Certifications in this area

6 profiles with product ID, admission requirement, required preparatory courses and certification condition.

Software Update Coordinator

IC-502-01
Category
Information Management
Language
English
Target group
Software Update Coordinators, Project Managers.
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-16”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following courses:

Certification condition
  • Passing the written examination
  • At least 1.5 years of professional experience in the relevant field of activity

Software Update Engineer

IC-502-02
Category
Information Management
Language
English
Target group
Software Update Engineers, Software Developers in the automotive sector.
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-17”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following courses:

Certification condition
  • Passing the written examination
  • At least 2 years of professional experience in the relevant field of activity

ISO 27001 Auditor

IC-502-03
Category
Information Management
Language
English
Target group
ISO 27001 Auditors, IT Security Officers.
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-18”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following course:

Certification condition
  • Passing the written examination
  • At least 6 months of professional experience in the relevant field of activity

IT Strategy Consultant

IC-502-04
Category
Information Management
Language
English
Target group
Individuals interested in the intersection of technology and business strategy. This includes IT professionals, business consultants, managers, and anyone looking to understand IT strategy consulting.
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-19”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following course:

Certification condition
  • Passing the written examination
  • At least 2 years of professional experience in the relevant field of activity

Senior IT Strategy Consultant

IC-502-05
Category
Information Management
Language
English
Target group
Individuals interested in the intersection of technology and business strategy. This includes IT professionals, business consultants, managers, and anyone looking to understand advanced IT strategy consulting.
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-20”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following courses:

Certification condition
  • Passing the written examination
  • Passing a technical interview
  • At least 3 years of professional experience in the relevant field of activity

Information Security Officer

IC-502-06
Category
Information Management
Language
English
Target group
Information Security Officers, IT Executives
Admission requirement
Proof of relevant prior knowledge equivalent to the main course “IC-802-E-10”.
Required preparatory courses

Participation in the main course requires fundamental prior knowledge, which is provided through the following courses:

Certification condition
  • Passing the written examination
  • At least 1.5 years of professional experience in the relevant field of activity

All required courses may be substituted by equivalent qualifications and/or relevant professional experience. The evaluation of knowledge acquired through other means is subject to a fee.

Our role

How we work

  • 1Planning and conducting certification audits to assess the conformity of your management system with the requirements of the standard
  • 2Independent decision on certification based on the audit results
  • 3Issuing and maintaining certificates
  • 4Conducting surveillance and recertification audits in accordance with the applicable rules and defined time intervals

Impartiality

Consulting or support services for the introduction, implementation or improvement of management systems are not part of our activity as a certification body.

FAQ

Frequently asked questions

Does the certification cover only ISO/IEC 27001?

The focus is on information security management per ISO/IEC 27001, complemented by aspects of structured information and update management in the sense of ISO 24089.

Is the certification limited to IT roles?

No. Information security is a management task. It addresses all roles responsible for an ISMS, not exclusively technical IT functions.

How is the currency of competence ensured?

Certified individuals receive an official certificate that specifies the scope and validity period. For re-certification, you must demonstrate that you still possess the required competence. This is done by proving your knowledge of current developments in your field.

Your request

What would ISO/IEC 27001 cost for you?

Simply request a non-binding quote, quickly and directly.

Your request refers to: ISO/IEC 27001, Personnel certification in Information Management

Sending becomes possible once the privacy consent has been confirmed.

  • Without obligation
  • DAkkS-accredited for management systems

Or call us directly: +49 30 86329721

Get in touch with us

Provide your contact details, and we'll get in touch with you shortly.

Sending becomes possible once the privacy consent has been confirmed.

Call us · +49 30 86329721