

1.495,- (hors TVA)

Formation


NCOI Learning



Nouveau


Information security is much more than technology. A strong security approach starts with clear governance, a practical strategy, defined responsibilities and policies that people can actually understand and use.
In this course, you learn how to define, implement and manage an Information Security Governance Programme. You discover how to organise information security within your organisation, which roles and responsibilities are involved, and how to translate complex laws, regulations and standards into practical policies, processes and controls.
You also explore how to build an actionable and measurable security strategy that supports your organisation’s objectives. Risk management, third-party risk, security awareness, auditing and compliance are key elements throughout the course.
The training combines expert-led theory with action learning. You work with a continuous business case involving a fast-growing scale-up preparing for international certification. Between the classroom days and the online follow-up session, you complete a practical assignment and knowledge assessment.
This course gives you the structure, tools and confidence to move beyond operational firefighting and build a security governance approach that is strategic, measurable and aligned with business needs.
This training is delivered in collaboration with Data Protection Institute.
After completing this course:
This course is designed for professionals who are involved in information security, governance, risk, compliance, privacy or legal responsibilities.
It is particularly relevant for security professionals, ISOs, CISOs, risk and compliance officers, Data Protection Officers, legal counsel and professionals who want to move from ad hoc security actions to a more structured governance approach.
The course is also useful for professionals who need to understand how information security policies are audited, how third-party risks are managed and how risk management methodologies can support broader compliance and privacy obligations.
This is a non-technical course. A basic understanding of IT is recommended. Experience in a corporate or management environment can be useful, but is not required.
The first day focuses on the foundations of an Information Security Governance Programme.
You start by exploring the difference between information security and cybersecurity. You learn how information security can be organised within an organisation and which roles, responsibilities and stakeholders are involved.
You then work on defining an effective information security strategy. The focus is on making this strategy actionable, measurable and aligned with the organisation’s corporate objectives.
Security awareness is also addressed as a key element in building a strong security culture. You learn why awareness programmes matter and how they contribute to reducing organisational risk.
The day also covers fundamental laws, regulations and standards that may impact your information security governance programme. You get an overview of international security and privacy-related frameworks, with specific attention to ISO27001/2, NIST CSF, NIST 800-53, CIS Controls, GDPR and NIS2.
Finally, you learn how to work with policies, processes and standards. You examine what documentation is really needed, who the target audience is, how to organise this documentation and how to make sure people understand and follow the rules.
The second day focuses on risk management, supplier risk and audit management.
You start with the basics of risk management: why it matters, which concepts and processes are important and who should be involved. You also receive an overview of standards and methodologies that can support risk analysis and mitigation.
Third-party risk management is then treated as a separate and essential topic. You learn which elements should be reviewed when assessing suppliers or external partners, including legal and regulatory compliance, contractual requirements, SLAs, penalties, certificates and the right to audit.
The course also looks at frameworks and methods that help you assess and manage third-party risks in a structured way.
The final part of the day focuses on audit management. You explore what auditing means, when it is needed and how to organise internal audits, both within your own organisation and towards third parties.
You also learn how to prepare for and comply with external audits, for example audits by customers, audits linked to certification or audits verifying compliance with laws and regulations. Attention is also given to your rights, obligations and the management of non-conformities.
After the classroom training, you take part in a 2-hour online follow-up session.
During this session, the practical assignment is reviewed and discussed. You receive feedback on the policies or risk assessments you prepared and can ask additional questions.
Between the classroom days and the online follow-up session, you complete the online knowledge assessment and prepare your assignment for discussion.
At the end of the course, participants receive a CISO Certificate of Completion.
Nos formations sont couvertes par plusieurs types de subventions. Vérifiez si vous pouvez bénéficier de l'une d'entre elles et ne payer qu'une partie vous-même.
This training is organised in collaboration with Data Protection Institute.
This is a classroom-based, non-technical course. Participants are advised to bring a laptop, tablet or notebook to take additional notes during the training.
Participants receive printed and digital course materials, including handouts of the presentations with notes, extra online training materials, a list of useful links on standards and frameworks, and exercises with solutions where applicable.
All participants will also receive access to extra online learning materials, including content on NIS2 lessons learned and the impact of the Cyber Resilience Act.

