Professional Track

Information Security Manager Track

Develop the capability to implement, manage and continuously improve an effective Information Security Management System aligned with ISO/IEC 27001

Professional Track

Information Security Manager Track

Develop the capability to implement, manage and continuously improve an effective Information Security Management System aligned with ISO/IEC 27001

Professional Track

Information Security Manager Track

Develop the capability to implement, manage and continuously improve an effective Information Security Management System aligned with ISO/IEC 27001

Information security managers reviewing systems in a professional office setting, representing leadership and governance of an information security management system.

Make information security part of everyday management

By embedding risk-based thinking, governance and operational controls into normal management processes, this track shows how an ISMS remains effective, usable and resilient over time.

Information security managers reviewing systems in a professional office setting, representing leadership and governance of an information security management system.

Make information security part of everyday management

By embedding risk-based thinking, governance and operational controls into normal management processes, this track shows how an ISMS remains effective, usable and resilient over time.

Information security managers reviewing systems in a professional office setting, representing leadership and governance of an information security management system.

Make information security part of everyday management

By embedding risk-based thinking, governance and operational controls into normal management processes, this track shows how an ISMS remains effective, usable and resilient over time.

Overview

Overview

Overview

The Information Security Manager Track is designed for professionals who are responsible for establishing and running an Information Security Management System (ISMS) in their organisation. Rather than focusing only on “implementation projects”, this programme covers the full lifecycle: from understanding context and risk through to day-to-day operation, performance evaluation and continual improvement.

The Information Security Manager Track is designed for professionals who are responsible for establishing and running an Information Security Management System (ISMS) in their organisation. Rather than focusing only on “implementation projects”, this programme covers the full lifecycle: from understanding context and risk through to day-to-day operation, performance evaluation and continual improvement.

Target audience

Target audience

Target audience

  • Practitioners, implementers, and consultants involved in the design, implementation, or improvement of information security management systems (ISMS) aligned with ISO/IEC 27001

  • Individuals with project or overall responsibility for establishing or evolving an information security management system

  • Current or aspiring information security managers, ISMS managers, or system owners responsible for operating and steering an existing ISMS

  • Members of information security, risk, or governance teams who play an active role in shaping, evolving, and continually improving information security management practices

  • Practitioners, implementers, and consultants involved in the design, implementation, or improvement of information security management systems (ISMS) aligned with ISO/IEC 27001

  • Individuals with project or overall responsibility for establishing or evolving an information security management system

  • Current or aspiring information security managers, ISMS managers, or system owners responsible for operating and steering an existing ISMS

  • Members of information security, risk, or governance teams who play an active role in shaping, evolving, and continually improving information security management practices

Learning outcomes

In this track, you will acquire the following capabilities.

Learning outcomes

In this track, you will acquire the following capabilities.

Learning outcomes

In this track, you will acquire the following capabilities.

Design an ISMS that actually works

  • Translate ISO/IEC 27001 into practical, organisation-specific governance and processes

  • Integrate information security coherently into the organisation’s existing management systems

Take ownership of information security governance

  • Define roles, responsibilities and decision rights for information security

  • Position information security clearly within management and operational decision-making

Manage risks, performance and improvement

  • Identify and assess information security risks before they turn into incidents or audit findings

  • Define monitoring and controls that provide management with meaningful security information

Lead audits and improvement with confidence

  • Prepare and support internal and external ISMS audits professionally

  • Use audit results, incidents and performance data to drive targeted improvements

Design an ISMS that actually works

  • Translate ISO/IEC 27001 into practical, organisation-specific governance and processes

  • Integrate information security coherently into the organisation’s existing management systems

Take ownership of information security governance

  • Define roles, responsibilities and decision rights for information security

  • Position information security clearly within management and operational decision-making

Manage risks, performance and improvement

  • Identify and assess information security risks before they turn into incidents or audit findings

  • Define monitoring and controls that provide management with meaningful security information

Lead audits and improvement with confidence

  • Prepare and support internal and external ISMS audits professionally

  • Use audit results, incidents and performance data to drive targeted improvements

Professional positioning

  • Establish a recognised competence profile as Information Security Manager, with a foundation for senior security roles in ISO 27001-based organisations

  • Take responsibility for the implementation of a new ISMS or the coordination of an existing system

  • Act as a competent counterpart to senior management, clients, auditors and certification bodies

Track ID

HAT-IS-M

Duration

~22 days

Language

English

List price

CHF 10,000

Excl. VAT. VAT may apply depending on customer location and status.

Programmes tailored to your organizational needs

Programmes tailored to your organizational needs

Modular system

Reuse of modules across tracks

Modular system

Reuse of modules across tracks

Modular system

Reuse of modules across tracks

Previously completed modules are recognized, avoiding duplication when pursuing additional Halderstone tracks.

Scalable credential model

Two credentials with one track

Scalable credential model

Two credentials with one track

Scalable credential model

Two credentials with one track

Core credential — shared foundation

Halderstone Diploma in Management System Management

  • Cross-domain management system foundation

  • Applicable across multiple ISO standards

  • Reusable for further specialisations

Core credential — shared foundation

Halderstone Diploma in Management System Management

  • Cross-domain management system foundation

  • Applicable across multiple ISO standards

  • Reusable for further specialisations

Core credential — shared foundation

Halderstone Diploma in Management System Management

  • Cross-domain management system foundation

  • Applicable across multiple ISO standards

  • Reusable for further specialisations

Specialisation credential — domain focus

Halderstone Certified Information Security Manager

  • Domain competence in information security

  • Translation of generic management system concepts to information security

  • Aligned with ISO/IEC 27001 requirements

Specialisation credential — domain focus

Halderstone Certified Information Security Manager

  • Domain competence in information security

  • Translation of generic management system concepts to information security

  • Aligned with ISO/IEC 27001 requirements

Specialisation credential — domain focus

Halderstone Certified Information Security Manager

  • Domain competence in information security

  • Translation of generic management system concepts to information security

  • Aligned with ISO/IEC 27001 requirements

Overview

Full curriculum

The curriculum below shows all modules included in this learning path. Core modules are shared across tracks and are recognised if already completed.

Overview

Full curriculum

The curriculum below shows all modules included in this learning path. Core modules are shared across tracks and are recognised if already completed.

Overview

Full curriculum

The curriculum below shows all modules included in this learning path. Core modules are shared across tracks and are recognised if already completed.

Core modules

Shared foundations common to all Manager tracks

Management system core

Expand...

Management system core

Expand...

Management system core

Expand...

Specialization modules

Role-specific modules that deepen your expertise in Information Security Management

Domain competence in Information Security Management and ISO/IEC 27001

Expand...

Domain competence in Information Security Management and ISO/IEC 27001

Expand...

Domain competence in Information Security Management and ISO/IEC 27001

Expand...

Final assessment

Practical and theoretical demonstration of your acquired competence as Information Security Manager

Capstone project

Expand...

Capstone project

Expand...

Capstone project

Expand...

Final exam

Expand...

Final exam

Expand...

Final exam

Expand...

Good to know

Answers to common questions

Good to know

Answers to common questions

Good to know

Answers to common questions

Does this track prepare me for a CISO role?

Does this track prepare me for a CISO role?

Does this track prepare me for a CISO role?

How are other frameworks and standards handled in this track?

How are other frameworks and standards handled in this track?

How are other frameworks and standards handled in this track?

What is included in a Halderstone professional track?

What is included in a Halderstone professional track?

What is included in a Halderstone professional track?

Are the tracks aligned with recognised standards such as ISO?

Are the tracks aligned with recognised standards such as ISO?

Are the tracks aligned with recognised standards such as ISO?

Do I need to complete all modules in the track?

Do I need to complete all modules in the track?

Do I need to complete all modules in the track?

Can I attend individual modules without enrolling in the full track?

Can I attend individual modules without enrolling in the full track?

Can I attend individual modules without enrolling in the full track?

Are modules recognised across different Halderstone tracks?

Are modules recognised across different Halderstone tracks?

Are modules recognised across different Halderstone tracks?

Is this track suitable if I am new to the topic?

Is this track suitable if I am new to the topic?

Is this track suitable if I am new to the topic?

How long does it take to complete the track?

How long does it take to complete the track?

How long does it take to complete the track?

What if I am unsure whether this track is right for me?

What if I am unsure whether this track is right for me?

What if I am unsure whether this track is right for me?

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.

Office scene with people standing, walking and sitting

Ready to improve your management systems?

We support continuous improvement by embedding ISO requirements into everyday practice and daily operations.