Online course: ISMS Documentation Management in Civil Aviation
💡 This course is part of the Academy of Information Security in Civil Aviation - PART-IS Manager training. |
Description and Objectives of the Training
This training provides a comprehensive insight into documentation management within the Information Security Management System (ISMS), with a special emphasis on the requirements of Part-IS.I.OR and the ISO/IEC 27001:2022 standard. Eleven thematic chapters cover all key categories of documentation – from ISMS manuals, policies, and methodologies to plans, records, registers, and reports. A dedicated chapter focuses on verifying the operational usability of documentation and preparing for external oversight, further emphasizing the importance of functionality.
The program is highly practical, focusing on active participant engagement. It includes nine concrete exercises that enable the creation of templates, application of knowledge in real scenarios, and audit simulation. This ensures that participants not only understand the documentation requirements but can also link them to organizational processes and demonstrate their effectiveness. The goal is to equip participants to independently develop, evaluate, and maintain ISMS documentation in accordance with regulatory requirements and best practices.
Target Audience
This training is intended for individuals involved in the development, maintenance, and oversight of ISMS documentation, including information security managers, quality managers, ISMS team members, internal auditors, process managers, aviation organization leadership, and anyone preparing the organization for external oversight according to the requirements of PART-IS.I.OR and the ISO/IEC 27001 standard.
Course Content
➤ Introduction to ISMS Documentation Management This introductory chapter provides an overview of the purpose and importance of documentation management within the Information Security Management System (ISMS). Participants will gain an understanding of the role of documented information in the context of the regulatory requirements of Part-IS.I.OR and the ISO/IEC 27001:2022 standard, as well as relevant guidelines such as ISO 10013:2021. The focus is on fundamental documentation principles, differences between document types, and the connection between documentation and risk and incident management systems. The document lifecycle is also covered, including creation, version control, approval, and archiving. The goal of this chapter is to build a foundational understanding of a systematic approach to managing documented information as the backbone of the ISMS in the aviation sector. ➤ ISMS Manual The ISMS manual is a comprehensive document that describes the information security management system as a whole. This chapter addresses its purpose, content, and relationships with other documents. Participants will learn how to structure the manual to serve as a useful tool for oversight, communication, and implementation of the ISMS, covering its scope, key processes, policies, responsibilities, and interconnections. Exercise 1: ISMS Manual Structure Participants will create a draft structure of the ISMS manual including key elements such as scope, policies, processes, and links to other documents. The objective is to understand the role of the manual and how to adapt it to the specific needs of the organization. This exercise also enhances the ability to structure a clear and concise document that facilitates internal communication and external oversight. ➤ Policies This chapter covers the types and purposes of key ISMS policies, such as the information security policy, information classification policy, asset use policy, and others. Emphasis is placed on the requirements of Part-IS.I.OR and ISO 27001, alignment with security objectives, approval by top management, and regular policy reviews. Exercise 2: Developing an Information Security Policy ➤ Methodologies This chapter addresses documented methodologies such as those for risk assessment and treatment, incident evaluation, compliance management, and other key areas. It includes the structure of a methodology and its connection to ISO/IEC 27005 and ISO 31000 standards. ➤ Procedures This chapter explains how to develop procedures that enable the implementation of policies and methodologies, including procedures for incident management, change management, access control, monitoring, and others. Emphasis is placed on a clear structure and defined roles. Exercise 4: Developing an Incident Management Procedure ➤ Plans ➤ Registers ➤ Operational Usability of ISMS Documentation |
Learning Outcomes
Upon completion of the training, participants will:
- understand the key types of ISMS documentation and their connection to processes,
- be able to structure and develop documents in line with regulatory requirements,
- distinguish between policies, methodologies, procedures, and records,
- be able to create templates and properly manage document versions and statuses,
- master the skills needed to prepare documentation for external audits,
- demonstrate the operational effectiveness of documentation through practical simulation,
- develop the ability to evaluate, maintain, and continuously improve the documentation system.
Literature
|
Discounts
We offer attractive discounts for group registrations. The applicable rates are as follows:
|
Additional information: Bojan Varga, e-mail: bojan.varga@siq.si
-
Dates: 15.07.2025-17.07.2025ID: 18738Please choose a dateRegistration
-
Duration:
3 Days (09:00 - 16:00)
24 school hours - Lecturer: Davorin Kacian
- Registration fee: 1375,00 EUR (does not include VAT)
We value and reward your loyalty
That is why we are introducing the Loyalty Bonus to reward our loyal participants.
More about loyalty bonus