Discipline

Information Security

Learn to set a security position, get help building it, and have it audited

ISO/IEC 270016 modules · 2 tracks

A security position that is visible, owned and defensible

Hold the chain together: what is inside the system, what could go wrong in it, who owns each exposure, and why each control is there or is not. ISO/IEC 27001 is one frame for that chain.

Overview

Security is now a management responsibility

Information security has become a legal question as well as a technical one. Regulation names management responsibility directly, customers ask for evidence before they will sign, and the answer to both has to be a system that works rather than a control list that reads well.

An information security management system (ISMS) asks for something narrower and harder than a control list: risks owned by people who can act on them, controls chosen because of those risks, and evidence that the choice still holds. Control catalogues are easy to map onto and easy to leave unexamined, which is how a security programme comes to be complete on paper and untested in practice.

Professional tracks

Build role-specific expertise

All tracks →

Halderstone tracks follow a modular structure. They first establish a strong, role-specific foundation across disciplines, which is then applied to the chosen discipline.

Training modules

Deepen your expertise

All modules →

Each module can be taken on its own and trains the calls a practitioner has to make without being prompted. These are the modules that teach this discipline; the cross-discipline core that every track shares is in the catalogue.

Advisory

Build and improve your ISMS

Learn more →

We help organisations strengthen information security through clear governance, risk-based prioritisation and practical control integration. This includes designing and improving ISMS structures, embedding security into operational processes, clarifying ownership and evidence, and creating an approach that supports assurance, audit readiness and effective decision-making.

The four phases below are the life of a management system, and an engagement can begin at any one of them.

  1. 01

    Design

    Establishing clear security governance and control structures

    Information security governance and policy framework design

    Definition of roles, responsibilities and decision rights

    Risk assessment methodology and risk treatment approach

    Security architecture and control design

    Integration into existing management systems (e.g. QMS, privacy, AI governance)

    Design of documentation and evidence structures

  2. 02

    Operate

    Making information security work in daily practice

    Information security risk assessments and regular updates

    Implementation of security controls and procedures

    Supplier and third-party security requirements and onboarding

    Incident and vulnerability handling processes

    Security awareness and role enablement

    Operational support for ISMS processes

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of information security governance

    Control effectiveness and implementation checks

    Internal audits (ISO/IEC 27001 or integrated systems)

    Supplier and third-party security reviews

    Audit readiness assessments and preparation support

  4. 04

    Evolve

    Keeping security effective as risks and environments change

    Continuous risk monitoring and reassessment

    Maturity assessments and improvement roadmaps

    Integration of new regulatory or contractual requirements

    Scenario analysis for emerging threats

    Executive sparring on strategic security decisions

Audit

Assess your ISMS

Learn more →

An ISMS audit tests effectiveness rather than coverage: whether the risks named are the risks actually run, whether the controls chosen against them reduce the exposure, and whether the reviews would notice if they stopped working.

Supported frameworks

ISO/IEC 27001 and ISO/IEC 27002

ISO/IEC 27005

NIST Cybersecurity Framework

CIS Controls

DORA

Organisation-specific information security frameworks

Free · no obligation

Thirty minutes to understand your situation and what you are trying to achieve. No preparation needed on your side.

Length
30 minutes
Where
Video call · link sent by email
Afterwards
Possible next steps, in writing

Prefer to write instead?

Pick a timeYour details

Times shown in
Zurich

The calendar cannot be reached just now. Please send a written brief instead.

Nothing suitable?