Training module

Operational Control in Information Security

Plan, implement and operate information security controls consistently in day-to-day activities in line with ISO/IEC 27001

Information SecurityManagement System Manager
Digital operations grid with security signals and control indicators, representing operational control in information security through planned operations, controlled change, and day-to-day ISMS execution.

Make your information security controls work in real operations

Turn SoA and risk-treatment decisions into owned routines, evidence, monitoring and review triggers that hold up under daily delivery pressure.

Overview

What this module is about

Selected information security controls often look complete in the Statement of Applicability, treatment plan or policy set before they are ready to survive daily operations.

This module develops the practical judgement needed to make ISO/IEC 27001 controls operationally real. Participants work through the evolving Northstar case to turn selected controls into owned routines, clear handovers, proportionate evidence, monitored execution, controlled exceptions, supplier interfaces and review triggers.

The focus is management-system implementation, not technical security operations. Scope, SoA and risk-treatment decisions are used as inputs, while the live work concentrates on maintainable control operation, assurance-ready evidence and the decisions needed when controls drift, exceptions extend, suppliers change or incidents expose weak routines.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

work with ISMS implementation, control ownership, evidence, exceptions or customer assurance.

need selected controls to work reliably beyond policies, SoA entries and treatment plans.

see unclear handovers between control owners, IT operations, service teams, suppliers or assurance roles.

want routines, records and monitoring that keep control operation traceable over time.

are preparing to strengthen control evidence before certification, recertification, customer assurance or management review.

It may not be the best fit if you…

want a short overview of ISO/IEC 27001 clauses only.

are mainly looking for technical hardening, tool configuration, penetration testing or SIEM operation.

need full ISMS scope, SoA design or risk assessment as the main focus.

expect a control-by-control Annex A interpretation workshop.

already have clearly owned, maintained and evidence-backed ISMS controls that work consistently in practice.

Agenda

What is taught

6 parts
01Controls as operational handoffs

Use SoA and risk-treatment decisions as operating inputs

Identify the routines, evidence and review triggers each selected control needs

Spot weak handovers before controls drift in daily work

02Ownership, interfaces and responsibilities

Separate control owner, performer, evidence owner and assurance user

Map shared-platform, supplier and service-team interfaces

Define escalation points when ownership and operating authority diverge

03Operating routines and evidence

Specify triggers, cadence, population, criteria and records

Distinguish design, execution, review and exception evidence

Judge whether evidence supports the assurance claim being made

04Exceptions, incidents and change triggers

Handle temporary deviations without silent acceptance

Connect incidents, near misses and compensating measures to control review

Decide when change should trigger SoA, risk or routine updates

05Supplier-operated controls

Keep retained responsibility visible when controls are externally operated

Define evidence frequency, exception reporting and escalation routes

Use supplier evidence without overclaiming control effectiveness

06Monitoring, assurance and management review

Read overdue reviews, stale exceptions and evidence gaps as control signals

Prepare customer-safe assurance and management-review inputs

Use AI-supported review with source checks and overclaim safeguards

Outcomes

Learning outcomes

01

Turn selected controls into operational routines with clear ownership, cadence, evidence and review triggers

02

Define handovers between control owners, IT operations, service teams, suppliers and assurance roles

03

Judge whether control evidence supports implementation status, customer assurance and management-review decisions

Specify operating criteria, records and evidence expectations for selected information security controls

Handle exceptions, compensating measures, incidents and near misses without undermining control intent

Use supplier evidence, workflow signals and monitoring indicators to detect control drift

Use AI-assisted review safely to compare artefacts, summarise evidence and flag overclaim risks

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Operational Control in Information Security is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-IS-S-03
Download fact sheet (PDF, 5.1 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Operational Control in Information Security · HAM-IS-S-03

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Operational Control in Information Security · HAM-IS-S-03

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.