Knowledge, Information, and Digital Records Management United Kingdom

Information Security Governance and Controls Training Course

Information Security Governance is the strategic framework of leadership, organizational structures, and processes that ensure an organization's information security supports its business goals. In an era where cyber threats are increasingly sophisticated and regulatory scrutiny is at an all-time high, simply deploying technical tools is no longer sufficient. Do you know if your current security investments are actually reducing the risks that matter most to your board? This course addresses the critical gap between technical security operations and executive-level oversight by providing a structured approach to GRC (Governance, Risk, and Compliance). You will explore how to leverage internationally recognized standards such as ISO/IEC 27001 and COBIT 2019 to build a resilient security posture that survives both audits and attacks.

This course is designed as a bridge for professionals moving from technical roles into strategic management or for existing leaders who need to formalize their governance structures. Information Security Governance enables professionals to define clear accountability, manage risk appetite, and demonstrate the business value of security initiatives. Can you prove the effectiveness of your control environment when a major stakeholder asks for a maturity report? By the end of this program, Information Security Managers, GRC Analysts, and IT Auditors will be equipped with the templates and frameworks necessary to lead organizational change. You will move beyond reactive firefighting to proactive, evidence-based governance that protects both reputation and revenue.

Duration
5 Days
Duration
Certificate
Certificate
Included
Delivery
Instructor-Led
Delivery
Level
Intermediate
Level
Download Brochure

Choose Your Preferred Training Format

Training Options

Reserve Your Spot Today — Pay When You're Ready!

Live Online Training

Join from anywhere with interactive virtual sessions

Starts
Ends
Weekend (4 Wks)
USD 850
Starts
Ends
Mon - Fri (5 Days)
USD 850
Starts
Ends
Weekend (4 Wks)
USD 850
Starts
Ends
Mon - Fri (5 Days)
USD 850
Starts
Ends
Weekend (4 Wks)
USD 850
Starts
Ends
Mon - Fri (5 Days)
USD 850
Starts
Ends
Mon - Fri (5 Days)
USD 850

Classroom Training

In-person sessions at premier locations

Nairobi Kenya
Mon - Fri
5 Days
USD 1,600
Kigali Rwanda
Mon - Fri
5 Days
USD 1,900
Dubai United Arab Emirates (UAE)
Mon - Fri
5 Days
USD 4,100
Addis Ababa Ethiopia
Mon - Fri
5 Days
USD 2,400
Customized Content
Team Training
Flexible Dates

In-person training at our premier venues — pick a city and date that works for you.

Location Duration Fee Language
Nairobi, Kenya Mon - Fri (5 Days) USD 1,600 English See dates & reserve →
Kigali, Rwanda Mon - Fri (5 Days) USD 1,900 English See dates & reserve →
Dubai, United Arab Emirates (UAE) Mon - Fri (5 Days) USD 4,100 English See dates & reserve →
Addis Ababa, Ethiopia Mon - Fri (5 Days) USD 2,400 English See dates & reserve →
Abuja, Nigeria Mon - Fri (5 Days) USD 2,800 English See dates & reserve →
Zanzibar, Tanzania Mon - Fri (5 Days) USD 2,400 English See dates & reserve →
Mombasa, Kenya Mon - Fri (5 Days) USD 1,700 English See dates & reserve →
Cape Town, South Africa Mon - Fri (5 Days) USD 3,900 English See dates & reserve →
Johannesburg, South Africa Mon - Fri (5 Days) USD 3,500 English See dates & reserve →
Kampala, Uganda Mon - Fri (5 Days) USD 1,900 English See dates & reserve →
Pretoria, South Africa Mon - Fri (5 Days) USD 3,300 English See dates & reserve →
Lagos, Nigeria Mon - Fri (5 Days) USD 2,500 English See dates & reserve →
Arusha, Tanzania Mon - Fri (5 Days) USD 2,000 English See dates & reserve →
Dar es Salaam, Tanzania Mon - Fri (5 Days) USD 1,900 English See dates & reserve →
Naivasha, Kenya Mon - Fri (5 Days) USD 1,700 English See dates & reserve →

Live, instructor-led sessions you can join from anywhere — pick the next start date below.

Code Start Date End Date Duration Fee
ISG-01 Weekend (4 Weeks) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Mon - Fri (5 Days) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Weekend (4 Weeks) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Mon - Fri (5 Days) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Weekend (4 Weeks) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Mon - Fri (5 Days) USD 850 Reserve my seat → Reserve team seats →
ISG-01 Mon - Fri (5 Days) USD 850 Reserve my seat → Reserve team seats →

Our instructor comes to your office — same curriculum and accredited certificate, with case studies built around the work your team actually does.

Team Training

Train your entire team together in a familiar environment for better collaboration

Fully Customized

Content tailored to your industry, tools, and specific business challenges

Cost Effective

Save on travel & accommodation costs when training multiple employees

Flexible Scheduling

Choose dates that work best for your team's availability and projects

How It Works
1
Request a Quote

Tell us about your team size, preferred dates, and training goals

2
Get a Custom Proposal

Receive a tailored training plan and competitive pricing within 24 hours

3
We Come to You

Our certified trainer arrives ready to deliver impactful, hands-on training

Ready to upskill your team on Information Security Governance and Controls Training?

No commitment required · Response within 24 hours

About the Course

The modern enterprise operates in a landscape of fragmented regulations and hyper-connected supply chains, making Information Security Governance a non-negotiable business capability. Organizations today require results they can prove through data-driven metrics rather than anecdotal evidence. To succeed in this field, you must demonstrate five core capabilities: strategic alignment of security with business drivers, comprehensive risk management using standardized methodologies, effective resource management, performance measurement through Key Goal Indicators (KGIs), and value delivery that justifies security spending. This course provides the roadmap to master these domains using the NIST Cybersecurity Framework (CSF) and the CIS Controls as your primary guides.

You will learn how to transform scattered security activities into a cohesive, audited system. Specifically, you will practice conducting maturity assessments, designing control matrices, and drafting governance charters that define clear roles and responsibilities. This course teaches you to apply the COBIT 2019 design factors to tailor a governance system that fits your specific organizational context. You will be introduced to the complexities of multi-jurisdictional compliance and third-party risk management, while gaining hands-on experience in building a security dashboard that speaks the language of the executive suite. We acknowledge the real-world constraints of budget limitations and talent shortages, positioning this training as a toolkit for delivering high-impact governance under realistic operational pressures.


Target Audience

This program is essential for professionals responsible for the strategic oversight and compliance of information assets within their organizations.

  • Information Security Governance Lead responsible for framework implementation
  • IT Compliance Manager overseeing regulatory adherence and audit readiness
  • GRC Analyst managing enterprise risk registers and control mapping
  • Chief Information Security Officer (CISO) aligning security with business strategy
  • IT Auditor evaluating the effectiveness of security control environments
  • Risk Management Specialist focusing on digital and information assets
  • Data Privacy Officer ensuring alignment between security and privacy controls
  • Security Operations Manager transitioning into a strategic leadership role
  • Third-Party Risk Manager assessing vendor security governance maturity
  • IT Governance Consultant advising clients on framework adoption

Course Objectives

This course equips you to design, implement, and measure information security governance initiatives that protect assets, ensure compliance, and drive strategic value.

  • Analyze current governance maturity using the CMMI-based maturity models
  • Apply COBIT 2019 principles to design a tailored security governance system
  • Build a comprehensive Information Security Strategy aligned with business objectives
  • Construct a robust Risk Register using ISO 31000 and NIST 800-30
  • Design a control matrix based on ISO/IEC 27001 and CIS Controls
  • Evaluate the effectiveness of security controls through automated monitoring tools
  • Navigate complex regulatory requirements including GDPR and industry-specific standards
  • Synthesize security performance data into executive-level KPI dashboards and reports

Requirements & Prerequisites

Participants should have at least 3 years of experience in IT, information security, or internal audit. A basic understanding of risk management concepts and familiarity with common security technologies (firewalls, encryption, IAM) is required. This is an intermediate-level course focused on management and governance rather than technical configuration.


Local Application and Business Return in United Kingdom

How participants can apply the training in local operating conditions, and the return their organisation can plan for.

How participants apply this

Participants in the UK use this course to turn security activity into board-ready governance: they define accountability, map controls to business risks, and build reporting that senior leaders can act on. In practice, that means translating technical findings into risk language, supporting audit responses, and structuring policy, exception, and assurance processes. They also apply the course to improve how third-party risk, access control, incident response, and control testing are governed across business units. For managers in regulated sectors, the course helps them prepare evidence for internal audit, external assurance, and executive review without overloading technical teams.

Expected ROI

Within 6–12 months, organisations usually see clearer ownership of security decisions, fewer ad hoc exceptions, and stronger evidence for audit and board reporting. The biggest operational gain is better prioritisation: teams can focus controls on the risks that matter most to the business rather than spreading effort evenly across low-impact issues. Leaders also tend to get faster and more consistent responses to regulator, audit, and stakeholder questions because governance artifacts are standardized. In mature implementations, this can reduce repeat findings and improve confidence in the control environment.

Training Methodology

This is a practical, outcome-driven course designed to turn governance aspirations into measurable action and credible reporting.

Methodology includes:

  • Hands-on maturity assessment exercise using the CMMI-based scoring tool
  • Scenario simulation requiring risk appetite definition for a digital transformation project
  • Control mapping workshop using the CIS Controls and ISO 27001 Annex A
  • Stakeholder mapping exercise to define the RACI matrix for security governance
  • Case study analysis of governance failures in the finance and healthcare sectors
  • Group workshop producing a draft Information Security Governance Charter
  • Reflection exercise benchmarking current organizational practices against COBIT 2019 standards

Upcoming Sessions

Next available dates worldwide

Virtual

(Zoom) Training
USD 850
18th Jul-9th Aug 2026

Nairobi

Kenya
USD 1,600
29th Jun-3rd Jul 2026

Kigali

Rwanda
USD 1,900
29th Jun-3rd Jul 2026

Dubai

United Arab Emirates (UAE)
USD 4,100
29th Jun-3rd Jul 2026

Addis Ababa

Ethiopia
USD 2,500
20th Jul-24th Jul 2026

Zanzibar

Tanzania
USD 2,400
20th Jul-24th Jul 2026

Abuja

Nigeria
USD 2,800
27th Jul-31st Jul 2026

Mombasa

Kenya
USD 1,700
20th Jul-24th Jul 2026

Cape Town

South Africa
USD 3,900
27th Jul-31st Jul 2026

Johannesburg

South Africa
USD 3,500
20th Jul-24th Jul 2026

Kampala

Uganda
USD 1,900
29th Jun-3rd Jul 2026

Pretoria

South Africa
USD 3,300
29th Jun-3rd Jul 2026

Lagos

Nigeria
USD 2,500
29th Jun-3rd Jul 2026

Certification

Recognized credentials that advance your career

Participants who complete the Information Security Governance and Controls Training Program earn a Trainingcred Certificate of Achievement, demonstrating professional competence and alignment with global standards in learning and development.

NITA Accredited

Accredited by the National Industrial Training Authority, ensuring programs meet nationally recognized standards of quality and relevance.

CPD Certified

Recognized by the CPD Certification Service, ensuring every program meets internationally benchmarked standards of professional excellence.

Why this course earns its place on your CV

Accredited training, practitioner trainers, and peers on the same career track — the three things real expertise is built on.

Strategic Skills Relevance

  • Master governance frameworks that align security initiatives with business objectives.
  • Learn to design, implement, and audit effective information security controls.
  • Bridge the gap between technical security measures and executive-level decision-making.

Career Advancement

  • Position yourself for senior roles in information security management and leadership.
  • Gain expertise employers actively seek for governance, risk, and compliance positions.
  • Differentiate your profile in a rapidly growing cybersecurity job market.

Practical Credibility

  • Apply real-world control frameworks directly to your organization from day one.
  • Train with industry-aligned content rooted in established security governance standards.
  • Build confidence to lead security audits, policy reviews, and risk assessments.

Tools and platforms relevant to this field

Examples United Kingdom teams may encounter, and that may be featured in training where they support the confirmed course scope.

4

These are field-relevant examples, not a promise that every tool will be covered. Exact coverage depends on the confirmed course scope, participant needs, and delivery format.

  • Microsoft Purview Microsoft
    Used to support information governance, data classification, retention, and compliance controls across Microsoft 365 environments.
  • ServiceNow GRC ServiceNow
    Used to manage governance, risk, and compliance workflows, including control testing, issues, and remediation tracking.
  • OneTrust OneTrust
    Used for privacy, third-party risk, and compliance management where organisations need structured evidence for governance and assurance.
  • Archer RSA
    Used for enterprise risk management and control oversight, especially in larger regulated organisations.

Real Results from Real Professionals

Thousands of professionals have transformed their careers through our training programs. Now, it's your turn.

Local market advisory

Course relevance for United Kingdom

A country-specific view of market pressure, regulatory context, and practical business return behind this training.

  • Market context
  • Regulatory fit
  • Business application

Why this course matters in United Kingdom

A market-specific advisory on the operating pressures this course helps teams address.

Information Security Governance matters in the United Kingdom because boards and senior leaders are under sustained pressure to show that cyber spending reduces real business risk, not just technical exposure. The UK market’s mix of regulated financial services, critical national infrastructure, and digitally dependent public services makes governance, risk ownership, and audit-ready controls especially important. This course is most relevant to boards, risk and compliance teams, IT auditors, and security leaders who need a common framework for decisions about risk appetite, control assurance, and accountability. It helps leaders judge whether their control environment is resilient enough to withstand regulatory scrutiny, operational disruption, and board-level challenge.
Board oversight is a business issue, not just an IT issue

UK organisations increasingly need directors and senior managers to evidence cyber oversight, which makes governance training relevant to board members, company secretaries, internal audit, and risk committees rather than only security teams.

Regulated sectors need defensible control assurance

In UK financial services and other regulated sectors, leaders must be able to explain how policies, controls, and monitoring map to business risk, making ISO/IEC 27001-style governance structures and audit trails highly practical.

Operational resilience raises the value of formal GRC

Where service continuity, third-party dependence, and incident recovery are board priorities, this course helps teams connect security controls to resilience outcomes, not just compliance checklists.

This training is timely in the UK because cyber governance expectations are rising across regulated industries and public-sector organisations, while boards are being asked to evidence stronger oversight of digital risk. It is also relevant where organisations are aligning security controls with audit, resilience, and compliance demands rather than treating security as a purely technical function.

Regulatory context in United Kingdom

The local regulators, laws, and frameworks shaping this discipline, with the curriculum mapped to what teams need to know.

5

Regulators

  • ICO The ICO matters because it oversees UK data protection and privacy compliance, both of which are central to information security governance and control design.
  • NCSC The NCSC matters because it provides UK cyber security guidance and good practice that organisations use to shape governance, risk management, and control frameworks.
  • FCA The FCA matters for financial services organisations that must demonstrate effective operational and technology risk governance.
  • PRA The PRA matters for banks and insurers that need strong board oversight, risk management, and operational resilience.
  • ONR The ONR matters for high-assurance sectors where cyber governance supports safety, resilience, and critical infrastructure protection.

Frameworks the course aligns with

  • 01 UK General Data Protection Regulation · 2018
  • 02 Data Protection Act 2018 · 2018
  • 03 Network and Information Systems Regulations 2018 · 2018
  • 04 Financial Services and Markets Act 2000 · 2000

Frequently Asked Questions

Got questions? We've gathered the answers to common queries to help you feel confident and informed.

It is designed primarily for leaders, managers, and assurance professionals who need to oversee security rather than configure tools. Technical staff also benefit if they are moving into governance, risk, or audit-facing roles.

It helps participants build the governance structure, evidence, and accountability needed to respond to compliance demands in a disciplined way. The main value is in showing how controls are overseen, tested, and improved over time.

No. It complements technical training by focusing on decision-making, oversight, and control assurance at management and board level. It is most effective when combined with strong operational security capability.

It helps leaders answer questions such as which risks matter most, who owns them, whether controls are working, and how to evidence that to auditors or directors. That makes it useful for governance, compliance, and resilience planning.

Trusted by 100+ organizations across 40+ countries

Premier Bank
Amnesty International
UNDT SACCO
UNFPA
USAID
AMREF Health Africa
KENTRADE
CPF
UFIA
UNICEF
Central Bank of Kenya
UNDP
GIZ
Premier Bank
Amnesty International
UNDT SACCO
UNFPA
USAID
AMREF Health Africa
KENTRADE
CPF
UFIA
UNICEF
Central Bank of Kenya
UNDP
GIZ
Barbours
Bank of Rwanda
RFA
Dahabshil Bank
Dorcas Aid
Finn Church Aid
KCB Foundation
Ministry of Education Saudi Arabia
NSSF Uganda
RBA
Reserve Bank of Malawi
WASREB Kenya
Virginia Commonwealth University
Barbours
Bank of Rwanda
RFA
Dahabshil Bank
Dorcas Aid
Finn Church Aid
KCB Foundation
Ministry of Education Saudi Arabia
NSSF Uganda
RBA
Reserve Bank of Malawi
WASREB Kenya
Virginia Commonwealth University