iso 27034 lead implementer traininig

ISO/IEC 27034 Lead Implementer

Mastering the implementation of application security (as) processes, activities & security techniques across the organization based on the International Standard ISO/IEC 27034 – Application Security

Course Description

This five-day intensive course enables the participants to understand specific principles and concepts proposed by ISO/IEC 27034 for AS and understand how they can be implemented, step by step, to help organizations to develop, acquire, implement, use, and maintain trustworthy applications, according to their specific business context, at an acceptable cost. More specifically, the ISO/IEC 27034 framework proposes components and processes to provide verifiable evidences that an application have reached and maintained a targeted level of trust as specified by the organization. The responsibility of a Certified ISO/IEC 27034 Application Security Lead Implementer is to assist organizations to put in place required 27034 framework elements and guide the organization to integrate Application Security Controls (ASC) seamlessly throughout the life cycle of their applications. AS applies not only to the software of an application but also to its other components and contributing factors that impact its security, such as its technological context, its regulatory context, its business context, its specifications, the sensitivity of its data, and the processes and actors supporting its entire life cycle.

Who Should Attend

  • Managers, such as information security managers, project managers, administrators, software development managers, application owners and line managers
  • Provisioning and operation teams such as architects, analysts, programmers, testers, system administrators, DBA, network administrators, and technical personnel

Course Duration

Day 1: Introduction: AS overview and concepts as proposed by ISO/IEC 27034

  • Introduction to ISO/IEC 27034 AS and its global vision
  • Fundamental principles in Information Security
  • Overview, concepts, principles, definitions, scope, components, processes and actors involved in AS
  • Embedded implicit concepts
  • Presentation of the 27034 series: ISO/IEC 27034-1, ISO/IEC 27034-2, ISO/IEC 27034-3, ISO/IEC 27034-4, ISO/IEC 27034-5, ISO/IEC 27034-5-1, ISO/IEC 27034-6.

Day 2: Implementation of AS based on ISO/IEC 27034

  • Security into application project
  • The Application Security Management Process
  • Provisioning and operating an application
  • Maintaining the Actual Level of Trust on the Targeted Level of Trust
  • Development of AS validation

Day 3: Implementation of AS based on ISO/IEC 27034 (cont.)

  • AS at the organization level
  • Goals of AS for an organization
  • The Organization Normative Framework (ONF)
  • The ONF committee
  • The ONF Management process
  • Integration of ISO/IEC 27034 elements into the organization’s existing processes
  • Design, validation, implementation, verification, operation and evolution of ASCs

  • The ASC libraries
  • The AS Traceability matrix
  • Drafting the certification process
  • Cases Study
  • 27034 implementation examples for small and large organizations
  • How 27034 can help to resolve conflicting regulations requirements for an application
  • Developing ASCs
  • Acquiring ASCs

Day 4: AS validation and certification

  • The purpose of internal AS audit
  • Minimize the cost of an audit
  • Be sure you have all expected evidences ready
  • Overview of the AS validation and certification process under 27034.
  • How to help an organization to be certified
  • How to help an application project to be certified
  • Protocols and ASC data structure based on ISO/IEC 27034
  • An free formal languages for ASC communication
  • ISO/27034 proposed XML schemas,
  • data structure, descriptions, graphical representation
  • ISO/IEC 27034 AS final review

Day 5: Certification Exam


ISO 27034 Foundation Certification or a basic knowledge of ISO 27034 is recommended.

Who Should Attend

The “Certified ISO/IEC 27034 Lead Application Security Implementer” exam fully meets the requirements of the PECB Examination and Certification Program (ECP). The exam covers the following competence domains:

  • Domain 1: Fundamental concepts and principles in application security
  • Domain 2: Application Security Control (ASC) and others best practice in AS
  • Domain 3: Preparation of an AS project based on ISO/IEC 27034
  • Domain 4: Implementing an AS project based on ISO/IEC 27034
  • Domain 5: Performance evaluation, monitoring and measurement of an AS project based on ISO/IEC 27034
  • Domain 6: Continual improvement of an AS project based on ISO/IEC 27034
  • Domain 7: Preparing an application project or an organization for an ISO/IEC 27034 certification audit

The “Certified ISO/IEC 27034 Lead Application Security Implementer” exam is available in different languages, including English, French, Spanish and Portuguese

Duration: 3 hours

For more information about the exam, refer to PECB section on ISO 27034 Lead Implementer Exam

For more information about the exam, refer to PECB section on ISO 27034 Lead Implementer Exam

After successfully completing the exam, participants can apply for the credentials of Certified ISO/IEC 27034 Application Security Provisional Implementer, Certified ISO/IEC 27034 Application Security Implementer or Certified ISO/IEC 27034 Application Security Lead Implementer, depending on their level of experience

A certificate will be issued to participants who successfully pass the exam and comply with all the other requirements related to the selected credential