The ISO/IEC 27034 Foundation training course provides participants with an understanding of the fundamental principles of application security and the requirements of ISO/IEC 27034. The course covers key domains, including the concepts and scope of application security, as well as organizational and application-level planning, application security controls, and monitoring of security controls.
Participants will also learn how to verify and align application security practices with organizational objectives and regulatory requirements , including how to tailor an Application Normative Framework (ANF) to define the necessary security controls and processes that help each application meet its Targeted Level of Trust (TLT).
The ISO/IEC 27034 Foundation training course enables participants to understand the fundamental concepts and principles of application security, as well as the structure, components, and requirements of ISO/IEC 27034. This course is designed to prepare professionals to support the implementation and maintenance of application security throughout the software life cycle.
By attending this course, participants will learn how ISO/IEC 27034 aligns with other standards, understand key security principles such as confidentiality, integrity, and availability, and gain insight into the roles involved in managing the Organization Normative Framework (ONF) and Application Normative Framework (ANF).
This training course is intended for:
By the end of this training course, participants will be able to:
There are no prerequisites to participate in this training course.
Day 1: Introduction to application security and ISO/IEC 27034
Day 2: Implementation and verification of application security controls
The “PECB ISO/IEC 27034 Foundation” exam fully meets all the PECB Examination and Certification Program (ECP) requirements. It covers the following competency domains:
Domain 1: Fundamental principles and concepts of application security
Domain 2: Organizational and application security planning, implementation, and monitoring
For specific information about exam type, languages available, and other details, please visit the List of PECB Exams and the Examination Rules and Policies.
After passing the exam, you can apply for the credential shown in the table below. The certificate requirements for PECB ISO/IEC 27034 Foundation are:
| Designation | Exam | Professional experience | MS audit/assessment experience | ASMS project experience | Other requirements |
| PECB Certificate Holder in ISO/IEC 27034 Foundation | Pass the PECB ISO/IEC 27034 Foundation Exam | None | None | None | Signing the PECB Code of Ethics |
Date:
17 Apr
For more information, please get in touch with us at support@pecb.com or visit www.pecb.com.
The PECB Certified ISO/IEC 27034 Lead Auditor training course provides participants with the skills and knowledge to audit application security processes based on ISO/IEC 27034 series.
Participants will learn to assess how application security is governed, implemented, and maintained, focusing on key ISO/IEC 27034 concepts such as the Organizational Normative Framework (ONF), Application Normative Framework (ANF), and Application Security Controls (ASCs). The course draws on auditing principles from ISO 19011 and ISO/IEC 17021-1 to support a structured approach to auditing application security. These standards are used as guidance rather than for certification, as ISO/IEC 27034 itself is not a certifiable standard.
Through practical exercises and scenario-based activities, participants will build competence in conducting application security audits in various organizational contexts.
As application security threats grow increasingly complex, organizations must ensure that all applications, whether internally developed, outsourced, or commercially purchased, are properly secured throughout their lifecycle. ISO/IEC 27034 provides structured guidance for achieving this.
By attending this course, participants will gain the skills to plan, manage, and report on audit activities; evaluate an organization’s ONF, its processes, and components associated with application security, the application security management process (ASMP), and the application’s level of trust.
This training is ideal for professionals seeking to enhance their auditing capabilities, contribute to organizational compliance, and support the ongoing development of application security practices.
This training course is intended for:
By the end of this training course, participants will be able to:
This training course includes essay-type exercises, multiple-choice quizzes, examples and best practices used in application security.
Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions.
The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared for the exam.
PECB offers various training course delivery formats, from traditional classroom settings to modern, technology-driven solutions. To learn more about these formats, please click here.
Participants who attend this course must be familiar with application security concepts and have in-depth knowledge of application security principles.
The PECB Certified ISO/IEC 27034 Lead Auditor training course provides participants with the skills and knowledge to audit application security processes based on ISO/IEC 27034 series.
Participants will learn to assess how application security is governed, implemented, and maintained, focusing on key ISO/IEC 27034 concepts such as the Organizational Normative Framework (ONF), Application Normative Framework (ANF), and Application Security Controls (ASCs). The course draws on auditing principles from ISO 19011 and ISO/IEC 17021-1 to support a structured approach to auditing application security. These standards are used as guidance rather than for certification, as ISO/IEC 27034 itself is not a certifiable standard.
Through practical exercises and scenario-based activities, participants will build competence in conducting application security audits in various organizational contexts.
As application security threats grow increasingly complex, organizations must ensure that all applications, whether internally developed, outsourced, or commercially purchased, are properly secured throughout their lifecycle. ISO/IEC 27034 provides structured guidance for achieving this.
By attending this course, participants will gain the skills to plan, manage, and report on audit activities; evaluate an organization’s ONF, its processes, and components associated with application security, the application security management process (ASMP), and the application’s level of trust.
This training is ideal for professionals seeking to enhance their auditing capabilities, contribute to organizational compliance, and support the ongoing development of application security practices.
This training course is intended for:
By the end of this training course, participants will be able to:
This training course includes essay-type exercises, multiple-choice quizzes, examples and best practices used in application security.
Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions.
The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared for the exam.
PECB offers various training course delivery formats, from traditional classroom settings to modern, technology-driven solutions. To learn more about these formats, please click here.
Participants who attend this course must be familiar with application security concepts and have in-depth knowledge of application security principles.
£1,425 – £2,789.96Price range: £1,425 through £2,789.96
| Credential | Exam | Professional experience | ASMS project experience | Other requirements |
| PECB Certified ISO/IEC 27034 Provisional Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | None | None | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Two years: One years of work experience in Application Security | Project activities: a total of 200 hours | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Lead Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Five years: Two years of work experience in Application Security | Project activities: a total of 300 hours | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Senior Lead Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Ten years: Seven years of work experience in Application Security | Project activities: a total of 1,000 hours | Signing the PECB Code of Ethics |
| Credential | Exam | Professional experience | ASMS project experience | Other requirements |
| PECB Certified ISO/IEC 27034 Provisional Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | None | None | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Two years: One years of work experience in Application Security | Project activities: a total of 200 hours | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Lead Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Five years: Two years of work experience in Application Security | Project activities: a total of 300 hours | Signing the PECB Code of Ethics |
| PECB Certified ISO/IEC 27034 Senior Lead Implementer | PECB Certified ISO/IEC 27034 Lead Implementer Exam or equivalent | Ten years: Seven years of work experience in Application Security | Project activities: a total of 1,000 hours | Signing the PECB Code of Ethics |
£1,425 – £2,789.96Price range: £1,425 through £2,789.96
Save 50% Today! Enroll in "ISO/IEC 27034 Application Security Foundation" now and take advantage of our special offer.