Who is this course for?
Application Security Lead
Embed security across the application lifecycle
AppSec Engineer
Build secure SDLC programs from scratch
Secure SDLC Manager
Own application security controls and reviews
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.
Application Security Lead
Embed security across the application lifecycle
AppSec Engineer
Build secure SDLC programs from scratch
Secure SDLC Manager
Own application security controls and reviews
Upcoming dates you can join soon.
Can't attend these dates? Self-study is available year-round.
This course runs multiple times per year, onsite and online.
No date works for you?
Request a private or flexible session
Train with practitioners. Pass with confidence.
Abilene Academy is the only PECB Titanium Partner in Switzerland — the highest accreditation tier in the industry — delivering certified training in information security, data protection, AI governance, and GRC compliance. 99% exam pass rate. 2,500+ professionals trained across 120+ countries and trusted by 600+ organizations. Multilingual programmes available.
Implement and manage application security controls using ISO/IEC 27034
This ISO 27034 Lead Application Security Implementer session runs classroom and virtual-live in Lausanne / Morges - Switzerland on 16 November 2026 – 19 November 2026. Delivered in EN.
Application security is no longer a purely technical concern. In the 2024–2025 landscape, regulators, customers, and auditors increasingly expect organizations to demonstrate structured, repeatable, and reviewable application security practices. ISO/IEC 27034 provides the governance framework to meet these expectations, but many organizations struggle to translate its principles into operational reality.
This course focuses on that translation. Participants work through how an application security program is planned, implemented, operated, and improved using ISO 27034 as a management framework rather than a checklist. The training emphasizes the creation and governance of the Organization Normative Framework, which defines security rules, responsibilities, and application security controls across the organization.
Rather than studying controls in isolation, participants apply ISO 27034 across the application security lifecycle. They examine how security requirements are defined at organizational level, tailored at application level, embedded into development and maintenance activities, and verified over time. Incident management, monitoring, and internal audit are treated as integral components of application security governance, not as afterthoughts.
Abilene Academy’s approach is implementation-driven. Exercises are built around a full case study, requiring participants to make design decisions, justify control choices, and document evidence expected during audits or management review. Trainers draw directly from consulting experience, highlighting common implementation pitfalls and governance failures seen in real organizations.
By the end of the course, participants are equipped to operate an ISO 27034-aligned application security program that is defensible, auditable, and aligned with organizational risk and delivery constraints.
Upon successfully completing the training course, you will be able to explain the key concepts and principles of application security based on ISO/IEC 27034 and interpret ISO/IEC 27034 guidelines for an application security program from the perspective of an implementer.
You will learn to initiate and plan implementation of an application security program by utilizing best practices, and support an organization in operating, maintaining, and continually improving an application security program based on ISO/IEC 27034.
ISO 27001 Lead Implementer · ISO 27001 Lead Auditor · ISO 27002 Lead Manager · ISO 27005 Risk Manager · ISO 31000 Lead Risk Manager
Christophe Mazzola isn’t your typical CISO; he’s an adventurer with a knack for translating IT gobbledygook into plain, everyday language. Christophe’s mission is to simplify cybersecurity for everyone. A multi-certified expert, and the soon-to-be author of Être en Cybersécurité, he’s spent the last decade diving deep into the world of cybersecurity. Christophe’s expertise spans across industries—whether it's guiding SaaS companies, military & defense, aerospace, financial or public administration.
Contact us for pricing
View course →4 days
Exam Included · Certification Available