Ethics and Law in Artificial Intelligence & Information Security / ISO 27001 Foundation
Program Objectives

This training program is open to anyone interested in expanding their professional skills. The practical examples and exercises are chosen so they map well to the daily work of Financial Controllers; participation is expressly open to everyone, regardless of current professional role. The course teaches methods, tools, and content that can be applied in many different work contexts.

Practical Application for Financial Controllers

The following typical tasks from the daily work of Financial Controllers serve as worked examples in the exercises; they can be adapted to other fields of activity during the course:

  • Rolling forecasts
  • Actual-vs-plan analysis
  • Management reports
  • Margin analyses
  • Variance analyses
Content

The program is divided into two core modules:

  • Ethics and Law in Artificial Intelligence*

This module critically examines the ethical dilemmas posed by modern AI technologies. It provides an overview of the EU AI Act and explores key concepts such as transparency, explainability, data protection, data security, algorithmic fairness, and non-discrimination in AI systems. Participants will learn about ethical principles in AI development and deployment, as well as governance, compliance, and international perspectives.

  • Information Security / ISO 27001 Foundation*

This module focuses on the fundamental concepts and value of information security, along with associated threats and risks. It covers the establishment and operation of information security management systems (ISMS) in accordance with ISO/IEC 27001. Topics include defining information value, protection goals, and security understanding. The course details the structure of management systems, asset identification, data flows, and roles and responsibilities within a security culture. It addresses policy hierarchies, minimum requirements, and the ISO/IEC 27001 standard. Incident management, risk assessment methodologies (threats, vulnerabilities, exposure), risk analysis, and treatment strategies are thoroughly covered. The integration of AI risks into the ISO logic and the implementation of ISO/IEC 27001 are key components. The module also delves into organizational, personnel, physical, and technical security measures, including secure-by-design principles and cryptography. Finally, it covers the measurement of security effectiveness through KPIs/KRIs, evidence collection, audit logic, and exam preparation.

Learning Objectives

Upon completion of this program, participants will be able to:

  • Analyze the ethical and legal landscape of Artificial Intelligence.
  • Understand the implications of the EU AI Act.
  • Evaluate and address issues of transparency, fairness, and data protection in AI systems.
  • Comprehend the core principles and value of information security.
  • Understand the requirements and implementation of an ISO 27001-compliant ISMS.
  • Identify and assess information security threats and risks.
  • Apply appropriate organizational, personnel, physical, and technical security measures.
  • Integrate AI-specific risks into information security management.
  • Prepare for relevant certifications in information security.

Career Prospects

The knowledge and skills acquired in this program are applicable in professional roles involving the development, deployment, management, and governance of AI systems, as well as in information security management. Typical areas of application include IT project management, software development, data analysis, cybersecurity, compliance, and risk management. Positions in consulting and auditing related to AI ethics and information security are also relevant.