top of page
Search

Managing Information Security with ISO 27001: Building a Risk-Based Information Security Management System

Information Security Requires More Than Cybersecurity Tools

Organizations invest heavily in firewalls, endpoint protection, identity-management systems, encryption, monitoring platforms, backup systems, and security-awareness training.


Yet serious information-security weaknesses can remain.


The problem is often not the absence of technology. It is the absence of a coordinated management system that connects:

  • Business objectives

  • Information assets

  • Risk assessment

  • Security policies

  • Assigned responsibilities

  • Technical and administrative controls

  • Incident response

  • Performance monitoring

  • Internal auditing

  • Management review

  • Continual improvement


ISO/IEC 27001 provides a structured approach for managing these interconnected elements through an Information Security Management System, commonly called an ISMS.

Corporate Compliance Seminars will present Managing Information Security (ISO 27001) on Wednesday, September 2, 2026. This live, interactive webinar is designed to help information technology professionals, security managers, auditors, and compliance officers understand ISO/IEC 27001, apply a risk-based approach to information security, strengthen an ISMS, and improve security-incident management. The course page describes the event as a two-hour Group Internet-Based program scheduled from 10:00 a.m. to 12:00 noon Central Time.


The goal is not merely to create more security documentation.


It is to build a management system that helps the organization identify, evaluate, treat, monitor, and communicate information-security risk.


What Is ISO/IEC 27001?

ISO/IEC 27001:2022 is the international standard that establishes requirements for an Information Security Management System.


ISO describes it as a framework organizations can use to establish, implement, maintain, and continually improve an ISMS. It is designed for organizations of different sizes and industries and emphasizes managing risks related to the information an organization owns, processes, stores, or transmits.


Although the standard is frequently called “ISO 27001,” its full designation is ISO/IEC 27001 because it is jointly published by the International Organization for Standardization and the International Electrotechnical Commission.


ISO/IEC 27001 does not prescribe one universal cybersecurity architecture.


Instead, it requires the organization to establish a systematic process for determining:

  • What information must be protected

  • Which threats and vulnerabilities matter

  • What consequences could result

  • Which risks require treatment

  • Which controls are appropriate

  • Who is accountable

  • How effectiveness will be measured

  • How the system will be improved


This risk-based structure is one of the standard’s greatest strengths.


Information Security Is Broader Than Information Technology

Information security is sometimes treated as an information technology responsibility.


That view is incomplete.


Information can be compromised through:

  • Employee error

  • Fraud

  • Weak vendor oversight

  • Poor physical security

  • Unclear policies

  • Excessive access

  • Inadequate training

  • Weak change management

  • Improper record disposal

  • Uncontrolled use of artificial intelligence

  • Incomplete incident response

  • Ineffective governance


A technically secure system can still be exposed when employees share passwords, confidential documents are left unattended, vendors retain unnecessary access, or management has not established clear accountability.


ISO/IEC 27001 promotes a holistic approach involving people, processes, policies, and technology rather than relying exclusively on technical safeguards. ISO identifies risk management, cyber resilience, and organization-wide protection among the principal purposes and benefits of an ISMS.


The Three Core Objectives: Confidentiality, Integrity, and Availability

Information-security programs commonly organize their objectives around three principles.


Confidentiality

Information is accessible only to authorized people, systems, or organizations.


Confidentiality risks include:

  • Unauthorized system access

  • Improper sharing of customer data

  • Excessive employee privileges

  • Stolen credentials

  • Misaddressed email

  • Insecure cloud storage

  • Disclosure by third parties

  • Use of confidential information in unapproved AI tools


Integrity

Information remains accurate, complete, and protected from unauthorized modification.


Integrity risks include:

  • Unauthorized journal entries

  • Altered customer records

  • Corrupted databases

  • Manipulated reports

  • Inadequate change control

  • Poor interface reconciliation

  • Malicious modification of files

  • Unreliable system configurations


Availability

Information and supporting systems are accessible when required.


Availability risks include:

  • Ransomware

  • Hardware failure

  • Network outages

  • Natural disasters

  • Denial-of-service attacks

  • Inadequate backup procedures

  • Vendor outages

  • Poor recovery planning

  • Key-person dependency


ISO explains that an effective ISMS is intended to preserve the confidentiality, integrity, and availability of information through a structured risk-management process.


An organization must consider all three objectives.


Information that is confidential but unavailable may still be useless. Information that is available but inaccurate may cause serious operational or financial harm.


An ISMS Is a Management System, Not a Binder

Some organizations approach ISO/IEC 27001 as a documentation project.


They create:

  • Policies

  • Risk registers

  • Control lists

  • Procedures

  • Meeting minutes

  • Training records

  • Audit reports


Documentation is important, but documentation alone does not create an effective ISMS.


A functioning ISMS should influence actual decisions.


It should help management determine:

  • Which systems receive funding

  • Which risks require escalation

  • Whether a vendor relationship is acceptable

  • How quickly incidents must be reported

  • Who can authorize risk acceptance

  • Which controls should be tested

  • How security performance will be measured

  • Whether corrective actions are effective


The Corporate Compliance Seminars program focuses on building and managing an ISMS aligned with ISO/IEC 27001, including risk management, security controls, incident response, and continual improvement.


Establish the Context of the Organization

A risk-based information-security program begins with understanding the organization.


Management should consider:

  • Business model

  • Products and services

  • Strategic objectives

  • Regulatory environment

  • Geographic footprint

  • Customers

  • Employees

  • Contractors

  • Technology architecture

  • Supply chain

  • Cloud services

  • Data flows

  • Legal obligations

  • Threat environment

  • Risk tolerance


A hospital, community bank, manufacturer, government agency, university, and software company do not face identical information-security risks.


Their ISMS programs should not be identical.


For example, a hospital may focus heavily on patient information, medical-device security, and system availability. A financial institution may emphasize transaction integrity, customer data, fraud prevention, and regulatory reporting. A manufacturer may prioritize operational technology, intellectual property, and supply-chain continuity.

ISO/IEC 27001 allows the ISMS to be adapted to the organization’s size, structure, objectives, and risk environment.


Define the Scope of the ISMS

The ISMS scope establishes its boundaries.


Possible scope elements include:

  • Business units

  • Geographic locations

  • Systems

  • Applications

  • Data centers

  • Cloud environments

  • Products

  • Services

  • Processes

  • Employees

  • Contractors

  • Third parties


A scope that is too broad may make implementation unmanageable.


A scope that is too narrow may exclude important risks or create misleading confidence.


For example, an organization might define its ISMS as covering a customer-facing software platform but exclude the human-resources system, corporate email, and general office network.


That may be appropriate for a specific certification objective, but management must understand that ISO/IEC 27001 conformity within one scope does not automatically mean the entire organization has been evaluated.


The scope should be clear, supportable, and aligned with business needs.

Information Asset Identification Comes Before Control Selection

An organization cannot protect information it has not identified.


Information assets may include:

  • Customer records

  • Employee records

  • Financial information

  • Intellectual property

  • Contracts

  • Research

  • Source code

  • System configurations

  • Authentication credentials

  • Audit evidence

  • Legal records

  • Operational data

  • Backup files

  • Paper records


The organization should determine:

  • Who owns the information?

  • Where is it stored?

  • How is it transmitted?

  • Who can access it?

  • How sensitive is it?

  • How long must it be retained?

  • Which laws or contracts apply?

  • What would happen if it were disclosed, modified, destroyed, or unavailable?


Asset inventories should address more than hardware.


The server is an asset, but the information stored on it may be far more important.


Classify Information According to Risk

Information classification helps an organization apply controls proportionately.


A classification framework may include categories such as:

  • Public

  • Internal

  • Confidential

  • Restricted


The classification should influence:

  • Access restrictions

  • Encryption requirements

  • Sharing procedures

  • Storage locations

  • Retention

  • Disposal

  • Vendor requirements

  • Incident response

  • Monitoring


A policy that labels information “confidential” without defining the required handling procedures provides limited protection.


Employees need practical instructions.


For example:

  • Can the information be emailed externally?

  • Must it be encrypted?

  • Can it be stored on a personal device?

  • Can it be entered into an AI platform?

  • Does it require secure destruction?

  • Which vendors may process it?


Classification must lead to action.


Risk Assessment Is the Foundation of ISO/IEC 27001

A risk assessment should identify events that could compromise the confidentiality, integrity, or availability of information.


A useful risk statement connects:

  • A threat

  • A vulnerability

  • An information asset or process

  • A potential consequence


Weak risk statement:

Cybersecurity risk.

Stronger risk statement:

A threat actor could exploit unpatched vulnerabilities in the public-facing customer portal, obtain unauthorized access to customer information, disrupt services, and create regulatory, financial, and reputational consequences.

The second statement is more useful because it can be evaluated and treated.


The CCS course emphasizes the risk-based approach advocated by ISO/IEC 27001 and practical methods for identifying and addressing cyber threats.


Risk Assessment Should Consider Business Consequences

Information-security risk should not be evaluated solely through technical severity scores.


Management should consider potential effects on:

  • Customers

  • Revenue

  • Operations

  • Financial reporting

  • Regulatory compliance

  • Legal obligations

  • Reputation

  • Safety

  • Strategic objectives

  • Contract performance

  • Public trust


For example, a system vulnerability may have a moderate technical rating but a high business impact when it affects a critical financial-reporting application.


Conversely, a technically severe vulnerability may present limited organizational exposure if the affected system is isolated, contains no sensitive information, and has strong compensating controls.


Risk must be understood in business terms.


Risk Treatment Connects Risks to Action

Once risks have been identified and assessed, management must determine how to address them.


Common risk-treatment options include:


Reduce the Risk

Implement or strengthen controls.


Examples:

  • Multifactor authentication

  • Encryption

  • Network segmentation

  • Security training

  • Vendor monitoring

  • Backup testing


Avoid the Risk

Stop the activity creating the exposure.


Examples:

  • Discontinue an unsupported application.

  • Prohibit storage of sensitive data on personal devices.

  • End a high-risk vendor relationship.


Transfer or Share the Risk

Shift part of the financial or operational exposure.


Examples:

  • Cyber insurance

  • Contractual indemnification

  • Outsourced services


Risk transfer does not eliminate accountability. An organization may outsource processing, but it cannot automatically outsource its legal, regulatory, or reputational responsibility.


Accept the Risk

Management formally accepts the residual exposure.


Risk acceptance should be:

  • Documented

  • Informed

  • Time-limited where appropriate

  • Approved at the correct level

  • Consistent with risk tolerance

  • Subject to monitoring


Risk should not be considered “accepted” merely because no one has taken action.


Security Controls Must Respond to Identified Risks

A common information-security mistake is implementing controls because they are popular, familiar, or included in a checklist.


ISO/IEC 27001 requires a risk-based rationale.


Controls may address areas such as:

  • Governance

  • Policies

  • Roles and responsibilities

  • Asset management

  • Identity and access management

  • Cryptography

  • Physical security

  • Operations security

  • Network security

  • Secure development

  • Supplier relationships

  • Incident management

  • Business continuity

  • Legal and regulatory compliance


The organization should be able to explain:

  • Which risk the control addresses

  • Who owns the control

  • How frequently it operates

  • What evidence demonstrates performance

  • How exceptions are handled

  • How effectiveness is assessed


A control that exists only in policy is not necessarily operating.


The Statement of Applicability Is a Critical Governance Document

In an ISO/IEC 27001 program, the Statement of Applicability records which controls are applicable to the ISMS and explains their implementation status and the rationale for inclusion or exclusion.


It should not be treated as a compliance checklist copied from another organization.


A useful Statement of Applicability should reflect:

  • The organization’s risk assessment

  • Legal and contractual obligations

  • Business requirements

  • Selected treatment decisions

  • Control ownership

  • Implementation status


An unjustified exclusion can create risk.


An unnecessary inclusion can create administrative burden and false expectations.


The organization should be able to defend every control decision.


Leadership Must Demonstrate Ownership

Information security cannot be delegated entirely to the Chief Information Security Officer or IT department.


Senior leadership should:

  • Approve the information-security policy

  • Establish risk tolerance

  • Assign roles and authority

  • Provide resources

  • Review performance

  • Resolve major issues

  • Support corrective action

  • Reinforce accountability

  • Participate in management review


When leadership treats information security as a technical function rather than an enterprise risk, the ISMS may become disconnected from strategy and operations.


Visible management support also influences employee behavior.


Employees are more likely to follow security requirements when leadership follows them as well.


Roles and Responsibilities Must Be Clear

An effective ISMS should establish responsibility for:

  • Information ownership

  • System ownership

  • Risk ownership

  • Control operation

  • Control monitoring

  • Incident response

  • Vendor oversight

  • Access approval

  • Policy maintenance

  • Internal auditing

  • Corrective action

  • Risk acceptance


Ambiguity creates gaps.


For example, IT may believe Human Resources is responsible for notifying it when an employee leaves. Human Resources may believe the manager initiates access removal.


The manager may assume the process is automatic.


The result may be terminated employees retaining system access.


A clear process should identify who initiates, approves, executes, verifies, and monitors the action.


Third-Party Risk Must Be Included in the ISMS

Organizations increasingly depend on:

  • Cloud providers

  • Managed service providers

  • Payroll processors

  • Payment processors

  • Software vendors

  • Consultants

  • Data-storage providers

  • Contractors

  • Business partners


A vendor may store sensitive information, operate critical systems, or possess privileged access.


Third-party security management should consider:

  • Due diligence

  • Contract requirements

  • Security responsibilities

  • Breach notification

  • Access restrictions

  • Data location

  • Subcontractors

  • Business continuity

  • Audit rights

  • Security reports

  • Termination procedures

  • Data return or destruction


A strong internal control environment cannot compensate for unmanaged third-party exposure.


Security Awareness Must Change Behavior

Annual training alone does not establish a security culture.


Effective awareness efforts should help employees understand:

  • Phishing

  • Business-email compromise

  • Password security

  • Data classification

  • Secure remote work

  • Incident reporting

  • Social engineering

  • Physical security

  • Use of removable media

  • Vendor impersonation

  • Artificial intelligence risks


Training should be tailored to responsibilities.


Executives, system administrators, developers, finance employees, call-center staff, and remote workers face different threats.


Organizations should also measure whether the training works.


Possible indicators include:

  • Phishing simulation results

  • Incident-reporting rates

  • Repeated policy violations

  • Completion rates

  • Knowledge assessments

  • Time required to report suspected incidents


Attendance is not the same as effectiveness.


Identity and Access Management Deserves Continuous Attention

Unauthorized or excessive access remains a major information-security risk.


An effective access-management process should address:

  • New users

  • Transfers

  • Terminations

  • Privileged accounts

  • Service accounts

  • Remote access

  • Emergency access

  • Periodic access reviews

  • Segregation of duties

  • Authentication

  • Logging and monitoring


Key questions include:

  • Is access based on job responsibility?

  • Who approves access?

  • Are privileged rights restricted?

  • Are dormant accounts disabled?

  • Are terminated users removed promptly?

  • Are access reviews evidence-based?

  • Are incompatible permissions identified?

  • Are vendor accounts monitored?


A technically advanced identity system can still fail when approvals, ownership, and monitoring are weak.


Security Incident Management Must Be Planned Before the Incident

The middle of a ransomware attack is not the time to decide who should contact legal counsel, regulators, customers, law enforcement, or the insurance carrier.


An incident-response program should define:

  • What constitutes an incident

  • How incidents are reported

  • Who triages the event

  • Severity classifications

  • Escalation criteria

  • Containment procedures

  • Evidence preservation

  • Internal communications

  • External communications

  • Regulatory notifications

  • Recovery

  • Post-incident review


The CCS event includes security-incident management and post-incident recovery as central learning topics.


Incident Response Should Be Tested

A written plan may contain weaknesses that become visible only during an exercise.


Testing methods may include:

  • Tabletop exercises

  • Technical simulations

  • Communications tests

  • Backup restoration tests

  • Vendor participation

  • Executive decision exercises

  • After-action reviews


Exercises can reveal:

  • Outdated contact information

  • Unclear authority

  • Missing dependencies

  • Inadequate backups

  • Contract limitations

  • Communication delays

  • Insufficient logging

  • Unavailable personnel

  • Weak escalation procedures


Each exercise should result in documented improvements.


Business Continuity Supports Information Availability

Information security and business continuity are closely connected.


An organization may prevent unauthorized access yet still fail when critical systems cannot be restored.


Management should understand:

  • Critical business processes

  • Maximum tolerable downtime

  • Recovery-time objectives

  • Recovery-point objectives

  • System dependencies

  • Manual alternatives

  • Backup arrangements

  • Vendor dependencies

  • Crisis communications

  • Recovery priorities


Backups should be:

  • Complete

  • Protected

  • Monitored

  • Separated from production where appropriate

  • Tested through restoration


A backup that has never been successfully restored is an assumption, not assurance.


Measuring ISMS Performance

Organizations cannot manage information security effectively without meaningful performance information.


Useful measures may include:

  • Critical vulnerabilities past due

  • Mean time to detect incidents

  • Mean time to contain incidents

  • Access-removal timeliness

  • Percentage of systems with supported software

  • Security-training completion

  • Phishing simulation failure rates

  • Vendor reviews completed

  • Backup restoration success

  • Open corrective actions

  • Repeat audit findings

  • High-risk exceptions

  • Incident trends


Metrics should support decisions.


A dashboard filled with percentages but no thresholds, trends, ownership, or required actions may create an appearance of oversight without helping management govern risk.


Internal Auditing Strengthens the ISMS

Internal audits help management determine whether the ISMS:

  • Conforms to organizational requirements

  • Aligns with ISO/IEC 27001 requirements

  • Has been implemented

  • Is operating effectively

  • Produces reliable evidence

  • Identifies and corrects deficiencies

  • Supports continual improvement


The audit should be independent of the activities being evaluated to the extent necessary for objectivity.


Audit procedures may include:

  • Reviewing governance

  • Evaluating risk assessments

  • Testing access controls

  • Reviewing vendor oversight

  • Inspecting incident records

  • Examining training

  • Testing backups

  • Reviewing corrective actions

  • Assessing management monitoring


The objective is not merely to determine whether documents exist.


It is to determine whether the management system works.


Management Review Keeps the ISMS Connected to the Business

Senior management should periodically review the ISMS.


A meaningful review may consider:

  • Internal and external changes

  • Risk-assessment results

  • Security incidents

  • Audit findings

  • Corrective actions

  • Performance measures

  • Resource needs

  • Stakeholder concerns

  • Improvement opportunities

  • Changes in legal or contractual requirements


Management review should result in decisions.


Possible outcomes include:

  • Additional funding

  • Revised priorities

  • Policy changes

  • New controls

  • Risk acceptance

  • Corrective-action escalation

  • Changes to scope

  • New performance measures


Meeting minutes without decisions or accountability provide little governance value.


Continual Improvement Is Essential

The threat environment, technology, organization, and legal landscape continue to change.


An ISMS must evolve with them.


Improvement opportunities may emerge from:

  • Incidents

  • Audit results

  • Vulnerability assessments

  • Penetration testing

  • Employee feedback

  • Vendor assessments

  • Regulatory changes

  • Technology changes

  • Management review

  • Corrective-action analysis


Continual improvement does not necessarily require constant major redesign.


It requires the organization to learn, prioritize, and respond systematically.


ISO/IEC 27001 Certification Is Not the Only Reason to Implement an ISMS

Organizations may implement ISO/IEC 27001 to:

  • Pursue certification

  • Meet customer expectations

  • Support regulatory compliance

  • Strengthen governance

  • Improve vendor confidence

  • Reduce security risk

  • Prepare for audits

  • Standardize practices

  • Improve incident readiness

  • Support international business


Certification can demonstrate that an independently assessed management system is in place within a defined scope.


However, the greater objective should be effective risk management.


A certificate should be evidence of a functioning system, not the sole purpose of the system.


Common ISO 27001 Implementation Mistakes

Treating ISO 27001 as an IT Project

Information security requires participation from leadership, legal, compliance, human resources, operations, procurement, and business management.


Copying Another Organization’s ISMS

Templates can help, but policies and controls must reflect the organization’s actual risks and operations.


Beginning with the Control List

Risk assessment and organizational context should inform control selection.


Defining an Artificially Narrow Scope

An overly narrow scope may exclude significant dependencies and create misleading assurance.


Failing to Assign Risk Owners

Risks remain unresolved when no accountable manager has authority to act.


Confusing Documentation with Operation

A documented procedure does not prove that employees follow it.


Weak Incident Exercises

An untested response plan may fail during a real emergency.


Inadequate Vendor Oversight

Outsourced processing can create significant data, continuity, and access risks.


Ignoring Corrective Actions

Repeated findings indicate that the ISMS is not learning effectively.


Focusing Only on Certification

The management system should improve security and resilience—not simply prepare the organization for an external audit.


What Participants Will Learn

The Managing Information Security (ISO 27001) webinar is designed to help attendees:

  • Develop a stronger understanding of ISO/IEC 27001.

  • Apply a risk-based approach to information security.

  • Understand how an ISMS is established and improved.

  • Align an information-security program with ISMS requirements.

  • Understand the role of security controls.

  • Strengthen incident-management practices.

  • Improve post-incident recovery.

  • Support confidentiality, integrity, and availability.

  • Apply information-security concepts within organizational governance.


The course agenda covers understanding ISO 27001, implementing an effective ISMS, and moving forward through incident management and compliance.


Who Should Attend?

The webinar is relevant to:

  • Information technology professionals

  • Information-security managers

  • Cybersecurity professionals

  • Internal auditors

  • IT auditors

  • Compliance officers

  • Risk-management professionals

  • Privacy professionals

  • Controllers

  • Finance leaders

  • Business-continuity professionals

  • Managers responsible for sensitive information

  • Professionals supporting ISO certification


The event page specifically identifies IT professionals, security managers, and compliance officers as primary audiences.


Information Security Must Be Managed as a Business Risk

Cybersecurity tools matter.


But tools alone do not create governance, define accountability, establish risk tolerance, validate control performance, prepare employees, manage vendors, or ensure that lessons are learned after an incident.


An effective ISMS brings those activities together.


ISO/IEC 27001 gives organizations a structured way to:

  • Understand their environment

  • Identify important information

  • Assess risk

  • Select proportionate controls

  • Assign accountability

  • Prepare for incidents

  • Monitor performance

  • Audit results

  • Correct weaknesses

  • Improve continuously


The result should be more than compliance.


It should be a stronger, more resilient organization.


Register for Managing Information Security (ISO 27001)

Corporate Compliance Seminars’ Managing Information Security (ISO 27001) webinar provides a practical introduction to risk-based information-security management.


Participants will examine the purpose of ISO/IEC 27001, the structure and operation of an ISMS, security-risk assessment, control implementation, incident management, recovery, compliance, and continual improvement.



Information security cannot be managed through technology alone.


It must be governed as an enterprise-wide system of people, processes, risks, controls, evidence, and continuous improvement.


Frequently Asked Questions

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard that defines requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System.


What is an ISMS?

An ISMS is a coordinated management system used to identify, assess, treat, monitor, and continually improve information-security risk. It connects governance, policies, employees, technology, controls, incident response, auditing, and management oversight.


Is ISO 27001 only for technology companies?

No. ISO/IEC 27001 is designed for organizations of different sizes and sectors because virtually every organization depends on information and technology.


Does ISO 27001 require certification?

An organization may use the standard to improve its information-security management without immediately pursuing certification. Certification is one method of demonstrating conformity within a defined scope.


What are confidentiality, integrity, and availability?

Confidentiality protects information from unauthorized disclosure. Integrity protects information from improper modification. Availability ensures that information and systems can be accessed when needed.


What is a risk-based approach to information security?

A risk-based approach identifies important assets, threats, vulnerabilities, and potential consequences before selecting controls. This helps the organization direct resources toward its most significant exposures.


What is the Statement of Applicability?

The Statement of Applicability documents which security controls are relevant to the organization’s ISMS, their implementation status, and the rationale for including or excluding them.


Why is incident management important?

Incident management helps an organization identify, report, contain, investigate, recover from, and learn from information-security events. The course includes incident response and post-incident recovery among its principal topics.


Who should attend this course?

The course is appropriate for IT professionals, security managers, internal and IT auditors, compliance officers, risk professionals, finance leaders, and managers responsible for information security.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page