ČR (37 500 Kč)
SR (1 500 €)
A practical five-day course on how to build and demonstrate compliance with NIS2 (Act No. 264/2025 Coll.) and ISO/IEC 27001:2022 using tools that an organization already has in Microsoft 365 — SharePoint Online, Microsoft Purview, Microsoft Entra and Microsoft 365 Copilot. The practical course shows how to build and demonstrate compliance with NIS2 (in the Czech Republic Act No. 264/2025 Coll.) and ISO/IEC 27001:2022 using tools that an organization largely already has in its Microsoft 365 — SharePoint Online, Microsoft Purview, Microsoft Entra and Microsoft 365 Copilot. The emphasis is on real deployment, not on the theory of the standard. Each module ends with a mapping of "capability › NIS2 requirement / control ISO 27001". The course works with AI continuously from day one — from practical tools for metadata (Autofill columns) through the Copilot Skills concept to custom and ready-made AI agents over ISMS content at the end of the week. The participant will take home a functional sample of managed ISMS documentation in SharePoint, a set of classification and DLP policies, access settings according to NIS2, the incident detection and reporting procedure, and experience in using standard tools for continuous compliance measurement (Compliance Manager).
M365 and SharePoint administrators
Security and compliance specialists
ISMS/KB managers
IT managers in organizations newly falling under NIS2
Knowledge within the scope of the courses listed in the sections Previous courses and Related courses
Basic orientation in Microsoft 365 administration (admin center, SharePoint, Entra)
Working with SharePoint Online at the advanced user level
Knowledge of the ISO/IEC 27001 standard is an advantage (not a requirement)
Basic overview of IT security and risk management (optional/an advantage)
GOPAS's own student materials in electronic or printed form
Framework and ISMS basics
Onboarding & access to the tenant — incl. a short introduction, where AI appears in the course (from ISMS design to agents on Friday).
NIS2 and ISO 27001 in practice — what NIS2 (264/2025 Coll.) and ISO 27001:2022 actually require from the organization; NÚKIB role, reporting deadlines, sanctions.
Mapping requirements to Microsoft 365 — mapping matrix requirements › M365 capabilities, licensing reality across pillars.
ISMS design in Microsoft 365 — target state, information architecture for controlled documentation, incl. brief mentions of AI as a design assistant
lab: establishing the ISMS workspace structure.
Managed ISMS documentation in SharePoint Online and Lists
Libraries as a repository of managed documentation — versioning, approval, access control
lab: managed documentation library with versioning and approval.
Content Type Hub and policy standardization — content types for policies and records, centralization across the tenant, incl. Autofill columns as practical AI tools for consistent metadata.
Lists as live evidence and workflow — Asset Register, Risk Register, SoA, incident log
lab: Asset Register and Risk Register with revision workflow, incl. Copilot Skills concept as a complement to workflow and registries.
Classification and Information Protection
Classification and sensitivity labels in Purview — label taxonomy, manual vs. auto-labeling
lab: design a label taxonomy and apply it to the ISMS library.
Data Loss Prevention across M365 — policies, simulation mode, incidents
lab: DLP policy in simulation mode.
Retention, lifecycle and advanced protection — retention policies and labels, records management, comparison with SharePoint Advanced Management
lab: retention policy for ISMS records.
Identity, detection and incidents
Conditional Access and access control — policy design, MFA, break-glass accounts
lab: set of CA policies incl. MFA pilot.
Privileged access and identity protection — PIM, Identity Protection
lab: PIM configuration for privileged roles.
Incident detection, audit and reporting — Unified Audit Log, 24-hour reporting process to NÚKIB
lab: event tracking and reporting documentation.
AI and compliance proofing
AI agents within the tenant — Copilot data boundary vs. Shadow AI, declarative agents
lab: simple compliance agent over ISMS library.
Ready-made agent from Microsoft Marketplace — installation and demo of Normiqa Navigator reference agent, comparison of "build your own" vs. "install ready-made".
Copilot governance and AI risk management — Purview DSPM for AI, labels and DLP for Copilot, admin consent for installed agents.
Compliance Manager and capstone — assessments, improvement actions, compliance score; capstone: linking course artifacts to compliance checks and reporting.
The prices are without VAT.
Didn’t find a suitable date or need training tailored to your team’s specific needs? We’ll be happy to prepare custom training for you.