NDPC Trains Staff on ISO Standards to Strengthen Information Security, Data Privacy

The Nigeria Data Protection Commission (NDPC) has organised a capacity-building programme on the ISO Certification Journey for the Information Security Management System (ISMS) and Privacy Information Management System (PIMS) as part of efforts to strengthen information security, privacy governance, and institutional capacity.

The training, held in furtherance of the Commission’s Strategic Roadmap and Action Plan on human capital development, is aimed at aligning the NDPC’s information security and privacy management practices with internationally recognised standards.

During the programme, participants were taken through the requirements of ISO/IEC 27001 and ISO/IEC 27701, with sessions covering the application of Clauses 4–10, information security risk assessment methodologies, Annex A security controls across organisational, people, physical, and technological domains, as well as the Commission’s policy framework.

The Commission said the initiative is designed to reinforce the protection of information assets, strengthen organisational resilience, and enhance regulatory effectiveness in line with global best practices.

According to the NDPC, the training also reflected its commitment to embedding international standards in information security and privacy governance as it progresses towards internationally recognised ISO certification.

The Commission noted that the programme would further promote institutional accountability, boost public confidence in Nigeria’s data protection ecosystem, and support the country’s digital transformation agenda by fostering a secure and privacy-conscious digital environment.

The capacity-building programme was facilitated by the Chief Consultant of GUUT Technologies Limited, Mr. Oluwagbenga Bamgbose.

Related posts