In furtherance of the Strategic Roadmap and Action Plan of the Nigeria Data Protection Commission (NDPC) on human capital, the Commission organised a capacity-building programme on the ISO Certification Journey for the Information Security Management System (ISMS) and Privacy Information Management System (PIMS) for its staff members.
The training is part of the Commission’s efforts to align its information security and privacy management practices with internationally recognised standards, reinforcing the protection of information assets, strengthening organisational resilience, and advancing regulatory effectiveness. Participants explored the requirements of ISO/IEC 27001 and ISO/IEC 27701, including the application of Clauses 4–10, information security risk assessment methodologies, Annex A security controls across organisational, people, physical, and technological domains, and the Commission’s policy framework.
The capacity-building initiative underscores the NDPC’s commitment to embedding global best practices in information security and privacy governance, supporting the Commission’s journey towards internationally recognised certification. It further strengthens institutional accountability, enhances public trust, and advances Nigeria’s digital transformation agenda by fostering a secure and privacy-conscious digital ecosystem.
The training was facilitated by the Chief Consultant at GUUT Technologies Limited, Mr Oluwagbenga Bamgbose.


