ISO/IEC 27001 Information Security Management Training
Practical, audit-ready training for building and maintaining a certifiable Information Security Management System — not a generic awareness course with a compliance badge stuck on it.
Four modules, built around who touches the risk
ISO/IEC 27001 Foundations — the ISMS, Annex A, and the Certification Process
The shared foundation — what the standard requires, how the 2022 revision changed Annex A, and how certification actually works.
ISMS Implementation Team
Risk assessment, the Statement of Applicability, and building the management system that will stand up to a certification audit.
Internal Auditors
Planning and conducting internal audits, gathering evidence, and writing findings that management review can actually act on.
Top Management & Leadership — with Extensive Governance Responsibility
Clause 5 leadership obligations, management review, resourcing, and the business case for certification, covered in depth.
ISO/IEC 27001 Foundations — the ISMS, Annex A, and the Certification Process
ISO/IEC 27001 is the internationally recognised standard for an Information Security Management System — a systematic, risk-based approach to protecting information, run on a Plan-Do-Check-Act cycle of continual improvement rather than a one-time checklist. The 2022 revision restructured Annex A from 114 controls under 14 categories down to 93 controls grouped into four themes — Organizational, People, Physical, and Technological — and organisations certified to the 2013 edition had until 31 October 2025 to transition or lose their certification. Organisations pursue certification for three overlapping reasons: it is increasingly a contractual precondition for enterprise and government customers, it demonstrates a defensible standard of care to regulators and insurers, and it gives boards a structured way to govern a risk that used to live only in IT. This module gives every participant — whichever track they move into next — the shared vocabulary, the current Annex A structure, and a realistic picture of what a Stage 1 and Stage 2 certification audit actually involves.
Core Risk Areas Covered
Access Control
Managing who can reach what — user registration, privileged access, authentication, and the technological controls that enforce least privilege.
Cryptography
Policy on when and how encryption is applied, and key management practices that keep it effective rather than theatrical.
Supplier Relationships & Third-Party Risk
Security requirements in supplier agreements, and monitoring, reviewing, and managing change in ICT supply chains.
Incident Management
Planning, detecting, assessing, and responding to information security events so that incidents are handled consistently, not improvised.
Business Continuity
ICT readiness for business continuity — a new 2022 control — and keeping information security intact when operations are disrupted.
Human Resource Security
Screening before employment, security responsibilities during employment, and disciplinary and termination processes that close access on the way out.
The Regulatory Landscape, Explained Plainly
GDPR Article 32 — Security of Processing
Article 32 requires 'appropriate technical and organisational measures' including risk assessment, encryption, resilience, and regular testing — the same substance an ISO/IEC 27001 ISMS is built to produce, though certification alone does not satisfy every GDPR obligation (e.g. data-subject rights).
EU NIS2 Directive — Article 21 Risk-Management Measures
Article 21(2) sets ten minimum cybersecurity risk-management measures for essential and important entities; ISO/IEC 27001's Annex A controls map closely onto them, making a certified ISMS a practical route toward demonstrating NIS2 compliance, alongside NIS2-specific obligations such as incident reporting timelines.
India's IT Act — SPDI Rules, 2011
Rule 8 of India's Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules names IS/ISO/IEC 27001 directly: a body corporate implementing and certifying to it is deemed to have complied with the 'reasonable security practices' required under Section 43A of the IT Act, 2000.
Regulatory emphasis is tailored to your country and jurisdiction — tell us where you operate in the form below and we'll scope the frameworks that matter most to you.
Built Around Who Actually Touches the Risk
After the shared foundation, participants split into focused tracks — each built from the systems and decisions that group actually owns.
ISMS Implementation Team
Information Security Managers · ISMS Project Leads · IT Risk Owners
Internal Auditors
Internal Audit Team Members · Compliance Reviewers · ISMS Champions
"Why split the training this way? The team implementing the ISMS needs to reason about which of 93 controls actually apply to their risk profile and defend that reasoning in a Statement of Applicability; the internal auditor needs to independently test whether those controls are actually operating, and write a finding that survives scrutiny from a certification body. Combining both audiences into one generic session either bores the implementers with audit mechanics or gives auditors implementation training that compromises their objectivity — so each track is built around the decisions and deliverables that role actually owns."
ISMS Implementation Team — Scenarios
Internal Auditors — Scenarios
Format for These Tracks
Top Management & Leadership
Executives · Board Members · ISMS Sponsors · Compliance Leadership
ISO/IEC 27001 places specific, non-delegable obligations on top management under Clause 5 — leadership commitment isn't a signature on a policy, it's an ongoing accountability that auditors specifically test for. Boards that treat certification as an IT project rather than a governance responsibility routinely fail their first Stage 2 audit, or pass it with an ISMS too thin to survive a real incident. This track goes deeper on governance, resourcing, and strategic integration than any other module in the programme.
Covered in Depth
- Instructor-led workshops
- Self-paced e-learning modules
- Scenario & tabletop exercises
- Role-specific refreshers
All four modules can be delivered together as a full program, or the role-specific tracks can be licensed independently for organisations that only need one audience covered.
The stakes behind the training
One Standard, Four Themes, 93 Controls
The 2022 restructuring consolidated a decade of scattered controls into a coherent framework — training built around that structure, not the outdated 2013 one.
Certification Is a Governance Exercise, Not a Paperwork Exercise
Auditors test whether leadership actually runs the PDCA cycle — this module treats management review and resourcing as first-class training content, not an afterthought.
Roles, Not Just Controls
A Statement of Applicability and an internal audit finding are only as good as the person who produced them. Training targets exactly those two roles.
Bring this training to your ISMS implementation team, internal audit function, or leadership.
Schedule a consultation to scope the right modules ahead of your next certification or surveillance audit. Tell us your country and we'll tailor the regulatory focus and delivery format to your region.
Modular by design
Run the full four-module program, or license just the tracks your organisation needs — built on the shared foundation module.
Looking for a different programme?
Explore our full range of accredited training categories.
