Request a Consultation
Compliance-Based Training

ISO/IEC 27001 Information Security Management Training

Practical, audit-ready training for building and maintaining a certifiable Information Security Management System — not a generic awareness course with a compliance badge stuck on it.

93
Annex A controls across 4 themes in the current ISO/IEC 27001:2022 standard (ISO/IEC 27001:2022)
96,709
Valid ISO/IEC 27001 certificates recorded worldwide (ISO Survey 2024)
31 Oct 2025
Deadline by which certification bodies stopped recognising the 2013 edition (IAF/ISO transition resolution)
1
Foundation Module — completed by every participant before entering their role-specific track

ISO/IEC 27001 Foundations — the ISMS, Annex A, and the Certification Process

ISO/IEC 27001 is the internationally recognised standard for an Information Security Management System — a systematic, risk-based approach to protecting information, run on a Plan-Do-Check-Act cycle of continual improvement rather than a one-time checklist. The 2022 revision restructured Annex A from 114 controls under 14 categories down to 93 controls grouped into four themes — Organizational, People, Physical, and Technological — and organisations certified to the 2013 edition had until 31 October 2025 to transition or lose their certification. Organisations pursue certification for three overlapping reasons: it is increasingly a contractual precondition for enterprise and government customers, it demonstrates a defensible standard of care to regulators and insurers, and it gives boards a structured way to govern a risk that used to live only in IT. This module gives every participant — whichever track they move into next — the shared vocabulary, the current Annex A structure, and a realistic picture of what a Stage 1 and Stage 2 certification audit actually involves.

93
Annex A controls in ISO/IEC 27001:2022, down from 114 in the 2013 edition, organised into 4 themes (ISO/IEC 27001:2022)
96,709
Valid ISO/IEC 27001 certificates recorded across 179,877 sites worldwide (ISO Survey 2024)
31 Oct 2025
Final date certification bodies could still issue or maintain certificates against ISO/IEC 27001:2013

Core Risk Areas Covered

Access Control

Managing who can reach what — user registration, privileged access, authentication, and the technological controls that enforce least privilege.

Cryptography

Policy on when and how encryption is applied, and key management practices that keep it effective rather than theatrical.

Supplier Relationships & Third-Party Risk

Security requirements in supplier agreements, and monitoring, reviewing, and managing change in ICT supply chains.

Incident Management

Planning, detecting, assessing, and responding to information security events so that incidents are handled consistently, not improvised.

Business Continuity

ICT readiness for business continuity — a new 2022 control — and keeping information security intact when operations are disrupted.

Human Resource Security

Screening before employment, security responsibilities during employment, and disciplinary and termination processes that close access on the way out.

The Regulatory Landscape, Explained Plainly

GDPR Article 32 — Security of Processing

Article 32 requires 'appropriate technical and organisational measures' including risk assessment, encryption, resilience, and regular testing — the same substance an ISO/IEC 27001 ISMS is built to produce, though certification alone does not satisfy every GDPR obligation (e.g. data-subject rights).

EU NIS2 Directive — Article 21 Risk-Management Measures

Article 21(2) sets ten minimum cybersecurity risk-management measures for essential and important entities; ISO/IEC 27001's Annex A controls map closely onto them, making a certified ISMS a practical route toward demonstrating NIS2 compliance, alongside NIS2-specific obligations such as incident reporting timelines.

India's IT Act — SPDI Rules, 2011

Rule 8 of India's Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules names IS/ISO/IEC 27001 directly: a body corporate implementing and certifying to it is deemed to have complied with the 'reasonable security practices' required under Section 43A of the IT Act, 2000.

Regulatory emphasis is tailored to your country and jurisdiction — tell us where you operate in the form below and we'll scope the frameworks that matter most to you.

Role-Specific Tracks

Built Around Who Actually Touches the Risk

After the shared foundation, participants split into focused tracks — each built from the systems and decisions that group actually owns.

2

ISMS Implementation Team

Information Security Managers · ISMS Project Leads · IT Risk Owners

Risk assessment methodology: identifying, analysing, and evaluating information security risks
Building and maintaining the asset inventory and information classification scheme
Producing the Statement of Applicability (SoA) — selecting, justifying, and excluding Annex A controls
Implementing Annex A controls across the Organizational, People, Physical, and Technological themes
Documented information requirements — policies, records, and version control that survive an audit
Working with certification bodies through Stage 1 (documentation review) and Stage 2 (implementation) audits
3

Internal Auditors

Internal Audit Team Members · Compliance Reviewers · ISMS Champions

Internal audit planning and scoping against the ISMS audit programme
Evidence-gathering techniques: interviews, document review, and observation in practice
Writing non-conformity reports that are specific, evidenced, and actionable
Applying ISO 19011 audit principles — integrity, fair presentation, and evidence-based conclusions
Auditor independence and competency requirements for a credible internal audit function
Tracking corrective actions to closure and verifying their effectiveness

"Why split the training this way? The team implementing the ISMS needs to reason about which of 93 controls actually apply to their risk profile and defend that reasoning in a Statement of Applicability; the internal auditor needs to independently test whether those controls are actually operating, and write a finding that survives scrutiny from a certification body. Combining both audiences into one generic session either bores the implementers with audit mechanics or gives auditors implementation training that compromises their objectivity — so each track is built around the decisions and deliverables that role actually owns."

ISMS Implementation Team — Scenarios

A newly onboarded SaaS vendor processes customer data — does it belong in the SoA and risk register?
A control is marked 'implemented' in the SoA but no evidence exists to demonstrate it
A Stage 2 auditor asks for the risk treatment plan behind a specific Annex A control selection

Internal Auditors — Scenarios

An access review log shows a terminated employee's account was disabled four days late
A department claims a control is 'not applicable' with no documented justification
A corrective action from last year's audit was closed without evidence it actually worked

Format for These Tracks

On-site or remote Audit-cycle-aligned sessions Virtual instructor-led Self-paced e-learning
4
With extensive, in-depth coverage — the discipline this role depends on most

Top Management & Leadership

Executives · Board Members · ISMS Sponsors · Compliance Leadership

ISO/IEC 27001 places specific, non-delegable obligations on top management under Clause 5 — leadership commitment isn't a signature on a policy, it's an ongoing accountability that auditors specifically test for. Boards that treat certification as an IT project rather than a governance responsibility routinely fail their first Stage 2 audit, or pass it with an ISMS too thin to survive a real incident. This track goes deeper on governance, resourcing, and strategic integration than any other module in the programme.

Covered in Depth

Management review requirements — what Clause 9.3 requires as inputs and outputs, and how often
Risk acceptance and residual risk sign-off — the decisions only top management can make
Resourcing the ISMS: budget, staffing, and competency planning that an auditor will ask to see evidence of
Demonstrating leadership commitment under Clause 5 — the specific behaviours auditors look for
Continual improvement and the Plan-Do-Check-Act cycle as an ongoing management discipline, not a project phase
Integrating ISO/IEC 27001 with business strategy rather than running it as a parallel compliance track
Communicating certification to customers, regulators, and the board — what it does and doesn't guarantee
Building the budget and ROI case for certification: contractual access, insurance posture, and audit cost avoidance
Delivery Format
  • Instructor-led workshops
  • Self-paced e-learning modules
  • Scenario & tabletop exercises
  • Role-specific refreshers

All four modules can be delivered together as a full program, or the role-specific tracks can be licensed independently for organisations that only need one audience covered.

Why It Matters at This Scale

The stakes behind the training

One Standard, Four Themes, 93 Controls

The 2022 restructuring consolidated a decade of scattered controls into a coherent framework — training built around that structure, not the outdated 2013 one.

Certification Is a Governance Exercise, Not a Paperwork Exercise

Auditors test whether leadership actually runs the PDCA cycle — this module treats management review and resourcing as first-class training content, not an afterthought.

Roles, Not Just Controls

A Statement of Applicability and an internal audit finding are only as good as the person who produced them. Training targets exactly those two roles.

Register Interest

Bring this training to your ISMS implementation team, internal audit function, or leadership.

Schedule a consultation to scope the right modules ahead of your next certification or surveillance audit. Tell us your country and we'll tailor the regulatory focus and delivery format to your region.

Modular by design

Run the full four-module program, or license just the tracks your organisation needs — built on the shared foundation module.

We reply within one business day. Prefer email? Write to info@thecyberdiplomat.com.

Looking for a different programme?

Explore our full range of accredited training categories.

View All Training