ISO/IEC 27001
Build, run and audit an information security management system that stands up to scrutiny.
ISO/IEC 27001: what it is and why it matters
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system. It is the standard organisations are most often audited against when a customer, regulator or board asks for independent assurance of how information risk is managed.
This course area helps you understand what the standard asks of management, how the risk-based approach works, and how the Annex A controls (aligned with ISO/IEC 27002) fit around the management system rather than replace it.
Built for the people who carry the work
- Information security, risk and compliance managers preparing for or maintaining certification
- Internal auditors and consultants who assess an ISMS
- Project leads who own scoping, risk treatment or the statement of applicability
- Executives and process owners who need to know what the standard expects of them
What you will be able to do
- Explain the structure of the standard and how clauses 4 to 10 form a management cycle
- Define an ISMS scope, context and interested-party requirements
- Run a risk assessment and risk treatment process and record decisions in a statement of applicability
- Select and justify controls from Annex A and map them to evidence
- Plan internal audits, management review and corrective action
- Prepare an organisation for a certification audit
Subject outline
- 01
Context, scope and leadership commitment
- 02
Information security policy and objectives
- 03
Risk assessment and risk treatment
- 04
Annex A control themes: organisational, people, physical and technological
- 05
Documented information, competence and awareness
- 06
Operation, monitoring, internal audit and management review
- 07
Nonconformity, corrective action and continual improvement
- 08
Certification audit stages and how to prepare
How it supports real work
Scoping an ISMS around real business services instead of the whole company
Turning a risk register into a defensible statement of applicability
Collecting evidence an auditor will actually accept
Aligning ISO/IEC 27001 with regulatory expectations your sector already has
Training, examination and certification are different steps
Reading the standard, attending training, passing a personal certification exam and certifying an organisation are four different things. Organisations are certified against ISO/IEC 27001 by accredited certification bodies. Individuals may pursue personnel certifications such as implementer or auditor credentials from bodies like PECB; those have their own exam and experience rules.
- Training builds knowledge. It does not by itself award a certificate.
- Personnel certification normally needs a passed exam and, for higher levels, documented experience.
- Organisational certification is awarded after an audit of your ISMS, not after anyone attends a course.
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Is ISO/IEC 27002 certifiable like ISO/IEC 27001?
No. ISO/IEC 27002 is a guidance document of controls. An organisation is certified against the requirements in ISO/IEC 27001, which draws on 27002 for control guidance.
How are the Annex A controls organised in the 2022 edition?
Into four themes: organisational, people, physical and technological.
Does attending this training certify my organisation?
No. Organisational certification comes from an audit by a certification body, not from training.
Will I receive a personal certification after the course?
Not automatically. Personal certification depends on the issuing body, which sets its own exam and eligibility rules. Ask us which route applies before you enrol.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for ISO/IEC 27001.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


