Live Founding Cohort open, limited seats remaining Back to main site →
Cybersecurity

ISO/IEC 27001 Lead Implementer Practitioner Certification

For the Indian CISO and ISMS Manager who has to build, run and pass an ISO/IEC 27001:2022 certification, not the PECB classroom trainer selling exam prep

₹9,999 Intermediate 6.7 hours 8 modules Founding Cohort: 836 seats left
Founding Cohort, DPDP Class of 2026. The first 1,000 learners to pass the final exam receive a permanent "Founding #N" badge on their certificate. 836 seats remaining.
8
Modules
40
Lessons
40
Exam questions
70%
Pass mark

A citation-anchored, exam-backed practitioner course on ISO/IEC 27001:2022 (with Amendment 1:2024 for climate change) as it actually runs for an Indian enterprise, SaaS, BPO or GCC preparing for first certification by a NABCB-accredited certification body. Not a PECB / BSI five-day exam-prep flyover. This course teaches the working ISMS: how to write the scope statement your CB will accept, staff the four mandatory documented information items under Clause 7.5, run the risk assessment methodology per ISO/IEC 27005:2022 that the auditor will test, build the Statement of Applicability that maps all 93 Annex A controls (organised across the four themes Organizational, People, Physical, Technological) to inclusion or exclusion justification, pass Stage 1 (documentation review) and Stage 2 (operating effectiveness) audits, handle nonconformities, obtain the certificate, and run the three-year certification cycle with annual surveillance. Includes a template pack the student can lift into a live implementation: ISMS Scope Statement, ISMS Manual TOC, Risk Assessment Register, Statement of Applicability (all 93 controls), Risk Treatment Plan, Internal Audit Programme, Management Review Agenda, CAPA Register, Incident Response Playbook, Certification Body RFP + Selection Matrix, Bridging Statement, DPDP Act 2023 to ISO 27701:2025 crosswalk.

Written against primary sources current to 29 August 2026 including ISO/IEC 27001:2022 (October 2022 base standard), ISO/IEC 27001:2022/Amd 1:2024 (February 2024 climate change amendment to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (February 2022, the 93 Annex A controls), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27701:2025 (October 2025 standalone privacy management system, three-year transition to October 2028 for 27701:2019 holders), NABCB Accreditation Symbol mandate from 1 July 2026, and BIS adoption as IS/ISO/IEC 27001:2022. Cross-check case material against public ISO 27001 certificates of Infosys, TCS, Wipro, HCLTech, Zoho, Freshworks, Razorpay and Sprinto. The course pairs naturally with SOC 2 Readiness Practitioner (US enterprise commercial gate), DPDP Act 2023 Compliance (Indian privacy overlay under Annex A.5.34 + ISO 27701:2025), CERT-In Directions Practitioner (Indian incident reporting under A.5.24-A.5.27), and RBI Cybersecurity Framework Practitioner (BFSI overlay).

What you will learn
  • Read the ISO/IEC 27001:2022 standard end-to-end and identify each of the ten main clauses (0 through 10) plus the normative Annex A control set
  • Apply Amendment 1:2024 climate action changes to Clauses 4.1 (climate as internal / external issue) and 4.2 (interested parties climate requirements)
  • Write an ISMS Scope Statement that a NABCB-accredited certification body will accept at Stage 1
  • Staff the four mandatory documented information items under Clause 7.5 (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability)
  • Run a risk assessment methodology per ISO/IEC 27005:2022 that produces a defensible risk register and drives control selection
  • Build a Statement of Applicability mapping all 93 Annex A controls (37 Organizational, 8 People, 14 Physical, 34 Technological) to Include or Exclude with clause-anchored justification
  • Implement the 11 new controls added in ISO/IEC 27002:2022 (threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding)
  • Design the Internal Audit Programme (Clause 9.2) and Management Review agenda (Clause 9.3) that produce operating-effectiveness evidence for Stage 2
  • Select a NABCB-accredited certification body through a formal RFP process scoring Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek and IRQS
  • Prepare for and pass Stage 1 (documentation review) and Stage 2 (operating effectiveness) audits including sample sizes and common nonconformities
  • Handle major and minor nonconformities through the CAPA process and obtain certificate issuance
  • Run the three-year certification cycle (surveillance Year 1 + Year 2, recertification Year 3) with bridging statements between audits
  • Plan the ISO 27701:2025 privacy add-on (standalone since October 2025) with a DPDP Act 2023 crosswalk
  • Anticipate the ISO/IEC 42001 AI Management System as the next layer
Prerequisites
  • Working exposure to an enterprise IT or SaaS environment (identity provider, MFA, cloud infrastructure, ticketing system, change management workflow) — typical for an ISMS Manager, DevOps Lead or CISO
  • Comfort reading a formal management-system standard with clauses and sub-clauses (ISO 9001 or ISO 20000 background is helpful but not required)
  • Familiarity with the concept of a risk register (likelihood x impact scoring, treatment options)
  • Access to your own organisation's information asset inventory, cloud services list, and current security policies is helpful for the practical exercises but not required
Who this is for
  • Indian CISOs and Heads of Security at enterprises, SaaS, BPO/KPO, Global Capability Centres and IT services organisations preparing first-time ISO 27001 certification or maintaining an existing certificate
  • ISMS Managers, ISMS Coordinators and Information Security Officers running the ISMS end to end
  • DevOps, Platform Engineering and Infrastructure Leads who own the technical controls (IAM, MFA, encryption, backup, change management, logging, monitoring) the auditor tests
  • Internal Auditors preparing evidence packs and running the ISMS Internal Audit Programme
  • Consultants at cyber advisory boutiques (KPMG, EY, Deloitte, PwC, mid-tier firms, boutique ISMS specialists) building or expanding an ISO 27001 practice
  • Quality Managers at IT services and BPO organisations who inherit the ISMS from a broader ISO 9001 or ISO 20000 heritage
  • Compliance and Risk Managers at BFSI, healthcare, telecom, retail and manufacturing organisations layering ISO 27001 onto RBI, IRDAI, SEBI, NABH or sector regulatory obligations
  • Sales and Customer Success teams at Indian SaaS responding to European, UK, APAC and Middle East vendor security questionnaires with the ISO 27001 certificate
  • Solutions Architects and Bid Managers responding to government tenders and enterprise RFPs that mandate ISO 27001 certification
About the author
dC
dcomply Cyber Practice
ISMS Design, Certification Readiness and Assurance

The dcomply Cyber Practice authors dcomply Academy courses in the cybersecurity and assurance track. Course material is built from the primary text of ISO/IEC standards (ISO/IEC 27001:2022 including Amendment 1:2024, ISO/IEC 27002:2022, ISO/IEC 27005:2022, ISO/IEC 27006:2015 + A1:2020, ISO/IEC 27701:2025, ISO/IEC 27017:2015 and ISO/IEC 27018:2019), IAF Mandatory Documents applicable to ISMS certification (MD 1, MD 4, MD 5, MD 22), NABCB accreditation policies and the January 2026 NABCB Policy on Transition to ISO/IEC 27701:2025, and the public ISO 27001 certification postures of major Indian IT services companies and SaaS. This course is built for the working practitioner: Indian CISOs and Heads of Security running the ISMS end to end, ISMS Managers and Coordinators preparing first-time certification, DevOps and Infrastructure Engineers who own the technical controls the auditor tests, Internal Auditors preparing evidence packs, consultants at cyber advisory boutiques building an ISO 27001 practice, and quality managers at IT services and BPO organisations who inherit the ISMS from a broader ISO 9001 or ISO 20000 heritage. Every substantive claim is cited to a primary source (ISO clause number, IAF MD reference, NABCB policy PDF, or specific public certification posture) and re-verified on a rolling cycle.

No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 70%.
Curriculum

Syllabus

8 modules, 40 lessons. Click any module to expand.

ISO/IEC 27001 is the international standard for an information security management system. It is the default enterprise procurement gate in Europe, UK, APAC and the Middle East, and a growing requirement for Indian enterprise, BFSI, healthcare and government tenders. This free-preview module walks what ISO 27001 actually is, where the standard comes from, how it compares to SOC 2 and NIST CSF, the substantive changes in the 2022 revision plus the February 2024 climate change amendment, the certification lifecycle (Stage 1, Stage 2, surveillance, recertification), and the operating timeline for a first-time Indian filer.

Free preview.

  1. 1. What ISO/IEC 27001 is and why enterprises demand it 10 min
  2. 2. ISO 27001 vs SOC 2 vs NIST CSF vs ISO 27701 10 min
  3. 3. The 2022 revision plus Amendment 1:2024 10 min
  4. 4. The certification lifecycle 10 min
  5. 5. The operating timeline for a first-time Indian filer 12 min

Clauses 4 through 6 of ISO/IEC 27001:2022 set the strategic layer of the ISMS. Clause 4 defines the scope and organisational context (with Amendment 1:2024 adding climate change consideration). Clause 5 defines top management commitment, ISMS policy and roles.

Clause 6 defines the risk assessment methodology, risk treatment approach and ISMS objectives. This is where certifications are won or lost at Stage 1 documentation review. Weak scope statements, generic ISMS policies and unclear risk methodologies produce the majority of Stage 1 nonconformities.

This module walks each clause with the artefacts that satisfy them.

  1. 1. Clause 4 Context of the organisation (including Amendment 1:2024 climate change) 9 min
  2. 2. Clause 5 Leadership and the ISMS Policy 8 min
  3. 3. Clause 6.1 Actions to address risks and opportunities 7 min
  4. 4. Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology 10 min
  5. 5. Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes 6 min

Clauses 7 through 10 of ISO/IEC 27001:2022 set the operating layer. Clause 7 covers resources, competence, awareness, communication and the four mandatory documented information items. Clause 8 executes the risk assessment methodology and produces the Risk Treatment Plan.

Clause 9 monitors, measures, runs internal audits and management reviews. Clause 10 handles nonconformity, corrective action and continual improvement. Stage 2 audit tests operating effectiveness of these clauses; internal audit programme quality and management review discipline are the two most common Stage 2 findings.

This module walks each clause with the operating cadences and artefacts that satisfy Stage 2.

  1. 1. Clause 7 Support — Resources, competence, awareness, communication 7 min
  2. 2. Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC 8 min
  3. 3. Clause 8 Operation — Executing the plan 7 min
  4. 4. Clause 9 — Monitoring, Internal Audit, Management Review 9 min
  5. 5. Clause 10 Improvement — Nonconformity and CAPA 7 min

ISO/IEC 27002:2022 organises the 93 controls of Annex A across four themes. This module walks the first two: A.5 Organizational (37 controls including policies, roles, threat intelligence, segregation of duties, supplier and cloud services, incident management, business continuity and legal/regulatory compliance) and A.6 People (8 controls including screening, terms of employment, awareness, disciplinary process, remote work and confidentiality agreements). Five of the 11 new controls added in the 2022 revision sit in these themes: A.5.7 Threat intelligence, A.5.23 Cloud services, A.5.30 ICT readiness for business continuity, A.7.4 Physical security monitoring (formally under Physical but grouped here for continuity), and A.5 Supplier updates.

Closes with the Statement of Applicability template covering all 93 controls with include / exclude / justification columns.

  1. 1. A.5 Organizational controls Part 1 (A.5.1 through A.5.20) 9 min
  2. 2. A.5 Organizational controls Part 2 (A.5.21 through A.5.37) 9 min
  3. 3. A.6 People controls (8 controls, A.6.1 through A.6.8) 7 min
  4. 4. The 11 new controls in ISO/IEC 27002:2022 walkthrough 9 min
  5. 5. Building the Statement of Applicability (all 93 controls) 8 min

Themes A.7 Physical (14 controls) and A.8 Technological (34 controls) contain the operational security controls most engineers recognise: perimeter, access, equipment, clear desk, storage disposal, and the full technical stack from IAM through cryptography, logging, backup, change management, secure development and network security. Six of the 11 new controls in the 2022 revision sit here: A.8.9 Configuration management, A.8.10 Information deletion, A.8.11 Data masking, A.8.12 Data leakage prevention, A.8.16 Monitoring activities, A.8.23 Web filtering, A.8.28 Secure coding. Closes with the Control Ownership Matrix (control to owner to evidence source) and cloud-specific alignment to ISO/IEC 27017 (cloud services code of practice) and ISO/IEC 27018 (cloud PII).

  1. 1. A.7 Physical controls (14 controls, A.7.1 through A.7.14) 8 min
  2. 2. A.8 Technological controls Part 1 (A.8.1 through A.8.17) 10 min
  3. 3. A.8 Technological controls Part 2 (A.8.18 through A.8.34) 10 min
  4. 4. Cloud-specific controls and ISO 27017 / 27018 alignment 8 min
  5. 5. Control Ownership Matrix and evidence sources 7 min

Risk assessment is the beating heart of the ISMS. Clause 6.1.2 requires a documented methodology; Clause 8.2 requires periodic execution. This module walks the working methodology per ISO/IEC 27005:2022: asset inventory and classification, threat identification, vulnerability identification, likelihood and impact scoring, inherent risk calculation, control application, residual risk calculation, and risk treatment options (Modify, Retain, Avoid, Share).

Closes with the Buy versus Build decision on GRC tooling covering Vanta, Drata, Sprinto (India-headquartered, popular with Indian SaaS), Secureframe, AuditBoard, Archer, ServiceNow GRC and MetricStream, scored on ISO 27001 module maturity, India presence, DPDP workflow support and cost band.

  1. 1. Choosing a risk methodology (asset-based, scenario-based, hybrid) 8 min
  2. 2. Asset inventory and information classification 7 min
  3. 3. Threat identification, vulnerability identification, likelihood + impact scoring 8 min
  4. 4. Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan 8 min
  5. 5. GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer) 8 min

You cannot self-certify. ISO/IEC 27001 certification requires a certification body accredited by an IAF MLA signatory (NABCB in India). This module walks what NABCB accreditation means, why the IAF MLA matters for international recognition of your certificate, the CB RFP process across Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek and IRQS, the Stage 1 audit (documentation review) with the artefacts the auditor tests and the common findings, the Stage 2 audit (operating effectiveness) with sample sizes and interview walkthroughs, handling major and minor nonconformities through the CAPA process, and certificate issuance.

Includes the CB RFP + Selection Matrix template.

  1. 1. What NABCB accreditation means (and why IAF MLA matters) 7 min
  2. 2. CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS) 8 min
  3. 3. Stage 1 audit — documentation review 8 min
  4. 4. Stage 2 audit — operating effectiveness testing 9 min
  5. 5. Handling nonconformities, CAPA closure, certificate issuance 7 min

Certification is the start, not the end. ISO 27001 runs on a three-year cycle: annual surveillance audits in Years 1 and 2 (typically 30 to 60 percent of the initial audit scope) and full recertification in Year 3. This module walks surveillance and recertification, publishing certification status on your customer trust portal and answering vendor security questionnaires (VSAQ, CAIQ, SIG), the bridging statement between annual audits, the ISO 27701:2025 privacy add-on (standalone since October 2025) with a full DPDP Act 2023 crosswalk, the ISO 27017 (cloud services code of practice) and ISO 27018 (cloud PII) extensions, and the emerging ISO/IEC 42001 AI Management System as the next layer for organisations deploying AI in production.

  1. 1. Surveillance Years 1 + 2, and recertification Year 3 7 min
  2. 2. Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires 7 min
  3. 3. ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk 8 min
  4. 4. ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions 6 min
  5. 5. ISO/IEC 42001 AI Management System as the next horizon 7 min
Frequently Asked

Everything a buyer usually asks

Who is this course for?
Indian CISOs and Heads of Security at enterprises, SaaS, BPO/KPO, Global Capability Centres and IT services organisations preparing first-time ISO 27001 certification or maintaining an existing certificate Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 8 modules covering 40 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 70% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹9,999 founding-cohort price (list price ₹19,999) One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme aimed at working Indian CISOs, ISMS Managers, Heads of Security, DevOps and Infrastructure Leads, Internal Auditors, and consultants at cyber advisory boutiques. Every substantive claim is anchored to a primary source: ISO clause number (e.g. Clause 6.1.2 Risk assessment, Clause 7.5 Documented information, Annex A.8.28 Secure coding), ISO/IEC 27001:2022/Amd 1:2024 climate action changes, NABCB policy PDF, IAF Mandatory Document reference, or specific public ISO 27001 certification posture (Infosys, TCS, Wipro, HCLTech, Zoho, Freshworks, Razorpay, Sprinto). Items flagged as UNVERIFIED in the lesson prose are pending re-verification against the current primary source and must be checked before the student acts on them in a live certification engagement.

The course maintains a 15-item verification checklist covering ISO revision timeline, Amendment 1:2024 currency, ISO 27002:2022 control set stability, ISO 27701:2025 transition rules, NABCB Accreditation Symbol mandate, BIS adoption identity to ISO text, PECB scheme parameters, GRC vendor pricing, and IAF MD applicability. This is not legal, tax, audit, or accounting advice and does not create a professional-client relationship. This course does not confer PECB, IRCA, BSI, TÜV or any other body's personal Lead Implementer or Lead Auditor certification. Those are separate personal-certification schemes governed by ISO/IEC 17024 requiring examination and CPD maintenance directly with the issuing body.

For certification of an organisation to ISO/IEC 27001:2022, engage a NABCB-accredited certification body (or an IAF MLA equivalent) directly.