ISO/IEC 27001 Lead Implementer Practitioner Certification
For the Indian CISO and ISMS Manager who has to build, run and pass an ISO/IEC 27001:2022 certification, not the PECB classroom trainer selling exam prep
A citation-anchored, exam-backed practitioner course on ISO/IEC 27001:2022 (with Amendment 1:2024 for climate change) as it actually runs for an Indian enterprise, SaaS, BPO or GCC preparing for first certification by a NABCB-accredited certification body. Not a PECB / BSI five-day exam-prep flyover. This course teaches the working ISMS: how to write the scope statement your CB will accept, staff the four mandatory documented information items under Clause 7.5, run the risk assessment methodology per ISO/IEC 27005:2022 that the auditor will test, build the Statement of Applicability that maps all 93 Annex A controls (organised across the four themes Organizational, People, Physical, Technological) to inclusion or exclusion justification, pass Stage 1 (documentation review) and Stage 2 (operating effectiveness) audits, handle nonconformities, obtain the certificate, and run the three-year certification cycle with annual surveillance. Includes a template pack the student can lift into a live implementation: ISMS Scope Statement, ISMS Manual TOC, Risk Assessment Register, Statement of Applicability (all 93 controls), Risk Treatment Plan, Internal Audit Programme, Management Review Agenda, CAPA Register, Incident Response Playbook, Certification Body RFP + Selection Matrix, Bridging Statement, DPDP Act 2023 to ISO 27701:2025 crosswalk.
Written against primary sources current to 29 August 2026 including ISO/IEC 27001:2022 (October 2022 base standard), ISO/IEC 27001:2022/Amd 1:2024 (February 2024 climate change amendment to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (February 2022, the 93 Annex A controls), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27701:2025 (October 2025 standalone privacy management system, three-year transition to October 2028 for 27701:2019 holders), NABCB Accreditation Symbol mandate from 1 July 2026, and BIS adoption as IS/ISO/IEC 27001:2022. Cross-check case material against public ISO 27001 certificates of Infosys, TCS, Wipro, HCLTech, Zoho, Freshworks, Razorpay and Sprinto. The course pairs naturally with SOC 2 Readiness Practitioner (US enterprise commercial gate), DPDP Act 2023 Compliance (Indian privacy overlay under Annex A.5.34 + ISO 27701:2025), CERT-In Directions Practitioner (Indian incident reporting under A.5.24-A.5.27), and RBI Cybersecurity Framework Practitioner (BFSI overlay).
What you will learn
- Read the ISO/IEC 27001:2022 standard end-to-end and identify each of the ten main clauses (0 through 10) plus the normative Annex A control set
- Apply Amendment 1:2024 climate action changes to Clauses 4.1 (climate as internal / external issue) and 4.2 (interested parties climate requirements)
- Write an ISMS Scope Statement that a NABCB-accredited certification body will accept at Stage 1
- Staff the four mandatory documented information items under Clause 7.5 (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability)
- Run a risk assessment methodology per ISO/IEC 27005:2022 that produces a defensible risk register and drives control selection
- Build a Statement of Applicability mapping all 93 Annex A controls (37 Organizational, 8 People, 14 Physical, 34 Technological) to Include or Exclude with clause-anchored justification
- Implement the 11 new controls added in ISO/IEC 27002:2022 (threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding)
- Design the Internal Audit Programme (Clause 9.2) and Management Review agenda (Clause 9.3) that produce operating-effectiveness evidence for Stage 2
- Select a NABCB-accredited certification body through a formal RFP process scoring Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek and IRQS
- Prepare for and pass Stage 1 (documentation review) and Stage 2 (operating effectiveness) audits including sample sizes and common nonconformities
- Handle major and minor nonconformities through the CAPA process and obtain certificate issuance
- Run the three-year certification cycle (surveillance Year 1 + Year 2, recertification Year 3) with bridging statements between audits
- Plan the ISO 27701:2025 privacy add-on (standalone since October 2025) with a DPDP Act 2023 crosswalk
- Anticipate the ISO/IEC 42001 AI Management System as the next layer
Prerequisites
- Working exposure to an enterprise IT or SaaS environment (identity provider, MFA, cloud infrastructure, ticketing system, change management workflow) — typical for an ISMS Manager, DevOps Lead or CISO
- Comfort reading a formal management-system standard with clauses and sub-clauses (ISO 9001 or ISO 20000 background is helpful but not required)
- Familiarity with the concept of a risk register (likelihood x impact scoring, treatment options)
- Access to your own organisation's information asset inventory, cloud services list, and current security policies is helpful for the practical exercises but not required
Who this is for
- Indian CISOs and Heads of Security at enterprises, SaaS, BPO/KPO, Global Capability Centres and IT services organisations preparing first-time ISO 27001 certification or maintaining an existing certificate
- ISMS Managers, ISMS Coordinators and Information Security Officers running the ISMS end to end
- DevOps, Platform Engineering and Infrastructure Leads who own the technical controls (IAM, MFA, encryption, backup, change management, logging, monitoring) the auditor tests
- Internal Auditors preparing evidence packs and running the ISMS Internal Audit Programme
- Consultants at cyber advisory boutiques (KPMG, EY, Deloitte, PwC, mid-tier firms, boutique ISMS specialists) building or expanding an ISO 27001 practice
- Quality Managers at IT services and BPO organisations who inherit the ISMS from a broader ISO 9001 or ISO 20000 heritage
- Compliance and Risk Managers at BFSI, healthcare, telecom, retail and manufacturing organisations layering ISO 27001 onto RBI, IRDAI, SEBI, NABH or sector regulatory obligations
- Sales and Customer Success teams at Indian SaaS responding to European, UK, APAC and Middle East vendor security questionnaires with the ISO 27001 certificate
- Solutions Architects and Bid Managers responding to government tenders and enterprise RFPs that mandate ISO 27001 certification
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 40 lessons. Click any module to expand.
ISO/IEC 27001 is the international standard for an information security management system. It is the default enterprise procurement gate in Europe, UK, APAC and the Middle East, and a growing requirement for Indian enterprise, BFSI, healthcare and government tenders. This free-preview module walks what ISO 27001 actually is, where the standard comes from, how it compares to SOC 2 and NIST CSF, the substantive changes in the 2022 revision plus the February 2024 climate change amendment, the certification lifecycle (Stage 1, Stage 2, surveillance, recertification), and the operating timeline for a first-time Indian filer.
Free preview.
- 1. What ISO/IEC 27001 is and why enterprises demand it 10 min
- 2. ISO 27001 vs SOC 2 vs NIST CSF vs ISO 27701 10 min
- 3. The 2022 revision plus Amendment 1:2024 10 min
- 4. The certification lifecycle 10 min
- 5. The operating timeline for a first-time Indian filer 12 min
Clauses 4 through 6 of ISO/IEC 27001:2022 set the strategic layer of the ISMS. Clause 4 defines the scope and organisational context (with Amendment 1:2024 adding climate change consideration). Clause 5 defines top management commitment, ISMS policy and roles.
Clause 6 defines the risk assessment methodology, risk treatment approach and ISMS objectives. This is where certifications are won or lost at Stage 1 documentation review. Weak scope statements, generic ISMS policies and unclear risk methodologies produce the majority of Stage 1 nonconformities.
This module walks each clause with the artefacts that satisfy them.
- 1. Clause 4 Context of the organisation (including Amendment 1:2024 climate change) 9 min
- 2. Clause 5 Leadership and the ISMS Policy 8 min
- 3. Clause 6.1 Actions to address risks and opportunities 7 min
- 4. Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology 10 min
- 5. Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes 6 min
Clauses 7 through 10 of ISO/IEC 27001:2022 set the operating layer. Clause 7 covers resources, competence, awareness, communication and the four mandatory documented information items. Clause 8 executes the risk assessment methodology and produces the Risk Treatment Plan.
Clause 9 monitors, measures, runs internal audits and management reviews. Clause 10 handles nonconformity, corrective action and continual improvement. Stage 2 audit tests operating effectiveness of these clauses; internal audit programme quality and management review discipline are the two most common Stage 2 findings.
This module walks each clause with the operating cadences and artefacts that satisfy Stage 2.
- 1. Clause 7 Support — Resources, competence, awareness, communication 7 min
- 2. Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC 8 min
- 3. Clause 8 Operation — Executing the plan 7 min
- 4. Clause 9 — Monitoring, Internal Audit, Management Review 9 min
- 5. Clause 10 Improvement — Nonconformity and CAPA 7 min
ISO/IEC 27002:2022 organises the 93 controls of Annex A across four themes. This module walks the first two: A.5 Organizational (37 controls including policies, roles, threat intelligence, segregation of duties, supplier and cloud services, incident management, business continuity and legal/regulatory compliance) and A.6 People (8 controls including screening, terms of employment, awareness, disciplinary process, remote work and confidentiality agreements). Five of the 11 new controls added in the 2022 revision sit in these themes: A.5.7 Threat intelligence, A.5.23 Cloud services, A.5.30 ICT readiness for business continuity, A.7.4 Physical security monitoring (formally under Physical but grouped here for continuity), and A.5 Supplier updates.
Closes with the Statement of Applicability template covering all 93 controls with include / exclude / justification columns.
- 1. A.5 Organizational controls Part 1 (A.5.1 through A.5.20) 9 min
- 2. A.5 Organizational controls Part 2 (A.5.21 through A.5.37) 9 min
- 3. A.6 People controls (8 controls, A.6.1 through A.6.8) 7 min
- 4. The 11 new controls in ISO/IEC 27002:2022 walkthrough 9 min
- 5. Building the Statement of Applicability (all 93 controls) 8 min
Themes A.7 Physical (14 controls) and A.8 Technological (34 controls) contain the operational security controls most engineers recognise: perimeter, access, equipment, clear desk, storage disposal, and the full technical stack from IAM through cryptography, logging, backup, change management, secure development and network security. Six of the 11 new controls in the 2022 revision sit here: A.8.9 Configuration management, A.8.10 Information deletion, A.8.11 Data masking, A.8.12 Data leakage prevention, A.8.16 Monitoring activities, A.8.23 Web filtering, A.8.28 Secure coding. Closes with the Control Ownership Matrix (control to owner to evidence source) and cloud-specific alignment to ISO/IEC 27017 (cloud services code of practice) and ISO/IEC 27018 (cloud PII).
- 1. A.7 Physical controls (14 controls, A.7.1 through A.7.14) 8 min
- 2. A.8 Technological controls Part 1 (A.8.1 through A.8.17) 10 min
- 3. A.8 Technological controls Part 2 (A.8.18 through A.8.34) 10 min
- 4. Cloud-specific controls and ISO 27017 / 27018 alignment 8 min
- 5. Control Ownership Matrix and evidence sources 7 min
Risk assessment is the beating heart of the ISMS. Clause 6.1.2 requires a documented methodology; Clause 8.2 requires periodic execution. This module walks the working methodology per ISO/IEC 27005:2022: asset inventory and classification, threat identification, vulnerability identification, likelihood and impact scoring, inherent risk calculation, control application, residual risk calculation, and risk treatment options (Modify, Retain, Avoid, Share).
Closes with the Buy versus Build decision on GRC tooling covering Vanta, Drata, Sprinto (India-headquartered, popular with Indian SaaS), Secureframe, AuditBoard, Archer, ServiceNow GRC and MetricStream, scored on ISO 27001 module maturity, India presence, DPDP workflow support and cost band.
- 1. Choosing a risk methodology (asset-based, scenario-based, hybrid) 8 min
- 2. Asset inventory and information classification 7 min
- 3. Threat identification, vulnerability identification, likelihood + impact scoring 8 min
- 4. Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan 8 min
- 5. GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer) 8 min
You cannot self-certify. ISO/IEC 27001 certification requires a certification body accredited by an IAF MLA signatory (NABCB in India). This module walks what NABCB accreditation means, why the IAF MLA matters for international recognition of your certificate, the CB RFP process across Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek and IRQS, the Stage 1 audit (documentation review) with the artefacts the auditor tests and the common findings, the Stage 2 audit (operating effectiveness) with sample sizes and interview walkthroughs, handling major and minor nonconformities through the CAPA process, and certificate issuance.
Includes the CB RFP + Selection Matrix template.
- 1. What NABCB accreditation means (and why IAF MLA matters) 7 min
- 2. CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS) 8 min
- 3. Stage 1 audit — documentation review 8 min
- 4. Stage 2 audit — operating effectiveness testing 9 min
- 5. Handling nonconformities, CAPA closure, certificate issuance 7 min
Certification is the start, not the end. ISO 27001 runs on a three-year cycle: annual surveillance audits in Years 1 and 2 (typically 30 to 60 percent of the initial audit scope) and full recertification in Year 3. This module walks surveillance and recertification, publishing certification status on your customer trust portal and answering vendor security questionnaires (VSAQ, CAIQ, SIG), the bridging statement between annual audits, the ISO 27701:2025 privacy add-on (standalone since October 2025) with a full DPDP Act 2023 crosswalk, the ISO 27017 (cloud services code of practice) and ISO 27018 (cloud PII) extensions, and the emerging ISO/IEC 42001 AI Management System as the next layer for organisations deploying AI in production.
- 1. Surveillance Years 1 + 2, and recertification Year 3 7 min
- 2. Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires 7 min
- 3. ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk 8 min
- 4. ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions 6 min
- 5. ISO/IEC 42001 AI Management System as the next horizon 7 min
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme aimed at working Indian CISOs, ISMS Managers, Heads of Security, DevOps and Infrastructure Leads, Internal Auditors, and consultants at cyber advisory boutiques. Every substantive claim is anchored to a primary source: ISO clause number (e.g. Clause 6.1.2 Risk assessment, Clause 7.5 Documented information, Annex A.8.28 Secure coding), ISO/IEC 27001:2022/Amd 1:2024 climate action changes, NABCB policy PDF, IAF Mandatory Document reference, or specific public ISO 27001 certification posture (Infosys, TCS, Wipro, HCLTech, Zoho, Freshworks, Razorpay, Sprinto). Items flagged as UNVERIFIED in the lesson prose are pending re-verification against the current primary source and must be checked before the student acts on them in a live certification engagement.
The course maintains a 15-item verification checklist covering ISO revision timeline, Amendment 1:2024 currency, ISO 27002:2022 control set stability, ISO 27701:2025 transition rules, NABCB Accreditation Symbol mandate, BIS adoption identity to ISO text, PECB scheme parameters, GRC vendor pricing, and IAF MD applicability. This is not legal, tax, audit, or accounting advice and does not create a professional-client relationship. This course does not confer PECB, IRCA, BSI, TÜV or any other body's personal Lead Implementer or Lead Auditor certification. Those are separate personal-certification schemes governed by ISO/IEC 17024 requiring examination and CPD maintenance directly with the issuing body.
For certification of an organisation to ISO/IEC 27001:2022, engage a NABCB-accredited certification body (or an IAF MLA equivalent) directly.
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS.
Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.