Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

How this ISO/IEC 27001 Lead Implementer Practitioner Certification register is built

This trust page is the citation register for the ISO/IEC 27001 Lead Implementer Practitioner Certification course. It cites 43 authorities across 16 statutory instruments, drawn from the legal basis snapshot above (ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.).

Primary sources: ISO/IEC 27001:2022 (13 entries), ISO/IEC 27002:2022 (9 entries), IAF Mandatory Document (3 entries).

Every claim in every ISO/IEC 27001 Lead Implementer Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
8
modules
40
lessons
43
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

DPDP Act 2023 (Sections 8-9 obligations) , DPDP Act 2023 data fiduciary duties 11 Aug 2023
Plain summary: DPDP Act 2023 sets obligations on data fiduciaries including reasonable security safeguards (Section 8(5)) and personal data breach notification (Section 8(6) + DPDP Rules 2025 Rule 7). Course maps these to A.5.34 (Privacy and protection of PII), A.5.24 through A.5.27 (incident management), A.8.11 (data masking), A.8.12 (DLP) and ISO 27701:2025 for a full PIMS overlay.
Section 8(5) of the DPDP Act 2023 requires a data fiduciary to implement appropriate technical and organisational measures to ensure effective observance of the provisions of the Act and the rules made thereunder. Section 8(6) requires notification of personal data breach to the Data Protection Board and to each affected data principal. DPDP Rules 2025 Rule 7 sets the operational parameters of the notification.

Sprinto ISO 27001 module (India) , Sprinto GRC platform ISO 27001 01 Jan 2026
Plain summary: Sprinto ISO 27001 module. India-headquartered (Bengaluru). Preferred by Indian SaaS for the DPDP Act 2023 workflow support alongside ISO 27001 and SOC 2. Pricing tends 30 to 50 percent below Vanta/Drata for Indian entities.
Sprinto offers ISO 27001 alongside SOC 2, GDPR, HIPAA, PCI DSS and DPDP Act 2023 modules. India-headquartered means native DPDP workflow (breach notification, consent tracking, DPO record-keeping) and INR-native pricing. Common choice for Indian SaaS at Series A and Series B.
Vanta ISO 27001 module , Vanta GRC platform ISO 27001 01 Jan 2026
Plain summary: Vanta ISO 27001 module. US-headquartered. Combined SOC 2 + ISO 27001 workflow. Automated evidence collection via integrations with AWS, GCP, Azure, GitHub, Okta, Jira and 100+ others. Course references Vanta as one of five GRC options in Module 6 Buy vs Build decision.
Vanta offers an ISO 27001 module in addition to its SOC 2 core. Automated evidence collection via 100+ integrations. Pricing not publicly listed; requires sales-led quote. Typical range for Indian SaaS Series A: USD 15,000 to USD 40,000 per year depending on employee count and modules.

IAF MD 5 (audit duration) , Duration of ISMS audits 01 Jan 2019
Plain summary: IAF MD 5 governs the calculation of audit duration for QMS and EMS. ISMS audit duration is governed by ISO/IEC 27006 tables based on effective number of personnel adjusted for complexity and risk. Together these ensure CBs cannot underbid audit day counts.
IAF MD 5 provides mandatory minimum audit duration tables that CBs must apply. For ISO/IEC 27001 certification, ISO/IEC 27006 Annex B provides the ISMS-specific tables: audit days scale with effective number of personnel in scope, adjusted upward for complexity factors (multi-site, high-risk sector, custom development environment) and downward for simplifying factors (single-site, low-risk sector, off-the-shelf tooling).
IAF MD 4 (use of ICT for auditing) , Remote and hybrid audit rules 01 Jan 2022
Plain summary: IAF MD 4 governs the use of information and communication technology (remote audits, video conferencing, screen sharing, document sharing platforms) in management system certification audits. Formalised post-pandemic. Applies to ISO 27001 Stage 1 and surveillance audits routinely; Stage 2 typically requires on-site component.
IAF MD 4 sets requirements for the use of ICT to support remote or hybrid audit activities. CBs must ensure the technology used protects audit information, allows effective interviewing and evidence review, and the audit outcome quality is not diminished. For ISO/IEC 27001, Stage 1 documentation review is commonly performed remotely; Stage 2 operating effectiveness typically has an on-site component.
IAF MD 22 (management system transitions) , Transition to new standard editions 01 Jan 2023
Plain summary: IAF MD 22 governs how CBs handle transitions between editions of management system standards. Applied to the ISO/IEC 27001:2013 to 2022 transition that closed 31 October 2025 and (in future) to any next-edition transition.
IAF MD 22 sets requirements for CBs during transition periods: how existing certificates are handled, the audit approach for transition audits, the deadline enforcement, and communication to certified organisations. The 27001:2013 to 27001:2022 transition ran from October 2022 (revision publication) to October 2025 (transition deadline).

ISO 19011:2018 (auditing guidelines) , Auditing management systems 15 Jul 2018
Plain summary: ISO 19011:2018 provides guidelines for auditing management systems. Governs first-party (internal) and second-party (customer) audits. Certification (third-party) audits are governed by ISO/IEC 17021-1 read with ISO/IEC 27006. ISMS internal audit programme (Clause 9.2) is designed per ISO 19011.
ISO 19011:2018 provides guidance on: principles of auditing (integrity, fair presentation, due professional care, confidentiality, independence, evidence-based, risk-based approach); managing an audit programme; conducting audits; competence and evaluation of auditors. Referenced by ISO/IEC 27001 Clause 9.2 for the internal audit programme design.

Clause 10 Improvement , Nonconformity and corrective action 25 Oct 2022
Plain summary: Clause 10 covers continual improvement (10.1) and nonconformity and corrective action (10.2). The CAPA process handles nonconformities from internal audits, management reviews, incidents and certification-body findings.
10.1 The organization shall continually improve the suitability, adequacy and effectiveness of the ISMS. 10.2 When a nonconformity occurs the organization shall: a) react to the nonconformity, take action to control and correct it, and deal with the consequences; b) evaluate the need for action to eliminate the causes of the nonconformity; c) implement any action needed; d) review the effectiveness of any corrective action taken; e) make changes to the ISMS if necessary. The organization shall retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and the results of any corrective action.
Clause 4.1 Understanding the organisation , Internal and external issues 25 Oct 2022
Plain summary: Clause 4.1 requires the organisation to determine internal and external issues that are relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS. Amendment 1:2024 adds the requirement to formally determine whether climate change is a relevant issue.
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system. NOTE (Amd 1:2024): The organization shall determine whether climate change is a relevant issue.
Clause 4.2 Interested parties , Needs and expectations of interested parties 25 Oct 2022
Plain summary: Clause 4.2 requires the organisation to determine interested parties relevant to the ISMS, their requirements, and which of those requirements will be addressed through the ISMS. Amendment 1:2024 adds a note that relevant interested parties may have specific climate-related requirements.
The organization shall determine: a) interested parties that are relevant to the information security management system; b) the relevant requirements of these interested parties; c) which of these requirements will be addressed through the ISMS. NOTE (Amd 1:2024): Relevant interested parties can have requirements related to climate change.
Clause 4.3 Scope of the ISMS , Determining scope 25 Oct 2022
Plain summary: Clause 4.3 requires the organisation to determine the boundaries and applicability of the ISMS to establish its scope. Scope shall be available as documented information. The scope statement is one of the four mandatory documented information items and is what the certification body reviews first at Stage 1.
The organization shall determine the boundaries and applicability of the information security management system to establish its scope. When determining this scope the organization shall consider: a) the external and internal issues referred to in 4.1; b) the requirements referred to in 4.2; c) interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations. The scope shall be available as documented information.
Clause 5 Leadership , Leadership and commitment 25 Oct 2022
Plain summary: Clause 5 covers leadership and commitment (5.1), ISMS policy (5.2) and organisational roles, responsibilities and authorities (5.3). Top management must demonstrate commitment; the ISMS policy is a mandatory documented information item.
5.1 Top management shall demonstrate leadership and commitment with respect to the information security management system. 5.2 Top management shall establish an information security policy that (a) is appropriate to the purpose of the organization, (b) includes information security objectives or provides the framework for setting them, (c) includes a commitment to satisfy applicable requirements, (d) includes a commitment to continual improvement. 5.3 Top management shall ensure that responsibilities and authorities for roles relevant to information security are assigned and communicated.
Clause 6.1.2 Risk assessment , Information security risk assessment 25 Oct 2022
Plain summary: Clause 6.1.2 requires the organisation to define and apply an information security risk assessment process. The methodology must produce consistent, valid and comparable results. Methodology is a mandatory documented information item.
The organization shall define and apply an information security risk assessment process that: a) establishes and maintains information security risk criteria that include risk acceptance criteria and criteria for performing information security risk assessments; b) ensures that repeated information security risk assessments produce consistent, valid and comparable results; c) identifies the information security risks; d) analyses the information security risks; e) evaluates the information security risks. The organization shall retain documented information about the information security risk assessment process.
Clause 6.1.3 Risk treatment , Information security risk treatment 25 Oct 2022
Plain summary: Clause 6.1.3 requires selection of risk treatment options and determination of controls. Requires production of the Statement of Applicability (SoA) containing the necessary controls and justification for inclusion and exclusion referencing Annex A. SoA is a mandatory documented information item.
The organization shall define and apply an information security risk treatment process to: a) select appropriate information security risk treatment options; b) determine all controls that are necessary; c) compare the controls determined in b) with those in Annex A and verify that no necessary controls have been omitted; d) produce a Statement of Applicability that contains: the necessary controls, justification for their inclusion, whether they are implemented or not, and the justification for excluding any Annex A controls; e) formulate an information security risk treatment plan; f) obtain risk owners' approval of the plan and acceptance of the residual risks.
Clause 6.2 ISMS objectives , Information security objectives and planning 25 Oct 2022
Plain summary: Clause 6.2 requires the organisation to establish information security objectives at relevant functions and levels. Objectives must be measurable where practicable, monitored, communicated and updated. Retain as documented information.
The organization shall establish information security objectives at relevant functions and levels. The objectives shall: a) be consistent with the information security policy; b) be measurable (if practicable); c) take into account applicable information security requirements, and results from risk assessment and risk treatment; d) be monitored; e) be communicated; f) be updated as appropriate; g) be available as documented information.
Clause 6.3 Planning of changes , Change planning (new in 2022) 25 Oct 2022
Plain summary: Clause 6.3 Planning of changes is new in the 2022 revision. Requires that when the organisation determines a need for changes to the ISMS, the changes are carried out in a planned manner.
When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.
Clause 7.5 Documented information , Documented information requirements 25 Oct 2022
Plain summary: Clause 7.5 sets requirements for creating, updating and controlling documented information. The four items required to be documented information are: ISMS scope (4.3), ISMS policy (5.2), risk assessment and treatment process (6.1.2 + 6.1.3), Statement of Applicability (6.1.3). Additional documented information items are required by other clauses (competence records, monitoring results, internal audit programme and results, management review results, nonconformity and corrective action records).
The organization's information security management system shall include: a) documented information required by this document; b) documented information determined by the organization as being necessary for the effectiveness of the ISMS. When creating and updating documented information the organization shall ensure appropriate identification and description, format, review and approval for suitability and adequacy. Documented information required by the ISMS and by this document shall be controlled to ensure it is available and suitable for use where needed and adequately protected.
Clause 8 Operation , Operational planning, risk assessment, treatment 25 Oct 2022
Plain summary: Clause 8 covers operational planning and control (8.1), operational execution of the risk assessment (8.2) and operational execution of the risk treatment plan (8.3). This is where the design of Clause 6 becomes operating reality. Stage 2 audit tests operating effectiveness of Clause 8.
8.1 The organization shall plan, implement and control the processes needed to meet requirements and to implement the actions determined in Clause 6, by establishing criteria for the processes and implementing control of the processes in accordance with the criteria. 8.2 The organization shall perform information security risk assessments at planned intervals or when significant changes are proposed or occur. 8.3 The organization shall implement the information security risk treatment plan.
Clause 9 Performance evaluation , Monitoring, internal audit, management review 25 Oct 2022
Plain summary: Clause 9 covers monitoring, measurement, analysis and evaluation (9.1), internal audit (9.2) and management review (9.3). Internal audit programme quality and management review discipline are the two most common Stage 2 findings.
9.1 The organization shall determine what needs to be monitored and measured, methods, when, by whom, when results shall be analysed and evaluated. 9.2 The organization shall conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the organization's own requirements and the requirements of this document, and is effectively implemented and maintained. 9.3 Top management shall review the organization's ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Documented information shall be retained as evidence of the results of management reviews.
ISO/IEC 27001:2022 (Oct 2022 base standard) , Information security management systems Requirements 25 Oct 2022
Plain summary: ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements. Published 25 October 2022 by ISO/IEC JTC 1/SC 27. Currently effective base standard for ISMS certification. Structure: ten main clauses (0 Introduction through 10 Improvement) plus Annex A referencing the 93 controls of ISO/IEC 27002:2022. Transition from ISO/IEC 27001:2013 closed 31 October 2025 per IAF Mandatory Document.
The 2022 revision aligns Clauses 4 through 10 with Annex SL harmonised management-system-standard structure shared with ISO 9001, 14001, 22301 and 42001. Substantive changes from 2013: Annex A restructured from 14 clauses (114 controls) into 4 themes (93 controls) mirroring ISO/IEC 27002:2022; 11 new controls introduced (threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding); Clause 6.3 Planning of changes added; Clause 8.1 wording tightened on planning and control of operational processes.

Amendment 1:2024 (climate action changes) , February 2024 climate change amendment 01 Feb 2024
Plain summary: ISO/IEC 27001:2022/Amd 1:2024 published February 2024. Two textual changes to two clauses. Clause 4.1 gains a mandatory NOTE requiring the organisation to determine whether climate change is a relevant issue. Clause 4.2 gains a NOTE that relevant interested parties may have climate-related requirements. No recertification required; amendment is picked up at the next scheduled surveillance or recertification audit. Organisation is permitted to conclude climate change is not relevant provided the determination is documented.
This amendment addresses climate change considerations within the ISMS framework. Clause 4.1 addition: the organization shall determine whether climate change is a relevant issue. Clause 4.2 addition: NOTE Relevant interested parties can have requirements related to climate change. The amendment is issued alongside identical amendments to more than thirty other ISO management-system standards including ISO 9001, 14001, 22301, 45001 and 42001. Organisations do not need to recertify to pick up the amendment; it is folded into the next scheduled surveillance or recertification audit.

A.5 Organizational controls (37 controls) , A.5.1 through A.5.37 15 Feb 2022
Plain summary: A.5 Organizational theme contains 37 controls covering policies for information security, roles and responsibilities, segregation of duties, contact with authorities and special interest groups, threat intelligence, information security in project management, inventory and classification of information, acceptable use, return of assets, information transfer, cloud services, supplier relationships, ICT supply chain, incident management, business continuity, PII protection, and legal / regulatory compliance.
A.5.1 Policies for information security; A.5.2 Information security roles and responsibilities; A.5.3 Segregation of duties; A.5.4 Management responsibilities; A.5.5 Contact with authorities; A.5.6 Contact with special interest groups; A.5.7 Threat intelligence (NEW); A.5.8 Information security in project management; A.5.9 Inventory of information and other associated assets; A.5.10 Acceptable use; A.5.11 Return of assets; A.5.12 Classification of information; A.5.13 Labelling of information; A.5.14 Information transfer; A.5.15 Access control; A.5.16 Identity management; A.5.17 Authentication information; A.5.18 Access rights; A.5.19 Information security in supplier relationships; A.5.20 Addressing information security within supplier agreements; A.5.21 Managing information security in ICT supply chain; A.5.22 Monitoring, review and change management of supplier services; A.5.23 Information security for use of cloud services (NEW); A.5.24 Information security incident management planning and preparation; A.5.25 Assessment and decision on information security events; A.5.26 Response to information security incidents; A.5.27 Learning from information security incidents; A.5.28 Collection of evidence; A.5.29 Information security during disruption; A.5.30 ICT readiness for business continuity (NEW); A.5.31 Legal, statutory, regulatory and contractual requirements; A.5.32 Intellectual property rights; A.5.33 Protection of records; A.5.34 Privacy and protection of PII; A.5.35 Independent review of information security; A.5.36 Compliance with policies, rules and standards; A.5.37 Documented operating procedures.
A.5.23 Cloud services (new) , Information security for use of cloud services 15 Feb 2022
Plain summary: A.5.23 Cloud services is a new control in the 2022 revision. Requires the organisation to establish processes for the acquisition, use, management and exit of cloud services. Pairs with ISO/IEC 27017 (cloud code of practice) for detailed guidance.
Processes for acquisition, use, management and exit from cloud services should be established in accordance with the organization's information security requirements. Includes: due diligence on cloud service providers; contractual clauses covering shared responsibility, data location, breach notification, right to audit, exit and portability; ongoing monitoring of the CSP's security posture.
A.5.34 Privacy and protection of PII , Privacy and PII protection 15 Feb 2022
Plain summary: A.5.34 requires the organisation to identify and meet requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements. This is the anchor point for DPDP Act 2023 compliance overlay onto the ISMS.
The organization should identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements. Guidance references ISO/IEC 29100 privacy framework and ISO/IEC 27701 for a PIMS extension of the ISMS.
A.5.7 Threat intelligence (new) , Threat intelligence programme requirement 15 Feb 2022
Plain summary: A.5.7 Threat intelligence is a new control in the 2022 revision. Requires the organisation to collect and analyse information relating to information security threats to produce threat intelligence. Sources include commercial threat intel feeds, sector ISACs (in India: CERT-In sectoral CERTs, RBI IB-CART for banks), open-source intel and internal telemetry.
Information relating to information security threats should be collected and analysed to produce threat intelligence. The purpose is to provide awareness of the organization's threat environment so that appropriate mitigation actions can be taken. Threat intelligence should be relevant, insightful, contextual and actionable.
A.6 People controls (8 controls) , A.6.1 through A.6.8 15 Feb 2022
Plain summary: A.6 People theme contains 8 controls covering pre-employment screening, terms and conditions of employment, information security awareness education and training, disciplinary process, responsibilities on termination or change of employment, confidentiality or non-disclosure agreements, remote working, and information security event reporting.
A.6.1 Screening; A.6.2 Terms and conditions of employment; A.6.3 Information security awareness, education and training; A.6.4 Disciplinary process; A.6.5 Responsibilities after termination or change of employment; A.6.6 Confidentiality or non-disclosure agreements; A.6.7 Remote working; A.6.8 Information security event reporting.
A.7 Physical controls (14 controls) , A.7.1 through A.7.14 15 Feb 2022
Plain summary: A.7 Physical theme contains 14 controls covering physical security perimeter, physical entry, securing offices rooms and facilities, physical security monitoring (new in 2022), protection against physical and environmental threats, working in secure areas, clear desk and clear screen, equipment siting and protection, security of assets off-premises, storage media, supporting utilities, cabling security, equipment maintenance and secure disposal or re-use of equipment.
A.7.1 Physical security perimeters; A.7.2 Physical entry; A.7.3 Securing offices, rooms and facilities; A.7.4 Physical security monitoring (NEW); A.7.5 Protecting against physical and environmental threats; A.7.6 Working in secure areas; A.7.7 Clear desk and clear screen; A.7.8 Equipment siting and protection; A.7.9 Security of assets off-premises; A.7.10 Storage media; A.7.11 Supporting utilities; A.7.12 Cabling security; A.7.13 Equipment maintenance; A.7.14 Secure disposal or re-use of equipment.
A.8 Technological controls (34 controls) , A.8.1 through A.8.34 15 Feb 2022
Plain summary: A.8 Technological theme contains 34 controls covering user endpoint devices, privileged access, information access restriction, source code access, secure authentication, capacity management, protection against malware, technical vulnerability management, configuration management (new), information deletion (new), data masking (new), data leakage prevention (new), backup, redundancy, logging, monitoring activities (new), clock synchronisation, use of privileged utility programs, installation of software, network security, security of network services, segregation of networks, web filtering (new), use of cryptography, secure system architecture and engineering principles, secure development lifecycle, application security requirements, secure coding (new), security testing in development and acceptance, outsourced development, separation of development test and production environments, change management, test information protection and information systems audit protection.
A.8.1 User endpoint devices; A.8.2 Privileged access rights; A.8.3 Information access restriction; A.8.4 Access to source code; A.8.5 Secure authentication; A.8.6 Capacity management; A.8.7 Protection against malware; A.8.8 Management of technical vulnerabilities; A.8.9 Configuration management (NEW); A.8.10 Information deletion (NEW); A.8.11 Data masking (NEW); A.8.12 Data leakage prevention (NEW); A.8.13 Information backup; A.8.14 Redundancy of information processing facilities; A.8.15 Logging; A.8.16 Monitoring activities (NEW); A.8.17 Clock synchronization; A.8.18 Use of privileged utility programs; A.8.19 Installation of software on operational systems; A.8.20 Networks security; A.8.21 Security of network services; A.8.22 Segregation of networks; A.8.23 Web filtering (NEW); A.8.24 Use of cryptography; A.8.25 Secure development lifecycle; A.8.26 Application security requirements; A.8.27 Secure system architecture and engineering principles; A.8.28 Secure coding (NEW); A.8.29 Security testing in development and acceptance; A.8.30 Outsourced development; A.8.31 Separation of development, test and production environments; A.8.32 Change management; A.8.33 Test information; A.8.34 Protection of information systems during audit testing.
A.8.28 Secure coding (new) , Secure coding principles and standards 15 Feb 2022
Plain summary: A.8.28 Secure coding is a new control in the 2022 revision. Requires secure coding principles to be applied to software development. Aligns with OWASP Top 10, CWE Top 25 and language-specific secure coding guides.
Secure coding principles should be applied to software development. Includes: use of secure coding standards; code review; security testing; management of external components and libraries (SBOM); protection against common vulnerabilities (injection, broken authentication, XSS, insecure deserialisation, misconfiguration, sensitive data exposure).
ISO/IEC 27002:2022 (Feb 2022, 93 controls) , The 93 Annex A controls across 4 themes 15 Feb 2022
Plain summary: ISO/IEC 27002:2022 published February 2022 as the companion controls standard to ISO/IEC 27001:2022. Contains 93 controls (down from 114 in 2013 edition) organised across four themes: A.5 Organizational (37 controls), A.6 People (8 controls), A.7 Physical (14 controls), A.8 Technological (34 controls). Introduces 11 new controls. Each control is now tagged with attributes (control type, information security properties, cybersecurity concepts, operational capability, security domain) to aid mapping to other frameworks.
The 2022 revision consolidated the 114 controls of ISO/IEC 27002:2013 into 93 controls by merging overlapping controls and introduced 11 new controls to address contemporary needs: A.5.7 Threat intelligence; A.5.23 Information security for use of cloud services; A.5.30 ICT readiness for business continuity; A.7.4 Physical security monitoring; A.8.9 Configuration management; A.8.10 Information deletion; A.8.11 Data masking; A.8.12 Data leakage prevention; A.8.16 Monitoring activities; A.8.23 Web filtering; A.8.28 Secure coding.

ISO/IEC 27005:2022 (risk management) , Information security risk management guidance 25 Oct 2022
Plain summary: ISO/IEC 27005:2022 provides guidance on managing information security risks. Companion to ISO/IEC 27001 Clauses 6.1.2 and 6.1.3. Supports both asset-based and event-based (scenario) risk approaches. Aligned with ISO 31000:2018 general risk management.
ISO/IEC 27005:2022 provides guidance to organizations on managing information security risks. It supports the requirements of ISO/IEC 27001 concerning actions to address information security risks and applies to all types of organizations. The document is aligned with ISO 31000:2018. It supports both an asset-based approach (identify assets, then threats and vulnerabilities to those assets) and an event-based (scenario) approach (identify risk scenarios and their consequences).

ISO/IEC 27006:2015 + A1:2020 , Requirements for ISMS certification bodies 01 Jan 2020
Plain summary: ISO/IEC 27006 sets requirements for bodies providing audit and certification of ISMS. Governs CB competence, audit day calculations, impartiality and independence rules. NABCB accredits Indian CBs against ISO/IEC 27006 read with IAF Mandatory Documents.
ISO/IEC 27006 supplements ISO/IEC 17021-1 (general requirements for CBs) with ISMS-specific requirements including: competence requirements for auditors (technical knowledge of information security, understanding of ISO/IEC 27001, audit skills); minimum audit-day calculations based on effective personnel numbers, scope complexity and risk; impartiality and independence rules; requirements for the initial certification (Stage 1 + Stage 2), surveillance and recertification audits.

ISO/IEC 27017:2015 (cloud code) , Code of practice for cloud services security 15 Dec 2015
Plain summary: ISO/IEC 27017:2015 provides a cloud-services-specific code of practice extending ISO/IEC 27002. Adds cloud-specific implementation guidance to selected 27002 controls and 7 additional cloud-only controls (CLD.6.3.1, CLD.8.1.5, CLD.9.5.1, CLD.9.5.2, CLD.12.1.5, CLD.12.4.5, CLD.13.1.4). Certifiable via a joint 27001 + 27017 certificate.
ISO/IEC 27017 provides additional implementation guidance for cloud service customers and cloud service providers for the information security controls in ISO/IEC 27002. Introduces 7 additional cloud-specific controls covering: shared roles and responsibilities within a cloud computing environment; removal of cloud service customer assets; segregation in virtual computing environments; virtual machine hardening; administrator's operational security; monitoring of cloud services; alignment of security management for virtual and physical networks.

ISO/IEC 27018:2019 (cloud PII) , Protection of PII in public clouds 01 Jan 2019
Plain summary: ISO/IEC 27018:2019 establishes commonly accepted control objectives and controls for the protection of PII in public clouds acting as PII processors. Cloud PII processor equivalent. Certifiable via a joint 27001 + 27018 certificate.
ISO/IEC 27018 addresses the protection of Personally Identifiable Information (PII) in public clouds acting as PII processors. Sets guidelines and controls in addition to ISO/IEC 27002 covering: consent and choice; purpose legitimacy and specification; collection limitation; use, retention and disclosure limitation; accuracy and quality; openness, transparency and notice; individual participation and access; accountability; information security; and privacy compliance.

ISO/IEC 27701:2025 (standalone PIMS) , Privacy information management system standalone 14 Oct 2025
Plain summary: ISO/IEC 27701:2025 published 14 October 2025 as the second edition. Transforms from a 27001 extension into a stand-alone Privacy Information Management System standard. Certification no longer requires prior 27001 certification. Three-year transition to October 2028 for 27701:2019 certificate holders. IAF transition arrangements developing as of course pin date. NABCB published transition policy January 2026.
ISO/IEC 27701:2025 is now a stand-alone management system standard for privacy. Prior 27701:2019 was an extension of ISO/IEC 27001 (PIMS-specific requirements added to the ISMS). The 2025 second edition contains its own Clauses 4 through 10 (mirroring the harmonised Annex SL structure) plus PIMS-specific controls for PII controllers and PII processors. Integrates with ISO/IEC 27001, ISO 9001 and ISO/IEC 42001. Three-year transition to 14 October 2028 for organisations holding 27701:2019 certificates.

ISO/IEC 42001:2023 (AI Management System) , AI Management System standard 18 Dec 2023
Plain summary: ISO/IEC 42001:2023 published December 2023 as the first international AI Management System standard. Mirrors ISO/IEC 27001 harmonised structure. Referenced in this course as the emerging next-layer standard organisations deploying AI in production should anticipate.
ISO/IEC 42001:2023 provides requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system (AIMS). Applicable to any organisation that provides or uses AI systems. Structured to be integrable with ISO/IEC 27001 and ISO 9001 via shared Clauses 4 through 10.

NABCB Accreditation (QCI, IAF MLA) , NABCB accreditation regime for CBs in India 01 Jan 2023
Plain summary: NABCB (National Accreditation Board for Certification Bodies) is the accreditation body under the Quality Council of India (QCI). Full member of IAF, ILAC and APAC; signatory to IAF MLA. Accredits Indian CBs for ISO/IEC 27001 (and other management system standards) against ISO/IEC 17021-1 read with ISO/IEC 27006.
NABCB accredits certification bodies operating in India. NABCB-accredited CB certificates carry IAF MLA recognition, meaning the certificate is recognised by IAF MLA signatories worldwide (equivalent to certificates from UKAS UK, ANAB US, DAkkS Germany, JAB Japan, etc.). Well-known NABCB-accredited CBs offering ISO/IEC 27001 include Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek and IRQS.
NABCB 27701:2025 Transition Policy , Transition policy for ISO/IEC 27701:2025 01 Jan 2026
Plain summary: NABCB Policy on Transition to ISO/IEC 27701:2025 published January 2026. Sets out how Indian CBs and certificate holders should transition from ISO/IEC 27701:2019 (extension of 27001) to ISO/IEC 27701:2025 (standalone PIMS). Aligned with IAF transition arrangements.
NABCB has published its Transition Policy on ISO/IEC 27701:2025 in January 2026. The policy sets a transition period aligned with IAF arrangements for organisations certified to ISO/IEC 27701:2019 to migrate to ISO/IEC 27701:2025. CBs must obtain accreditation extension to 27701:2025 before issuing certificates to the new edition.
NABCB Symbol Mandate 1 July 2026 , Accreditation symbol mandate 01 Jul 2026
Plain summary: NABCB Accreditation Symbol became mandatory on all accredited certificates issued in India with effect from 1 July 2026. Certificates issued without the NABCB Symbol after this date are non-compliant with NABCB accreditation rules. Certified organisations should verify their current certificate displays the Symbol.
Use of NABCB Accreditation Symbol on Accredited Certificates is made mandatory with effect from 01 July 2026. All NABCB-accredited certification bodies issuing new or renewed certificates on or after this date must display the NABCB Symbol on the certificate.

NIST Cybersecurity Framework 2.0 , NIST CSF v2.0 (Feb 2024) 26 Feb 2024
Plain summary: NIST CSF 2.0 published February 2024. Six Functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. Referenced in this course for the NIST CSF to ISO 27001 crosswalk (Govern maps to ISO Clauses 4-5 + selected Annex A; Identify maps to Clause 6.1.2 + A.5 asset controls; Protect to A.5-A.8; Detect to A.8.15-A.8.16; Respond to A.5.24-A.5.27; Recover to A.5.29-A.5.30).
NIST Cybersecurity Framework 2.0 introduces a sixth Function (Govern) alongside the original five (Identify, Protect, Detect, Respond, Recover). US federal contractor and critical infrastructure orientation. Widely adopted globally as a common vocabulary. Crosswalks cleanly to ISO/IEC 27001:2022 clauses and Annex A controls.

Freshworks ISO 27001 posture , Freshworks trust portal 01 Jan 2024
Plain summary: Freshworks Trust Portal at freshworks.com/security publishes ISO/IEC 27001 certification alongside SOC 2 Type II, ISO 27017 / 27018, ISO 27701, GDPR, DPDP, HIPAA (for Freshdesk healthcare). Represents the SaaS unicorn baseline.
Freshworks Trust Portal freshworks.com/security publishes ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, SOC 2 Type II, GDPR, DPDP, HIPAA, and product-specific compliance attestations. Cited in this course as the operating benchmark for a mid-cap Indian SaaS trust portal.
Infosys ISO 27001 posture , Infosys ISMS certification 01 Jan 2024
Plain summary: Infosys maintains ISO/IEC 27001:2022 certification across its global delivery centres. Represents the mature Indian IT services baseline: multi-site scope, integrated with ISO 9001 and ISO 20000, extended with ISO 27017 / 27018 for cloud and ISO 27701 for privacy.
Infosys public data-privacy and security disclosure confirms ISO/IEC 27001 certification across multiple delivery centres. The company operates an integrated management system covering ISO 9001 (quality), ISO 20000 (service management), ISO 27001 (security), ISO 27017 / 27018 (cloud and cloud PII) and ISO 27701 (privacy).
Zoho ISO 27001 posture , Zoho ISMS + cloud extensions 01 Jan 2024
Plain summary: Zoho publishes its ISMS posture including ISO/IEC 27001, ISO/IEC 27017 (cloud), ISO/IEC 27018 (cloud PII) and ISO/IEC 27701 (privacy) alongside SOC 2, GDPR, DPDP, HIPAA and PCI DSS. Represents the mature Indian SaaS baseline.
Zoho zoho.com/security.html page publishes: ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, SOC 2 Type II, GDPR, DPDP Act 2023, HIPAA, PCI DSS certifications and attestations. Cited in this course as the current bar for a mature Indian SaaS company.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.