Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this ISO/IEC 27001 Lead Implementer Practitioner Certification register is built
This trust page is the citation register for the ISO/IEC 27001 Lead Implementer Practitioner Certification course. It cites 43 authorities across 16 statutory instruments, drawn from the legal basis snapshot above (ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.).
Primary sources: ISO/IEC 27001:2022 (13 entries), ISO/IEC 27002:2022 (9 entries), IAF Mandatory Document (3 entries).
Every claim in every ISO/IEC 27001 Lead Implementer Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
DPDP Act 2023 (Sections 8-9 obligations) , DPDP Act 2023 data fiduciary duties 11 Aug 2023
Sprinto ISO 27001 module (India) , Sprinto GRC platform ISO 27001 01 Jan 2026
Vanta ISO 27001 module , Vanta GRC platform ISO 27001 01 Jan 2026
IAF MD 5 (audit duration) , Duration of ISMS audits 01 Jan 2019
IAF MD 4 (use of ICT for auditing) , Remote and hybrid audit rules 01 Jan 2022
IAF MD 22 (management system transitions) , Transition to new standard editions 01 Jan 2023
ISO 19011:2018 (auditing guidelines) , Auditing management systems 15 Jul 2018
Clause 10 Improvement , Nonconformity and corrective action 25 Oct 2022
Clause 4.1 Understanding the organisation , Internal and external issues 25 Oct 2022
Clause 4.2 Interested parties , Needs and expectations of interested parties 25 Oct 2022
Clause 4.3 Scope of the ISMS , Determining scope 25 Oct 2022
Clause 5 Leadership , Leadership and commitment 25 Oct 2022
Clause 6.1.2 Risk assessment , Information security risk assessment 25 Oct 2022
Clause 6.1.3 Risk treatment , Information security risk treatment 25 Oct 2022
Clause 6.2 ISMS objectives , Information security objectives and planning 25 Oct 2022
Clause 6.3 Planning of changes , Change planning (new in 2022) 25 Oct 2022
Clause 7.5 Documented information , Documented information requirements 25 Oct 2022
Clause 8 Operation , Operational planning, risk assessment, treatment 25 Oct 2022
Clause 9 Performance evaluation , Monitoring, internal audit, management review 25 Oct 2022
ISO/IEC 27001:2022 (Oct 2022 base standard) , Information security management systems Requirements 25 Oct 2022
Amendment 1:2024 (climate action changes) , February 2024 climate change amendment 01 Feb 2024
A.5 Organizational controls (37 controls) , A.5.1 through A.5.37 15 Feb 2022
A.5.23 Cloud services (new) , Information security for use of cloud services 15 Feb 2022
A.5.34 Privacy and protection of PII , Privacy and PII protection 15 Feb 2022
A.5.7 Threat intelligence (new) , Threat intelligence programme requirement 15 Feb 2022
A.6 People controls (8 controls) , A.6.1 through A.6.8 15 Feb 2022
A.7 Physical controls (14 controls) , A.7.1 through A.7.14 15 Feb 2022
A.8 Technological controls (34 controls) , A.8.1 through A.8.34 15 Feb 2022
A.8.28 Secure coding (new) , Secure coding principles and standards 15 Feb 2022
ISO/IEC 27002:2022 (Feb 2022, 93 controls) , The 93 Annex A controls across 4 themes 15 Feb 2022
ISO/IEC 27005:2022 (risk management) , Information security risk management guidance 25 Oct 2022
ISO/IEC 27006:2015 + A1:2020 , Requirements for ISMS certification bodies 01 Jan 2020
ISO/IEC 27017:2015 (cloud code) , Code of practice for cloud services security 15 Dec 2015
ISO/IEC 27018:2019 (cloud PII) , Protection of PII in public clouds 01 Jan 2019
ISO/IEC 27701:2025 (standalone PIMS) , Privacy information management system standalone 14 Oct 2025
ISO/IEC 42001:2023 (AI Management System) , AI Management System standard 18 Dec 2023
NABCB Accreditation (QCI, IAF MLA) , NABCB accreditation regime for CBs in India 01 Jan 2023
NABCB 27701:2025 Transition Policy , Transition policy for ISO/IEC 27701:2025 01 Jan 2026
NABCB Symbol Mandate 1 July 2026 , Accreditation symbol mandate 01 Jul 2026
NIST Cybersecurity Framework 2.0 , NIST CSF v2.0 (Feb 2024) 26 Feb 2024
Freshworks ISO 27001 posture , Freshworks trust portal 01 Jan 2024
Infosys ISO 27001 posture , Infosys ISMS certification 01 Jan 2024
Zoho ISO 27001 posture , Zoho ISMS + cloud extensions 01 Jan 2024
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.