ISO 27001:2022 Lead Implementer & Auditor Bootcamp
Build an ISMS, write the Statement of Applicability, and run the audit, end to end.
Tuition
$2,000
Intermediate
Level
6
Modules
28
Lessons
6
Graded quizzes
6
Assignments
22 hours
Estimated time
What you will be able to do
- Explain the ISMS and the mandatory ISO 27001 Clauses 4–10
- Define scope, leadership commitment and the information security policy
- Run an ISO 27001 risk assessment and choose risk treatments
- Write a Statement of Applicability across the 93 Annex A controls in 4 themes
- Implement and evidence Annex A controls a certification auditor will accept
- Run an internal audit to ISO 19011 and prepare for Stage 1 and Stage 2
- Classify Major vs Minor nonconformities and write a CAPA with root-cause analysis
What is inside
6 modules, 28 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
ISO 27001 & the ISMS: Clauses 4 to 10
This is where ISO 27001 actually starts: not with a control list, but with a management system. You will learn what ISO/IEC 27001:2022 is, what an accredited certificate really means, why Clauses 4 to 10 are the mandatory spine while Annex A is only a reference set of 93 controls, how the Plan-Do-Check-Act loop keeps the whole thing alive, the difference between ISO 27001 and ISO 27002, and how an ISO 27001 certification differs from a SOC 2 attestation. You finish by writing a one-page explainer for a non-technical executive at Honeycomb Bakery.
5 lessons · 16 quiz questions · assignment
- 02
Context, Leadership & Planning (Clauses 4-6)
Module 1 told you what ISO 27001 is. This module is where you actually start building the ISMS. You will work through the first three management-system clauses: Clause 4 (context, interested parties, scope), Clause 5 (leadership, the information security policy, roles), and Clause 6 (the risk assessment, the four treatment options, risk acceptance, and objectives). You will also see how the risk work feeds the Statement of Applicability. You finish by scoping an ISMS and building a risk assessment for Honeycomb Bakery Group.
4 lessons · 20 quiz questions · assignment
- 03
Annex A & the Statement of Applicability
Clauses 4 to 10 are the mandatory ISMS machine. Annex A is the menu of controls that machine chooses from. This module walks you through the 93 Annex A:2022 controls reorganised into four themes, the eleven genuinely new 2022 controls, the five control attributes, and the single most important document in the whole ISMS: the Statement of Applicability. You finish by writing a Mini SoA for Honeycomb Bakery, with applicable controls with real implementation, evidence and owners, plus at least one excluded control with a defensible justification.
4 lessons · 16 quiz questions · assignment
- 04
Operation & Implementing the Controls
Modules so far built the management system on paper: scope, risk assessment, the Statement of Applicability. This module is where the ISMS starts to breathe. You will learn Clause 8, operational planning and control, and running the risk assessment and treatment at planned intervals, then walk through implementing and evidencing eight key Annex A:2022 controls across all four themes. You will learn to read the risk treatment plan as the bridge from the risk register to the selected controls, and to name the exact evidence a certification auditor will sample. You finish by selecting six controls for Honeycomb Bakery and mapping three real risks to them.
5 lessons · 16 quiz questions · assignment
- 05
Performance Evaluation & the Internal Audit
Clause 9 is where the ISMS gets checked. You will learn how monitoring, measurement, analysis and evaluation work under Clause 9.1, how to build and run an internal audit programme under Clause 9.2, the ISO 19011 principles that govern every audit, how to write findings that survive challenge because they cite evidence, and why a missing management review under Clause 9.3 is a textbook Major nonconformity. You finish by building a short internal audit plan for Honeycomb Bakery and writing three evidence-based findings.
5 lessons · 16 quiz questions · assignment
- 06
Certification, Nonconformities, CAPA & Capstone
You have built the ISMS and you have audited it. Now you take it to certification. This module covers Clause 10, which deals with nonconformity, corrective action and continual improvement, then walks the certification journey from Stage 1 readiness to the Stage 2 audit, how findings are classified, and how to write a CAPA that separates correction from corrective action using a real 5-whys. You finish with the capstone: a three-finding CAPA memo pack from a Honeycomb Stage 2 audit, plus interview prep for ISO 27001 roles.
5 lessons · 18 quiz questions · assignment