Home / Courses / Corporate Governance and Compliance (GRC) / ISO/IEC 27001 Lead Implementer (Information Security)
Corporate Governance and Compliance (GRC)

ISO/IEC 27001 Lead Implementer (Information Security)

ISO/IEC 27001 is the management system standard that boards, customers and procurement teams already trust…

Code BII-27001LI 5-Day Almaty, Dubai, London, Online Online + Classroom
Overview

Course Description

ISO/IEC 27001 is the management system standard that boards, customers and procurement teams already trust — and it has become the entry requirement for selling into enterprise. It is also the foundation for AI governance: because ISO 42001 shares the same high-level structure, organisations with a working ISMS find AI management dramatically easier to implement.

This course develops the capability to implement an ISMS and take it to certification. Participants learn the standard's structure, context and scope definition, leadership and policy, information security risk assessment and treatment, the Annex A control set, the Statement of Applicability, documented information, internal audit and management review, and the certification process.

Objectives

What you will achieve

By the end of this training course, participants will be able to:

  • Explain ISO/IEC 27001 and the ISMS concept
  • Establish context, scope and interested parties
  • Define leadership commitment, policy and roles
  • Conduct information security risk assessment and treatment
  • Apply the Annex A control set
  • Produce and maintain the Statement of Applicability
  • Manage documented information and operational control
  • Prepare for and pass certification audit
Training methodology

How the course is delivered

The course works through the standard clause by clause with practical exercises in scoping, risk assessment, control selection and Statement of Applicability development on realistic organisational scenarios.

The programme also positions ISO 27001 as the foundation for ISO 42001, reflecting the common implementation path organisations follow when adding AI governance.

Who should attend

Designed for

This training course is ideal for:

  • Information security and IT managers
  • GRC, compliance and risk professionals
  • CISOs and security leads
  • Consultants implementing ISMS
  • Anyone preparing for ISO 27001 certification
Course outline

Daily programme

DAY 01The Standard and the ISMS
  • ISO/IEC 27001 and the ISMS concept
  • Management system standards and certification
  • Structure and the high-level structure
  • Context, scope and interested parties
DAY 02Leadership and Risk
  • Leadership, policy and roles
  • Information security objectives
  • Information security risk assessment
  • Risk treatment and acceptance
DAY 03Controls and Applicability
  • The Annex A control set
  • Organisational and people controls
  • Physical and technological controls
  • The Statement of Applicability
DAY 04Operation and Documentation
  • Operational planning and control
  • Documented information
  • Awareness, competence and communication
  • Supplier and third-party security
DAY 05Evaluation and Certification
  • Monitoring, measurement and evaluation
  • Internal audit and management review
  • Continual improvement
  • Certification process, path to ISO 42001, workshop
Certificate

Certification & accreditation

BII Certificate of Completion

BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.

Schedule

Upcoming sessions

DatesVenueFormatFee
21 - 25 Sep 2026 Almaty Classroom US$ 3950 Register
26 - 30 Apr 2027 Online Online US$ 3950 Register
07 - 11 Jun 2027 London Classroom US$ 3950 Register
02 - 06 Aug 2027 Dubai Classroom US$ 3950 Register
Enrolment

Register, request in-house, or download the agenda

Choose an action and share your details — our team responds within one business day with dates, fees and the full programme.

Poster