ISO/IEC 27001:2022 Lead Implementer Training
Build, run and certify an information security management system against ISO/IEC 27001:2022 — from mandate and scope through risk assessment, the Statement of Applicability and Annex A controls to a Stage 2 audit.
29
Lessons
~16h
Study time
30
Exam questions
Earns a QR-verifiable Certificate of Training
Overview
About this course
ISO/IEC 27001:2022 is the certifiable standard for an information security management system, and since the 2013 edition's transition period closed on 31 October 2025 every valid certificate is issued against the 2022 requirements. This course teaches the implementer's side of that standard: how to win the mandate, define a scope that stands up, run a risk assessment that produces defensible decisions, select and operate controls, and take the management system through Stage 1 and Stage 2 to an accredited certificate.
The programme follows the order in which the work is actually done, mapping each step to the clause it satisfies: business case and project governance; context, interested parties and the scope statement with its boundaries and interfaces; policy, objectives and the duties top management cannot delegate; risk assessment and treatment at 6.1.2 and 6.1.3 with ISO/IEC 27005:2022 as the method reference, comparing asset-threat-vulnerability and event-based identification; the Statement of Applicability as the document tying the 93 Annex A controls to the treatment decisions, including justified exclusions and controls adopted for non-risk reasons; the 2022 Annex A themes, attributes and eleven new controls, using ISO/IEC 27002:2022 as implementation guidance — guidance that cannot itself be certified against; the support and operation clauses; and performance evaluation, internal audit and management review.
It is written for CISOs, IT and security managers, GRC staff and consultants who own an ISMS project. No prior ISO/IEC 27001 knowledge is assumed; a working IT background is.
Assessment is a 30-question online exam with a 70% pass mark, and successful learners receive a verifiable SKEDMIA certificate. Approximately 16.5 hours of self-paced study, with downloadable scope, risk register and SoA templates and a nine-month implementation plan.
What you earn
A certificate anyone can verify in seconds
Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.
Verified at skedmia.com/verify
Certified by
Syllabus
Course content
10 modules · 29 lessons · ~16h
01Module 1 — ISO/IEC 27001:2022, the Standard Family and the Implementation Project3 lessons
- What ISO/IEC 27001:2022 Requires and What Certification Commits You To34 min
- The ISO/IEC 27000 Family — 27002, 27005, 27003 and the Sector ExtensionsPreview30 min
- The ISMS as a Project — Mandate, Business Case and Governance35 min
02Module 2 — Context, Interested Parties and Scope — Clause 4 in Practice3 lessons
- Understanding the Organisation and Its Context — Clause 4.132 min
- Interested Parties and Their Requirements — Clause 4.230 min
- Defining the Scope — Boundaries, Interfaces and Dependencies (4.3 and 4.4)40 min
03Module 3 — Leadership, Policy, Roles and Objectives — Clauses 5, 6.2 and 6.33 lessons
- Top Management's Duties — Clause 5.1 Leadership and Commitment33 min
- The Information Security Policy and Measurable Objectives — 5.2 and 6.235 min
- Roles, Responsibilities and Authorities — Clause 5.3 in Practice35 min
04Module 4 — The Risk Management Framework — Clause 6.1 and ISO/IEC 27005:20223 lessons
- Actions to Address Risks and Opportunities — 6.1.1 and the Risk Process32 min
- Risk Criteria, Scales and Risk Owners40 min
- Asset-Threat-Vulnerability or Event-Based? Choosing the Identification Approach40 min
05Module 5 — Conducting the Risk Assessment — Identification, Analysis and Evaluation3 lessons
- Risk Identification — Building Credible Scenarios33 min
- Risk Analysis and Evaluation — Getting to a Defensible Score40 min
- The Risk Register as a Working Document35 min
06Module 6 — Risk Treatment and the Statement of Applicability — Clause 6.1.33 lessons
- Treatment Options and Control Selection — 6.1.3(a) and (b)32 min
- The Statement of Applicability — 93 Controls, Justifications and Exclusions40 min
- The Risk Treatment Plan — From Decision to Delivery35 min
07Module 7 — Annex A and ISO/IEC 27002:2022 — Themes, Attributes and the Eleven New Controls3 lessons
- The 2022 Annex A Structure — Four Themes and Five Attributes34 min
- The Eleven New Controls — What They Actually Demand40 min
- Implementing Controls — Turning the SoA into Operating Reality35 min
08Module 8 — Support and Operation — Clauses 7 and 83 lessons
- Resources, Competence and Awareness — 7.1, 7.2 and 7.333 min
- Communication and Documented Information — 7.4 and 7.535 min
- Operational Planning, Change and Outsourcing — 8.1, 8.2, 8.3 and 6.340 min
09Module 9 — Performance Evaluation, Improvement and Certification — Clauses 9, 10 and the Audit Journey3 lessons
- Monitoring, Measurement and the Internal Audit Programme — 9.1 and 9.232 min
- Management Review, Nonconformity and Continual Improvement — 9.3 and 1040 min
- The Certification Journey — Certification Body, Stage 1, Stage 2 and Surveillance40 min
10Course materials & downloads2 lessons
- ISMS Core Document Pack — Scope Statement, Risk Register and Statement of Applicability Templates (PDF)
- Nine-Month Implementation Plan and Certification Readiness Checklist (PDF)
Free Zone
Free documents for this standard
Keep browsing
More it, security & ai training

ISO 27001 (The International Information Security Standard)
ISO 27001 2013 VS 27001 2022

IT Courses
Internet Of Things
NewInformation Security

