What Is ISO 27001 Training?
ISO 27001 training is professional development in ISO/IEC 27001:2022, the international standard for information security management systems (ISMS). It equips professionals to design, implement, operate, and audit an ISMS including all 93 Annex A controls across four categories, risk assessment methodology, and third-party certification audit preparation.
ISO 27001 is the world's leading standard for information security management. In 2026, ISO 27001:2022 certification is increasingly required by enterprise clients, financial services regulators, and public sector organisations as evidence of systematic information security controls, making ISO 27001 training one of the most commercially valuable credentials in the UK compliance market.
This CPD-certified course covers the complete ISO 27001:2022 framework, from ISMS scope definition and risk assessment through all 93 Annex A controls, Statement of Applicability, and internal audit, preparing your team for a UKAS-accredited ISO 27001 certification audit with confidence.
ISO 27001 Course Curriculum: Updated for 2022
The ISO 27001:2022 curriculum takes you from standard interpretation through to full certification readiness:
ISO 27001:2022 Standard
- Standard structure: clauses 4–10 and their requirements
- Key changes from ISO 27001:2013 to ISO 27001:2022
- ISO 27001 and related standards: 27002, 27005, 27701
- Certification bodies: UKAS-accredited certification in the UK
ISMS Design
- Defining ISMS scope: inclusions, exclusions, and interfaces
- Understanding organisational context: stakeholders and requirements
- Leadership and commitment: management responsibilities
- Statement of Applicability (SoA): structure and preparation
Risk Assessment
- Asset-based risk assessment methodology
- Threat modelling and vulnerability identification
- Risk treatment: accept, transfer, mitigate, or avoid
- Risk owner accountability and treatment plan documentation
Annex A Controls
- Organisational controls (A.5): policies, roles, threat intelligence, asset management
- People controls (A.6): screening, training, disciplinary processes, remote working
- Physical controls (A.7): physical security perimeters, equipment maintenance
- Technological controls (A.8): endpoint security, identity management, encryption, logging
Audit & Certification
- Internal audit programme design and scheduling
- Conducting ISMS internal audits: evidence collection
- Non-conformity management and corrective action
- Stage 1 and Stage 2 external certification audit preparation
