Tranchulas

ISO 27001 Implementation Training Course

Design, evidence and certify an ISMS against ISO/IEC 27001:2022

An intensive three-day implementation course covering the full management system: organisational context and scope, ISO 27005 risk assessment, risk treatment and the Statement of Applicability, all 93 Annex A controls, the documented information the standard requires, internal audit, and Stage 1 and Stage 2 certification. Thirteen applied modules, six workshop exercises, and the artefacts an auditor will actually sample.

About the Course

ISO/IEC 27001:2022 is now the only edition in play — the transition period from the 2013 standard closed on 31 October 2025, and every live certificate is against the 2022 edition of the standard with 93 Annex A controls across four themes rather than 114 across fourteen. It also carries Amendment 1:2024, the climate-action change to Clause 4 that requires an organisation to determine whether climate change is a relevant issue in its context. It is short, easy to miss, and auditors do ask for the determination, including where the answer is no.

This course trains implementers to take the decisions in the right order. Most failed implementations are not control failures; they are scope failures and sequence failures. Participants define a defensible ISMS scope, run an ISO 27005-aligned risk assessment against criteria agreed in advance, and produce a Statement of Applicability that is an output of risk treatment rather than a checklist justified afterwards — because Clause 6.1.3 requires exactly that, and reversing it is what unravels at audit.

The course also treats the ISMS as the evidence base it has become. NIS2, DORA and the EU Cyber Resilience Act now draw on the same risk records, incident evidence and management accountability, so a system built only to pass a certification audit will not answer a regulator. Day three closes on internal audit, Stage 1 and Stage 2 preparation, corrective action, surveillance and re-certification — the years in which most management systems quietly decay.

ISO 27001 implementation training sits within the wider Tranchulas cyber security training catalogue, alongside related programmes such as our GDPR practitioner course for teams building an integrated compliance capability.

  • Compliance
    Why Choose Tranchulas
    • CREST Cyber Training Provider, delivering to an internationally recognised standard
    • Built on ISO/IEC 27001:2022 including Amendment 1:2024, re-verified before every delivery
    • Six workshop exercises producing real artefacts — scope statement, risk register, SoA, audit findings
    • Templates you keep: Statement of Applicability, risk treatment plan, internal audit programme, corrective action record
  • Elite team
    Who Should Attend
    • ISMS implementers and project leads working to a certification date
    • Information security managers and CISOs who own the risk decisions
    • Compliance and risk officers
    • Internal and external auditors
    • IT and engineering managers operating the controls
    • Cybersecurity consultants advising on ISO 27001 implementation

Professional Capabilities

Participants leave able to build a management system that produces defensible evidence — not only through certification, but through surveillance audits, re-certification and a standards family that is visibly moving.

Search black

Strategic ISMS Planning

Establish organisational context under Clauses 4.1 to 4.3, including the Amendment 1:2024 climate determination, and define an ISMS scope boundary that holds up under questioning rather than one drawn for convenience.

Gears

Risk Management Expertise

Run an ISO 27005-aligned risk assessment from asset identification through to scored risk, against criteria and acceptance levels agreed before anything is scored — and record who owns the residual risk.

Brain

Master Control Implementation

Select controls by risk and justify every Annex A inclusion and exclusion across all four themes: 37 organisational, 8 people, 14 physical and 34 technological controls.

Target2

Audit and Compliance Leadership

Plan and run an internal audit programme to Clause 9.2, grade nonconformities, drive corrective action to verified closure, and manage Stage 1 and Stage 2 certification audits.

Course Content & Learning Experience

Our comprehensive ISO 27001 Implementation curriculum combines foundational principles with advanced, practical audit techniques. Through engaging workshops and real-world case studies, participants gain hands-on experience tackling challenges encountered by information security managers, compliance officers, and industry experts.

Globe
Strategic Planning & Risk Assessment Foundation

Establish the foundations everything else rests on: the 2022 clause structure, organisational context under Clauses 4.1 to 4.3 including the Amendment 1:2024 climate determination, the ISMS scope boundary, leadership and policy under Clause 5, and an ISO 27005-aligned risk assessment run against criteria agreed in advance.

Workshop Experience: Draft a scope statement and defend it, then conduct an asset inventory, threat and vulnerability analysis and initial risk identification against agreed risk criteria — producing risk register entries someone else could reproduce.

Key Learning Areas:

  • ISO/IEC 27001:2022 structure, and what a certificate actually asserts
  • Clauses 4.1 to 4.3, interested parties, and the Amendment 1:2024 climate consideration
  • Defining an ISMS scope boundary with justified exclusions and named interfaces
  • Information security policy, governance and Clause 5 leadership evidence
  • ISO 27005 risk methodology: assets, threats, vulnerabilities and risk criteria
AI-Enhanced Audits
Control Implementation & Policy Development

Turn risk into controls and evidence. Risk treatment options and control selection, a Statement of Applicability produced as an output of treatment rather than a checklist justified afterwards, all 93 Annex A controls across the four themes, and the documented information Clause 7.5 actually requires.

Workshop Experience: Develop risk treatment strategies for identified risks, build a Statement of Applicability with a stated reason against every inclusion and exclusion, map controls to business requirements, and assemble a sample ISMS documentation package under version control.

Key Learning Areas:

  • Treatment options — modify, retain, avoid, share — and control selection driven by risk
  • Statement of Applicability and risk treatment plan under Clause 6.1.3
  • Organisational, people and physical controls, including what they mean without an office
  • Technological controls: access, cryptography, network, secure development and cloud
  • Documented information, record keeping and document control under Clause 7.5
Integration
Audit Excellence & Continuous Improvement

Audit the result and take it to certification. Clause 9.1 monitoring and measurement, management review that produces decisions, an internal audit programme to Clause 9.2, incident management and continuity, then Stage 1 and Stage 2 preparation, corrective action, surveillance and re-certification.

Workshop Experience: Conduct a mock internal audit, grade the nonconformities and write findings that survive challenge — then prepare for a certification audit and face the Stage 1 interview on the decisions taken on day two.

Key Learning Areas:

  • Clause 9.1 metrics that show whether controls work, and Clause 9.3 management review
  • Internal audit planning, auditor independence, evidence sampling and reporting
  • Incident management, ICT readiness, and where statutory reporting clocks run separately
  • Stage 1 and Stage 2 audits, managing external auditors, corrective action to closure
  • Integration with ISO/IEC 42001 and privacy management, supplier assurance and security culture

Upcoming Training Dates

16 - 18

November, 2026

COSMO HUB-Petrakijina 24

Sarajevo, Bosnia and Herzegovina