
ISO 27001 Course
Master ISO 27001 from the ground up and gain the expertise to build, implement, and certify an Information Security Management System. This course covers every clause, control, and audit requirement you need to protect your organisation and earn stakeholder trust. Whether you're leading an ISMS project or supporting certification, this is the practical training that gets results.
What you will learn:
This course takes you through every requirement of the ISO 27001 standard, from foundational information security concepts to the full certification audit process. You will learn how to define your ISMS scope, conduct risk assessments, select Annex A controls, and produce a Statement of Applicability. You will also develop security policies, design awareness programmes, and establish performance monitoring processes. The course covers internal auditing, nonconformity management, and corrective action planning. By the end, you will have the knowledge to lead an ISO 27001 implementation and guide your organisation through external certification.
How you study practically ISO 27001 Course
How you practise ISO 27001 Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 37 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Information Security and ISO 27001
Introduction to Information Security and ISO 27001
Lesson 1 • Overview of the ISO 27001 Standard
Introduces the structure, purpose, and history of ISO 27001. Positions the standard within the broader ISO/IEC 27000 family.
Lesson 2 • Business Case for ISO 27001 Certification
Examines organisational drivers for adopting ISO 27001. Connects certification benefits to risk reduction and stakeholder trust.
Lesson 3 • Roles and Responsibilities in an ISMS
Defines key roles required to operate an Information Security Management System. Clarifies accountability structures needed throughout implementation.
Lesson 4 • Core Concepts of Information Security
Covers confidentiality, integrity, and availability as the CIA triad. Provides the conceptual baseline required for all subsequent ISO 27001 topics.
Chapter 2HideHide detailsSee detailsUnderstanding the ISMS Framework
Understanding the ISMS Framework
Lesson 1 • Leadership and Commitment Requirements
Addresses Clause 5 obligations for top management engagement. Demonstrates how leadership commitment directly enables ISMS effectiveness.
Lesson 2 • The Plan-Do-Check-Act Cycle
Explains the PDCA model as the operational engine of an ISMS. Demonstrates how each phase drives continuous improvement.
Lesson 3 • Defining Organisational Context
Covers Clause 4 requirements for understanding internal and external issues. Establishes context as the foundation for scope and risk decisions.
Lesson 4 • Determining the ISMS Scope
Guides students through scoping decisions that define ISMS boundaries. Correct scoping prevents gaps and over-engineering in implementation.
Lesson 5 • ISMS Documentation Architecture
Introduces mandatory and supporting documentation required by the standard. Establishes document control practices used throughout the ISMS lifecycle.
Chapter 3HideHide detailsSee detailsInformation Security Risk Management
Information Security Risk Management
Lesson 1 • Establishing the Risk Assessment Process
Covers criteria, methodology selection, and process documentation for risk assessment. A consistent methodology is required for repeatable, auditable results.
Lesson 2 • Risk Management Fundamentals
Establishes risk terminology and frameworks aligned with ISO 31000. Provides the conceptual grounding needed before applying ISO 27001 risk processes.
Lesson 3 • Statement of Applicability
Explains the purpose, structure, and mandatory content of the Statement of Applicability. Connects control selection justifications to risk treatment decisions.
Lesson 4 • Identifying and Analysing Risks
Guides students through systematic risk identification and likelihood-impact analysis. Produces a prioritised risk register as a core ISMS artefact.
Lesson 5 • Risk Treatment Planning
Covers the four risk treatment options and selection criteria. Links treatment decisions to Annex A controls and the Statement of Applicability.
Chapter 4HideHide detailsSee detailsAnnex A Controls Deep Dive
Annex A Controls Deep Dive
Lesson 1 • Incident Management and Business Continuity Controls
Examines controls for detecting, responding to, and recovering from security events. Connects incident management to business continuity planning requirements.
Lesson 2 • Organisational and People Controls
Examines controls governing policies, roles, human resources, and supplier relationships. These controls form the governance layer of the ISMS.
Lesson 3 • Technological Controls: Access and Cryptography
Addresses access management, authentication, and cryptographic controls. These controls directly mitigate unauthorised access and data exposure risks.
Lesson 4 • Technological Controls: Operations and Networks
Covers operational security, network controls, and vulnerability management. Operational controls maintain day-to-day security posture across systems.
Lesson 5 • Physical and Environmental Controls
Covers controls protecting physical facilities, equipment, and media. Physical security failures can bypass all technical controls.
Chapter 5HideHide detailsSee detailsImplementing the ISMS
Implementing the ISMS
Lesson 1 • Security Awareness and Training Programmes
Covers designing and delivering security awareness programmes required by Clause 7. Awareness reduces human-factor risks identified in the risk assessment.
Lesson 2 • Implementation Planning and Roadmap
Covers project planning, resource allocation, and milestone setting for ISMS implementation. A structured roadmap prevents scope creep and missed deadlines.
Lesson 3 • Developing Security Policies and Procedures
Guides creation of the policy hierarchy from top-level policy to operational procedures. Policies must align with organisational context and risk treatment decisions.
Lesson 4 • Implementing Technical and Physical Controls
Addresses the practical deployment of selected Annex A controls. Connects control implementation to documented risk treatment decisions.
Lesson 5 • Operational Readiness and Go-Live
Prepares the organisation to operate the ISMS in production. Validates that all mandatory elements are in place before the monitoring phase begins.
Chapter 6HideHide detailsSee detailsPerformance Evaluation and Monitoring
Performance Evaluation and Monitoring
Lesson 1 • Monitoring and Measurement Processes
Establishes continuous monitoring processes for controls and risk posture. Ongoing monitoring detects control failures before they become incidents.
Lesson 2 • Internal Audit Planning and Execution
Guides students through planning, conducting, and documenting internal ISMS audits. Internal audits provide evidence of conformance required for certification.
Lesson 3 • Defining Security Metrics and KPIs
Covers selection and design of meaningful information security metrics. Metrics must demonstrate ISMS effectiveness and support management decisions.
Lesson 4 • Management Review Process
Covers Clause 9.3 management review inputs, outputs, and frequency requirements. Management reviews drive strategic decisions about ISMS direction and resources.
Chapter 7HideHide detailsSee detailsContinual Improvement and Nonconformity Management
Continual Improvement and Nonconformity Management
Lesson 1 • Identifying and Classifying Nonconformities
Defines nonconformity types and sources within an ISMS context. Accurate classification determines the appropriate corrective action response.
Lesson 2 • Root Cause Analysis Techniques
Introduces structured root cause analysis methods applicable to security nonconformities. Identifying true root causes prevents recurrence of the same failures.
Lesson 3 • Driving Continual Improvement
Explores proactive improvement opportunities beyond reactive nonconformity management. Continual improvement sustains certification and adapts the ISMS to evolving threats.
Lesson 4 • Corrective Action Planning and Tracking
Covers designing, assigning, and tracking corrective actions to closure. Effective tracking ensures nonconformities are resolved before certification audits.
Chapter 8HideHide detailsSee detailsISO 27001 Certification Audit Process
ISO 27001 Certification Audit Process
Lesson 1 • Stage 1 Documentation Review
Explains the purpose and process of the Stage 1 readiness review. Stage 1 findings must be resolved before proceeding to the on-site Stage 2 audit.
Lesson 2 • Stage 2 On-Site Certification Audit
Prepares students for the full conformity assessment conducted on-site. Demonstrates how auditors sample evidence and evaluate ISMS effectiveness.
Lesson 3 • Selecting a Certification Body
Covers criteria for choosing an accredited certification body and managing the engagement. The right certification body ensures audit credibility and process efficiency.
Lesson 4 • Post-Certification ISMS Maturity Growth
Guides organisations from basic certification compliance toward ISMS maturity. Maturity growth maximises the long-term security and business value of the ISMS.
Lesson 5 • Surveillance and Recertification Audits
Covers ongoing surveillance audit obligations and the three-year recertification cycle. Sustained conformance requires continuous ISMS operation between audits.
Your valid completion certificate
This course is for you:
IT managers tasked with achieving ISO 27001 certification for their organisation.
Compliance officers expanding their expertise into information security frameworks.
Security consultants who advise clients on building formal governance programmes.
System administrators ready to move into security leadership and management roles.
Risk analysts seeking structured methods to address information security threats.
Career changers from auditing or legal backgrounds entering the cybersecurity field.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top training programmes
FAQ
Who is Dedika?
Is the certificate valid in Kenya?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















