ISO 27001 Training Courses

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our ISO 27001 training courses teach your team how to build, run and audit an information security management system (ISMS) that meets ISO/IEC 27001:2022. Security Solution Consultants (SSC) delivers ISO 27001 Foundation, Internal Auditor, Lead Auditor and Lead Implementer courses, plus ISO/IEC 27002 controls training, live online or on-site for teams across Australia, New Zealand, the Gulf and Asia.

Instructor beside a screen showing a glowing shield and padlock graphic while participants work on laptops, representing ISO 27001 training
ISO 27001 training gives your team a shared language for information security.

ISO 27001 courses at a glance

CourseTypical durationBest for
ISO 27001 Foundation2 daysAnyone involved in an ISMS: staff, managers, IT and project teams
ISO 27002 Foundation: information security controls2 daysIT, security and control owners who implement Annex A controls
ISO 27001 Internal Auditor3 daysStaff who will run internal ISMS audits under clause 9.2
ISO 27001 Lead Implementer5 daysISMS managers and consultants building or improving an ISMS
ISO 27001 Lead Auditor5 daysExperienced professionals leading audits, including certification-style audits
ISO 27001 executive briefing2 to 3 hoursExecutives and board members who sponsor the ISMS

What the standard covers

ISO/IEC 27001:2022 sets the requirements for an ISMS in clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: organisational (37), people (8), physical (14) and technological (34). ISO/IEC 27002:2022 gives the detailed guidance for implementing each control. The transition period from the 2013 edition ended on 31 October 2025, so all certified organisations now work to the 2022 edition, and our courses teach it exclusively.

Course details

ISO 27001 Foundation

Typical duration: 2 days. Who it is for: people new to ISO 27001, and anyone who will contribute to an ISMS.

  • Why information security management matters and how certification works
  • The structure of ISO/IEC 27001:2022: clauses 4 to 10 and Annex A
  • Risk assessment and risk treatment, and the Statement of Applicability
  • Documented information, roles, competence and awareness
  • Internal audit, management review and continual improvement

You will be able to: explain the requirements of ISO 27001 confidently and take part in an ISMS project or audit.

ISO 27002 Foundation: information security controls

Typical duration: 2 days. Who it is for: control owners in IT, security, HR, facilities and supplier management.

  • The 93 controls and their organisational, people, physical and technological themes
  • Control attributes such as control type and cybersecurity concept, and how to use them
  • New 2022 controls including threat intelligence, cloud services, data masking, data leakage prevention and secure coding
  • Evidence that shows a control is designed and operating

You will be able to: select, implement and evidence Annex A controls in proportion to your risks.

ISO 27001 Internal Auditor

Typical duration: 3 days. Who it is for: staff who will plan and conduct internal ISMS audits.

  • Audit principles from ISO 19011 and the requirements of clause 9.2
  • Building a risk-based audit programme and audit plan
  • Interviewing, sampling and collecting objective evidence
  • Writing clear nonconformities and audit reports
  • Following up corrective actions

You will be able to: run independent internal audits that satisfy certification auditors and improve the ISMS.

Two professionals in an audit role-play reviewing a binder of evidence and a tablet, representing ISO 27001 auditor training
Role-play audits build the confidence to ask the right questions and test real evidence.

ISO 27001 Lead Implementer

Typical duration: 5 days. Who it is for: ISMS managers, security leads and consultants responsible for an ISMS.

  • Planning an ISMS project: scope, context, interested parties and leadership commitment
  • Designing a risk method, risk register and treatment plan
  • Writing a Statement of Applicability and proportionate policies
  • Implementing and operating controls, metrics and awareness
  • Preparing for Stage 1 and Stage 2 certification audits

You will be able to: lead an ISO 27001 implementation from gap assessment to certification readiness.

ISO 27001 Lead Auditor

Typical duration: 5 days. Who it is for: auditors, consultants and security professionals who will lead audit teams.

  • The audit lifecycle from ISO 19011 and how certification bodies apply ISO/IEC 27006
  • Stage 1 and Stage 2 audit planning and leading an audit team
  • Evaluating risk assessment, Statement of Applicability and control effectiveness
  • Grading findings, closing meetings and audit reports
  • Exam preparation where an accredited exam is included

You will be able to: plan, lead and report on ISMS audits to a professional standard.

Practical exercises

Workshop participants arranging coloured cards into a control grid beside a laptop, representing ISO 27001 implementer training
Participants build real ISMS artefacts during the course, not just read about them.

Each course uses a realistic case study organisation. Participants define a scope, build a risk register, choose controls for a Statement of Applicability, collect evidence and conduct a short audit. For private courses we can use your own scope and documents, so the training doubles as the first step of your ISMS project.

How the ISO 27001 training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who implement and audit information security management systems for clients every year, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Need more than training? See our ISO 27001 implementation and certification services, ISO 27001 certification in New Zealand, or browse all cyber security and compliance training.

Frequently asked questions

Most people start with ISO 27001 Foundation. If you will run internal audits, continue to Internal Auditor; if you will build or manage the ISMS, choose Lead Implementer; if you will lead audits professionally, choose Lead Auditor.

Yes. All courses teach the 2022 edition, including the 93 Annex A controls. The transition from the 2013 edition ended on 31 October 2025.

Every participant receives a certificate of completion. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner; your quote confirms the exam details.

Lead Implementer teaches you to build and run an ISMS. Lead Auditor teaches you to audit one and lead an audit team. Many ISMS managers take both, starting with the role they will perform first.

Yes. We deliver private on-site courses and live online classes, and can use your own scope, policies and risk register in the exercises.

Training is not a certification requirement, but clause 7.2 requires people to be competent for their roles. Trained internal auditors and an ISMS manager who understands the standard make certification faster and audits smoother.

Plan ISO 27001 training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com