Our ISO 27001 training courses teach your team how to build, run and audit an information security management system (ISMS) that meets ISO/IEC 27001:2022. Security Solution Consultants (SSC) delivers ISO 27001 Foundation, Internal Auditor, Lead Auditor and Lead Implementer courses, plus ISO/IEC 27002 controls training, live online or on-site for teams across Australia, New Zealand, the Gulf and Asia.

| Course | Typical duration | Best for |
|---|---|---|
| ISO 27001 Foundation | 2 days | Anyone involved in an ISMS: staff, managers, IT and project teams |
| ISO 27002 Foundation: information security controls | 2 days | IT, security and control owners who implement Annex A controls |
| ISO 27001 Internal Auditor | 3 days | Staff who will run internal ISMS audits under clause 9.2 |
| ISO 27001 Lead Implementer | 5 days | ISMS managers and consultants building or improving an ISMS |
| ISO 27001 Lead Auditor | 5 days | Experienced professionals leading audits, including certification-style audits |
| ISO 27001 executive briefing | 2 to 3 hours | Executives and board members who sponsor the ISMS |
ISO/IEC 27001:2022 sets the requirements for an ISMS in clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: organisational (37), people (8), physical (14) and technological (34). ISO/IEC 27002:2022 gives the detailed guidance for implementing each control. The transition period from the 2013 edition ended on 31 October 2025, so all certified organisations now work to the 2022 edition, and our courses teach it exclusively.
Typical duration: 2 days. Who it is for: people new to ISO 27001, and anyone who will contribute to an ISMS.
You will be able to: explain the requirements of ISO 27001 confidently and take part in an ISMS project or audit.
Typical duration: 2 days. Who it is for: control owners in IT, security, HR, facilities and supplier management.
You will be able to: select, implement and evidence Annex A controls in proportion to your risks.
Typical duration: 3 days. Who it is for: staff who will plan and conduct internal ISMS audits.
You will be able to: run independent internal audits that satisfy certification auditors and improve the ISMS.

Typical duration: 5 days. Who it is for: ISMS managers, security leads and consultants responsible for an ISMS.
You will be able to: lead an ISO 27001 implementation from gap assessment to certification readiness.
Typical duration: 5 days. Who it is for: auditors, consultants and security professionals who will lead audit teams.
You will be able to: plan, lead and report on ISMS audits to a professional standard.

Each course uses a realistic case study organisation. Participants define a scope, build a risk register, choose controls for a Statement of Applicability, collect evidence and conduct a short audit. For private courses we can use your own scope and documents, so the training doubles as the first step of your ISMS project.
Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.
Need more than training? See our ISO 27001 implementation and certification services, ISO 27001 certification in New Zealand, or browse all cyber security and compliance training.
Most people start with ISO 27001 Foundation. If you will run internal audits, continue to Internal Auditor; if you will build or manage the ISMS, choose Lead Implementer; if you will lead audits professionally, choose Lead Auditor.
Yes. All courses teach the 2022 edition, including the 93 Annex A controls. The transition from the 2013 edition ended on 31 October 2025.
Every participant receives a certificate of completion. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner; your quote confirms the exam details.
Lead Implementer teaches you to build and run an ISMS. Lead Auditor teaches you to audit one and lead an audit team. Many ISMS managers take both, starting with the role they will perform first.
Yes. We deliver private on-site courses and live online classes, and can use your own scope, policies and risk register in the exercises.
Training is not a certification requirement, but clause 7.2 requires people to be competent for their roles. Trained internal auditors and an ISMS manager who understands the standard make certification faster and audits smoother.
Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.
Prefer email? Write to info@secsolutionshub.com

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.