- 13 Sections
- 72 Lessons
- 660 Minutes
- ISMS Purpose and the ISO/IEC 27000 Family
Outcome: Explain the purpose, value, architecture and current ISO/IEC 27000-family context of an information security management system.
Case: Project Pramaan is a fictional Indian software-services company growing into regulated markets. Leaders want a certificate quickly, but security work is fragmented and ownership is unclear.
Tools: Standards-family map, ISMS value case, CIA and risk worksheet
7 - Requirements Architecture and Evidence
Outcome: Interpret the ISO/IEC 27001 management-system structure and distinguish requirements, guidance, controls, evidence and certification.
Case: Project Pramaan has hundreds of security documents but cannot show how they connect to requirements, risk decisions or operating evidence.
Tools: Clause architecture map, Requirement-evidence matrix, Document-status register
7 - Context, Interested Parties, Scope, and Climate
Outcome: Analyse organizational context, interested parties, climate relevance and scope to define a defensible ISMS boundary.
Case: Project Pramaan operates from Pune and Bengaluru, uses cloud suppliers and remote staff, serves EU and Indian clients, and faces flood and heat risks affecting facilities and availability.
Tools: Context register, Interested-party matrix, ISMS scope statement
7 - Leadership, Policy, Roles, and Governance
Outcome: Translate leadership, policy, roles and governance requirements into accountable management practices.
Case: Project Pramaan's security manager owns every task on paper, while executives approve budgets without reviewing risk or performance.
Tools: Leadership evidence map, Information-security policy, Responsibility matrix
7 - Information-Security Risk Assessment and Treatment
Outcome: Design a repeatable information-security risk assessment and treatment method with clear criteria, ownership and approval.
Case: Project Pramaan uses inconsistent scoring: one team rates likelihood 1–3, another uses colours, and suppliers are assessed without defined acceptance criteria.
Tools: Risk methodology, Risk register, Risk treatment plan
7 - Statement of Applicability and Annex A Controls
Outcome: Build a risk-linked Statement of Applicability and select controls from the four ISO/IEC 27002 themes without treating Annex A as a checklist.
Case: Project Pramaan copied a generic Statement of Applicability listing every control as applicable, but many rows have no risk link, implementation status or rationale.
Tools: SoA design, Control selection record, Control-theme map
7 - Support, Competence, Communication, and Documents
Outcome: Plan resources, competence, awareness, communication and controlled documented information for an effective ISMS.
Case: Project Pramaan has training attendance records but no competence criteria, and policies are stored in several uncontrolled repositories.
Tools: Resource plan, Competence matrix, Document-control register
7 - Operational Planning and Control
Outcome: Operate risk treatment, controls and planned processes while managing changes, suppliers and retained evidence.
Case: Project Pramaan approves risk plans but operational teams change cloud configurations, suppliers and release processes without updating risks or evidence.
Tools: Operational control plan, Change-risk record, Supplier evidence pack
7 - Monitoring, Measurement, Analysis, and Evaluation
Outcome: Design useful monitoring, measurement, analysis and evaluation that demonstrates performance and effectiveness.
Case: Project Pramaan reports activity counts—patches installed and emails sent—but cannot explain whether risk, objectives or controls are improving.
Tools: Measurement plan, Metric definition sheet, Performance dashboard
7 - Internal Audit, Management Review, and Improvement
Outcome: Plan an impartial internal audit programme, management review, nonconformity handling, corrective action and continual improvement.
Case: Project Pramaan's internal audits repeat the same checklist, auditors review their own work, and corrective actions close without root-cause evidence.
Tools: Audit programme, Finding and CAPA log, Management-review pack
7- 10.1Plan the audit programme
- 10.2Protect objectivity and impartiality
- 10.3Collect and evaluate audit evidence
- 10.4Write findings and corrective actions
- 10.5Conduct management review
- 10.6Drive continual improvement
- 10.7Module 10 Assessment — Internal Audit, Management Review, and Improvement5 Minutes5 Questions
- Certification Readiness and Audit Practice
Outcome: Prepare responsibly for accredited certification and distinguish Stage 1, Stage 2, surveillance, recertification and certification-body roles.
Case: Project Pramaan must select a credible certification body and prepare for Stage 1 and Stage 2 without coaching employees to hide weaknesses.
Tools: Certification roadmap, Certification-body due diligence, Readiness evidence index
7 - Capstone: Project Pramaan
Outcome: Create and defend a foundation ISMS pack for the fictional Project Pramaan organization.
Case: Project Pramaan must establish a foundation ISMS for its managed cloud platform, remote engineering teams, Indian personal data, international customers, critical suppliers and climate-related availability risks.
Tools: Foundation ISMS pack, Executive review, Oral defence
7 - Final ExaminationFinal assessment for ISO/IEC 27001 Foundation. Passing score: 70%.1
