Design Your Own ISMS From Scratch
“From Blank Page to Audit-Ready. In 90 Days.”
A 90-day project-based internship where you build a complete Information Security Management System for a fictional organization. Draft policies, conduct risk assessments, develop a Statement of Applicability, and produce audit-ready documentation aligned with ISO 27001:2022.
Program Highlights
What You’ll Learn
Define ISMS scope and context of the organization per ISO 27001 Clauses 4-10
Conduct a comprehensive information security risk assessment using ISO 27005 methodology
Develop a risk treatment plan and Statement of Applicability (SoA)
Write information security policies covering all Annex A control themes
Create an internal audit program and audit checklists
Build cloud security controls documentation aligned with ISO 27017/27018
Design a privacy information management extension using ISO 27701
Prepare a management review presentation for executive leadership
Tools & Technologies
What You’ll Deliver
Complete ISMS documentation package (15+ documents)
Risk assessment report with treatment plan
Statement of Applicability (SoA) covering all 93 Annex A controls
Information security policy set (8+ policies)
Internal audit checklist and program schedule
Final Capstone: Full ISMS implementation report ready for certification audit
Who Should Apply
- Final-year students in IT, Computer Science, or Management
- Freshers aspiring to become ISO 27001 implementers or auditors
- IT professionals transitioning into information security management
- Anyone preparing for ISO 27001 Lead Implementer certification
Prerequisites
- Basic understanding of information security concepts
- Ability to read and interpret standards documentation
- Strong documentation and writing skills
- A laptop with internet access and document editing tools
Program Format
Related Training Courses
Complement your internship with these in-depth training programs.
ISMS Foundations (ISO 27001)
Comprehensive training on ISO 27001 Information Security Management System fundamentals, clauses, Annex A controls, and the PDCA cycle.
Enroll NowInformation Security Risk Management
Master risk assessment methodologies aligned with ISO 31000 and ISO 27005, including risk identification, analysis, evaluation, and treatment.
Enroll NowCloud Security Management
Learn to manage cloud security using ISO 27017 and ISO 27018 frameworks, covering shared responsibility, cloud controls, and cloud privacy.
Enroll NowPrivacy Information Management (ISO 27701)
Learn to extend your ISMS with privacy controls for PII controllers and processors, aligned with GDPR and global privacy regulations.
Enroll NowReady to Start Your Internship?
Apply now for the Design Your Own ISMS From Scratch internship program. Build real-world skills, work with a mentor, and launch your career in information security management.