Practitioner Track · Outline + Hands-on Labs

ISO 27001:2022 — ISMS Practitioner Track

From Scope Statement to certification-ready ISMS

A structured outline of the Information Security Management System discipline, aligned to ISO/IEC 27001:2022. Every chapter here has a matching hands-on lab in the 22-Day GRC Simulation — this outline is your map; the simulation is your workshop.

5 chapters· ~12 hours reading· 5 matching hands-on labs

Course outline

Chapter 1

ISMS Fundamentals + the ISO 27000 Family

What an ISMS is, why organisations pursue certification, how the ISO 27000 family fits together (27001 mandatory, 27002 guidance, 27005 risk, 27017 cloud, 27701 privacy), and the Plan-Do-Check-Act cycle.

Key concepts

  • Confidentiality, Integrity, Availability (CIA triad)
  • ISO 27001 (requirements) vs ISO 27002 (implementation guidance)
  • Statement of Applicability (SoA) is the load-bearing document
  • PDCA lifecycle
  • Certification body vs accreditation body distinction

Chapter 2

Clauses 4-10 — The mandatory requirements

The ten clauses of ISO 27001:2022, focusing on what a certification auditor tests: context (4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9), improvement (10).

Key concepts

  • Clause 4.3 — Determining the scope of the ISMS
  • Clause 5.2 — Information Security Policy
  • Clause 6.1.2 — Information Security Risk Assessment
  • Clause 6.1.3 — Information Security Risk Treatment + SoA
  • Clause 9.2 — Internal audit
  • Clause 9.3 — Management review
  • Clause 10.1 — Continual improvement

Chapter 3

All 93 Annex A Controls Across the 4 Themes

ISO 27001:2022 restructured Annex A into 4 themes: Organisational (37), People (8), Physical (14), Technological (34). We cover the control catalogue, the 5 attributes (control type, information security properties, cybersecurity concepts, operational capabilities, security domains), and how to select applicable controls.

Key concepts

  • Theme 1: Organisational (A.5.x) — policies, roles, threat intelligence, cloud services
  • Theme 2: People (A.6.x) — screening, terms of employment, training, disciplinary
  • Theme 3: Physical (A.7.x) — perimeters, entry controls, workspace, storage media
  • Theme 4: Technological (A.8.x) — access control, cryptography, backup, logging, secure dev
  • SoA justification for each 'Not Applicable' control

Chapter 4

Risk Assessment + Treatment Methodology

How to run a defensible risk assessment: identify assets, threats, vulnerabilities, existing controls, then compute inherent + residual risk. Treatment options (mitigate, transfer, accept, avoid) and the risk treatment plan.

Key concepts

  • Asset-centric vs threat-centric approaches
  • Likelihood + Impact rating scales (qualitative + quantitative)
  • Risk register content requirements
  • Risk treatment plan alignment with SoA
  • Residual risk acceptance by risk owners

Chapter 5

Internal Audit + Management Review

Preparing for the internal audit programme (Clause 9.2) and running effective management reviews (Clause 9.3). Sample sizes, evidence collection, deficiency categorisation, and stage 1 + stage 2 certification audits.

Key concepts

  • Audit programme vs audit plan
  • Sample size: statistical vs risk-based
  • Deficiency severity: major NC, minor NC, opportunity for improvement
  • Stage 1 audit (readiness) vs Stage 2 audit (certification)
  • 3-year certification cycle + annual surveillance

Ready for the workshop?

The 22-Day GRC Practical Simulation is where you actually produce the deliverables — scope statements, SoAs, control tests, evidence packs. Full access is included with the 22-Day Program enrolment or Cohort 2026 candidature.