ISO/IEC 27001 — Lead Implementer
This roadmap prepares you for ISO/IEC 27001:2022 Lead Implementer certification exams. Where Foundation taught what the standard requires, this roadmap is about actually building it — a real project plan, a policy framework, a risk register, implemented controls, an internal audit program, and a functioning management review cycle. Exam preparation only — official certification is issued exclusively by an accredited body (PECB, BSI, IBITGQ), never by VigilForge.
📋 Lessons (13 total)
Learn why an ISMS implementation must be run as a real project with executive sponsorship and a RACI matrix — not a side task handed to IT — and map out a realistic implementation timeline.
Learn the three-tier policy hierarchy, what makes a policy actually implementable rather than aspirational, and how to avoid the classic mistake of copy-pasting a template no one follows.
Go beyond Foundation's simple risk matrix — build a real, living risk register, understand risk appetite vs. tolerance, and learn when quantitative risk analysis is worth the extra effort.
Build a real asset inventory and classification scheme, and design a working identity lifecycle (joiner-mover-leaver) with role-based access and a real access review cadence.
Build a real key management lifecycle and cryptography standard, and implement physical security appropriately whether your organization has an office, is fully remote, or somewhere in between.
Build a real change management process, an actually-monitored logging pipeline, a segmented network design, and a backup strategy that includes tested restores — not just scheduled dumps.
Integrate security into every SDLC phase rather than bolting it on at the end, choose testing types appropriately across the pipeline, manage third-party dependencies, and stay accountable for outsourced code.
Build a tiered supplier risk program — due diligence proportional to risk, contractual security clauses that mean something, ongoing monitoring, and a secure offboarding process.
Build a real incident response plan with named roles, scenario-specific playbooks, and a tabletop exercise program — because an untested incident plan is exactly as risky as an untested backup.
Run a real Business Impact Analysis to set RTO/RPO targets, build BCP and DRP as distinct but connected plans, and choose the right level of test rigor for each.
Design an internal audit program that achieves real independence even in a small organization, follow a repeatable audit methodology, write findings as objective evidence rather than impressions, and track them to closure.
Run a management review that produces real decisions instead of a rubber stamp, build an ISMS metrics dashboard, and funnel findings from every source into one continual improvement register.
A comprehensive review and 20-question practice exam covering everything from lessons 1-12 — launching the ISMS project, the policy framework, risk methodology, all major control implementations, supplier risk, incident management, BCDR, internal audit, and management review.
From Theory to Implementation
Foundation taught you what the standard requires. This roadmap is about actually building the thing — policies, registers, playbooks, and programs an auditor could review.
Prerequisite
The Foundation roadmap's concepts (risk vocabulary, clauses 4-10, Annex A, the SoA) are assumed throughout — complete it first if you haven't.
Go to Foundation roadmap →What You'll Learn
- ✓ Launch and structure a real ISMS implementation project
- ✓ Write an actual policy framework, not just describe one
- ✓ Build a working risk register and treatment plan
- ✓ Implement Annex A controls across all 4 themes in practice
- ✓ Design an internal audit program and continual improvement cycle