Roadmaps / ISO/IEC 27001 — Lead Implementer
🏗️
intermediate Roadmap #14

ISO/IEC 27001 — Lead Implementer

This roadmap prepares you for ISO/IEC 27001:2022 Lead Implementer certification exams. Where Foundation taught what the standard requires, this roadmap is about actually building it — a real project plan, a policy framework, a risk register, implemented controls, an internal audit program, and a functioning management review cycle. Exam preparation only — official certification is issued exclusively by an accredited body (PECB, BSI, IBITGQ), never by VigilForge.

📚 13 lessons ⏱ ~40h 📊 intermediate

Create a free account to track your progress and unlock all features.

Get Started Free Sign In
ISMS Project Management Policy Framework Risk Register Control Implementation Incident Management Business Continuity Internal Audit Program

📋 Lessons (13 total)

1
Launching the ISMS Implementation Project Medium

Learn why an ISMS implementation must be run as a real project with executive sponsorship and a RACI matrix — not a side task handed to IT — and map out a realistic implementation timeline.

⏱ 55m
2
Building the Policy Framework Medium prereq required

Learn the three-tier policy hierarchy, what makes a policy actually implementable rather than aspirational, and how to avoid the classic mistake of copy-pasting a template no one follows.

⏱ 60m
3
Risk Management Methodology in Depth Hard prereq required

Go beyond Foundation's simple risk matrix — build a real, living risk register, understand risk appetite vs. tolerance, and learn when quantitative risk analysis is worth the extra effort.

⏱ 65m
4
Implementing Asset Management & Access Control Medium prereq required

Build a real asset inventory and classification scheme, and design a working identity lifecycle (joiner-mover-leaver) with role-based access and a real access review cadence.

⏱ 60m
5
Implementing Cryptography & Physical Security Medium prereq required

Build a real key management lifecycle and cryptography standard, and implement physical security appropriately whether your organization has an office, is fully remote, or somewhere in between.

⏱ 55m
6
Implementing Operational & Network Security Hard prereq required

Build a real change management process, an actually-monitored logging pipeline, a segmented network design, and a backup strategy that includes tested restores — not just scheduled dumps.

⏱ 65m
7
Implementing a Secure Development Lifecycle Medium prereq required

Integrate security into every SDLC phase rather than bolting it on at the end, choose testing types appropriately across the pipeline, manage third-party dependencies, and stay accountable for outsourced code.

⏱ 60m
8
Implementing a Supplier Risk Management Program Medium prereq required

Build a tiered supplier risk program — due diligence proportional to risk, contractual security clauses that mean something, ongoing monitoring, and a secure offboarding process.

⏱ 55m
9
Implementing Incident Management Medium prereq required

Build a real incident response plan with named roles, scenario-specific playbooks, and a tabletop exercise program — because an untested incident plan is exactly as risky as an untested backup.

⏱ 60m
10
Implementing Business Continuity & Disaster Recovery Medium prereq required

Run a real Business Impact Analysis to set RTO/RPO targets, build BCP and DRP as distinct but connected plans, and choose the right level of test rigor for each.

⏱ 60m
11
Building the Internal Audit Program Medium prereq required

Design an internal audit program that achieves real independence even in a small organization, follow a repeatable audit methodology, write findings as objective evidence rather than impressions, and track them to closure.

⏱ 60m
12
Management Review & Continual Improvement in Practice Medium prereq required

Run a management review that produces real decisions instead of a rubber stamp, build an ISMS metrics dashboard, and funnel findings from every source into one continual improvement register.

⏱ 60m
13
Implementer Practice Exam Hard prereq required

A comprehensive review and 20-question practice exam covering everything from lessons 1-12 — launching the ISMS project, the policy framework, risk methodology, all major control implementations, supplier risk, incident management, BCDR, internal audit, and management review.

⏱ 90m
🏗️

From Theory to Implementation

Foundation taught you what the standard requires. This roadmap is about actually building the thing — policies, registers, playbooks, and programs an auditor could review.

Prerequisite

The Foundation roadmap's concepts (risk vocabulary, clauses 4-10, Annex A, the SoA) are assumed throughout — complete it first if you haven't.

Go to Foundation roadmap →

Recommended Before

Complete earlier roadmaps in the sequence for best results.

View all roadmaps →

What You'll Learn

  • Launch and structure a real ISMS implementation project
  • Write an actual policy framework, not just describe one
  • Build a working risk register and treatment plan
  • Implement Annex A controls across all 4 themes in practice
  • Design an internal audit program and continual improvement cycle