ISO/IEC 27001 — GRC & Compliance
This roadmap prepares you for ISO/IEC 27001:2022 certification exams (Foundation level, with Implementer and Auditor tiers planned). You'll learn why organizations formalize security governance, how risk assessment and treatment work, what the 93 Annex A controls actually require, and how the certification audit process itself functions. This is exam preparation — the official certification is issued only by an accredited body (PECB, BSI, IBITGQ), never by VigilForge.
📋 Lessons (14 total)
Understand why organizations formalize security through an Information Security Management System, and the core vocabulary — assets, threats, vulnerabilities, and risk — that ISO/IEC 27001 is built on.
Understand how ISO/IEC 27001 fits into a wider family of related standards, and how the standard itself is organized — mandatory management clauses versus the Annex A control reference.
Learn what clauses 4 and 5 actually require: defining the ISMS scope, identifying interested parties, and the specific, auditable things top management must demonstrably do.
Learn the concrete steps of ISO/IEC 27001's risk assessment and treatment process — from setting criteria through to the four treatment options and information security objectives.
Learn what clause 7 requires for resources, competence, awareness, communication, and documented information — and how clause 8 turns risk treatment plans into day-to-day operational reality.
Learn what clause 9 requires for monitoring, internal audit, and management review, and how clause 10 turns findings into corrective action that closes the PDCA loop back to clause 6.
Survey the 37 Organizational controls by cluster — policies, asset management, access control, supplier relationships, incident management, and compliance — rather than memorizing each in isolation.
Cover all 8 People controls, from pre-hire screening through post-termination responsibilities, and learn when it's legitimate to mark a control 'not applicable' in a small organization's SoA.
Cover all 14 Physical controls, and learn how the shared responsibility model with cloud providers changes — but doesn't eliminate — an organization's physical control obligations.
Survey the largest Annex A theme — 34 controls covering access, operations, data protection, networks, and secure development — grouped into 7 practical clusters.
Learn how to actually build a Statement of Applicability that an auditor would accept — the single document where risk assessment, Annex A, and evidence all have to agree with each other.
Learn the real mechanics of getting certified — the Stage 1/Stage 2 audit split, how findings are classified, the surveillance and recertification cycle, and who accredits the certification bodies themselves.
Walk through a realistic gap analysis on a fictional cybersecurity training platform, applying everything from clauses 4-10, all 93 Annex A controls, and the SoA in a single connected narrative.
A comprehensive review and 20-question practice exam covering everything from lessons 1-13 — ISMS fundamentals, all clauses, all 93 Annex A controls, the SoA, and the certification process.
Exam Prep, Not the Exam
This roadmap prepares you for ISO/IEC 27001 certification exams. Completing it earns a VigilForge internal attestation of training completion — not the official certification, which is issued only by an accredited body (PECB, BSI, IBITGQ).
What You'll Learn
- ✓ Why organizations formalize security through an ISMS
- ✓ Assets, threats, vulnerabilities, and risk — precisely defined
- ✓ The 93 Annex A controls across all 4 themes
- ✓ How to build a Statement of Applicability (SoA)
- ✓ How the certification audit process actually works