Roadmaps / ISO/IEC 27001 — GRC & Compliance
⚖️
beginner Roadmap #13

ISO/IEC 27001 — GRC & Compliance

This roadmap prepares you for ISO/IEC 27001:2022 certification exams (Foundation level, with Implementer and Auditor tiers planned). You'll learn why organizations formalize security governance, how risk assessment and treatment work, what the 93 Annex A controls actually require, and how the certification audit process itself functions. This is exam preparation — the official certification is issued only by an accredited body (PECB, BSI, IBITGQ), never by VigilForge.

📚 14 lessons ⏱ ~20h 📊 beginner

Create a free account to track your progress and unlock all features.

Get Started Free Sign In
ISMS Risk Management Annex A Controls Statement of Applicability PDCA Cycle Audit & Certification GRC

📋 Lessons (14 total)

1
Why an ISMS? Introduction to Security Governance Easy

Understand why organizations formalize security through an Information Security Management System, and the core vocabulary — assets, threats, vulnerabilities, and risk — that ISO/IEC 27001 is built on.

⏱ 40m
2
The ISO/IEC 27000 Family & the Structure of ISO/IEC 27001 Easy

Understand how ISO/IEC 27001 fits into a wider family of related standards, and how the standard itself is organized — mandatory management clauses versus the Annex A control reference.

⏱ 40m
3
Context of the Organization & Leadership (Clauses 4-5) Medium prereq required

Learn what clauses 4 and 5 actually require: defining the ISMS scope, identifying interested parties, and the specific, auditable things top management must demonstrably do.

⏱ 50m
4
Planning: Risk Assessment & Treatment (Clause 6) Medium prereq required

Learn the concrete steps of ISO/IEC 27001's risk assessment and treatment process — from setting criteria through to the four treatment options and information security objectives.

⏱ 60m
5
Support & Operation of the ISMS (Clauses 7-8) Medium prereq required

Learn what clause 7 requires for resources, competence, awareness, communication, and documented information — and how clause 8 turns risk treatment plans into day-to-day operational reality.

⏱ 55m
6
Performance Evaluation & Improvement (Clauses 9-10) Medium prereq required

Learn what clause 9 requires for monitoring, internal audit, and management review, and how clause 10 turns findings into corrective action that closes the PDCA loop back to clause 6.

⏱ 50m
7
Annex A — Organizational Controls (5.1-5.37) Medium prereq required

Survey the 37 Organizational controls by cluster — policies, asset management, access control, supplier relationships, incident management, and compliance — rather than memorizing each in isolation.

⏱ 70m
8
Annex A — People Controls (6.1-6.8) Easy prereq required

Cover all 8 People controls, from pre-hire screening through post-termination responsibilities, and learn when it's legitimate to mark a control 'not applicable' in a small organization's SoA.

⏱ 40m
9
Annex A — Physical Controls (7.1-7.14) Easy prereq required

Cover all 14 Physical controls, and learn how the shared responsibility model with cloud providers changes — but doesn't eliminate — an organization's physical control obligations.

⏱ 45m
10
Annex A — Technological Controls (8.1-8.34) Medium prereq required

Survey the largest Annex A theme — 34 controls covering access, operations, data protection, networks, and secure development — grouped into 7 practical clusters.

⏱ 70m
11
The Statement of Applicability & Risk Treatment Plan Medium prereq required

Learn how to actually build a Statement of Applicability that an auditor would accept — the single document where risk assessment, Annex A, and evidence all have to agree with each other.

⏱ 55m
12
The Certification Process: Stage 1, Stage 2 & Beyond Easy prereq required

Learn the real mechanics of getting certified — the Stage 1/Stage 2 audit split, how findings are classified, the surveillance and recertification cycle, and who accredits the certification bodies themselves.

⏱ 45m
13
Case Study: Conducting a Gap Analysis Hard prereq required

Walk through a realistic gap analysis on a fictional cybersecurity training platform, applying everything from clauses 4-10, all 93 Annex A controls, and the SoA in a single connected narrative.

⏱ 75m
14
Foundation Practice Exam Hard prereq required

A comprehensive review and 20-question practice exam covering everything from lessons 1-13 — ISMS fundamentals, all clauses, all 93 Annex A controls, the SoA, and the certification process.

⏱ 90m
⚖️

Exam Prep, Not the Exam

This roadmap prepares you for ISO/IEC 27001 certification exams. Completing it earns a VigilForge internal attestation of training completion — not the official certification, which is issued only by an accredited body (PECB, BSI, IBITGQ).

Recommended Before

Complete earlier roadmaps in the sequence for best results.

View all roadmaps →

What You'll Learn

  • Why organizations formalize security through an ISMS
  • Assets, threats, vulnerabilities, and risk — precisely defined
  • The 93 Annex A controls across all 4 themes
  • How to build a Statement of Applicability (SoA)
  • How the certification audit process actually works