← All courses
$20

ISO 27001

Go deep on ISO 27001 — the international certification European and cross-border buyers ask for. Understand the ISMS at its core, scope it, run the risk assessment and Statement of Applicability, apply the Annex A controls, build the evidence and internal-audit discipline, and navigate certification. The information-security-management deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal advice.

"Our ISMS is scoped, our SoA ties every control to a risk, and we're ready for the Stage 1 and Stage 2 certification audit"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    What ISO 27001 actually is — the certification, not a checklist

    ISO 27001 is an international standard you get certified against — and its core isn't a list of controls, it's a management system: a repeatable, risk-based way of running security that you continually improve.

  2. 2

    Scope & the ISMS — draw the boundary buyers will actually trust

    The ISMS scope is the boundary of what your security management system covers — chosen wide enough that the certificate means something, tight enough that certification is achievable.

  3. 3

    Risk assessment & the Statement of Applicability

    ISO 27001 is risk-based: you assess the risks to your information, decide how to treat each one, and the controls you apply — recorded in the Statement of Applicability — follow from that reasoning, not from a template.

  4. 4

    The controls (Annex A) — four themes, mostly the shared core

    ISO 27001's Annex A isn't hundreds of bespoke technical controls — it's a set organized into four themes (Organizational, People, Physical, Technological), most of which are the same foundational controls every framework asks for; you apply the ones your SoA and risk assessment justify.

  5. 5

    Evidence, internal audit & management review — proving the ISMS runs

    A certificate isn't earned by having controls — it's earned by proving they operate: documented evidence, an internal audit you run on yourself, a leadership review, and a loop that keeps improving.

  6. 6

    Certification & staying certified — the audit and the living ISMS

    Certification isn't a finish line: an accredited body audits your ISMS in two stages, issues a certificate valid for roughly three years, and checks in with surveillance audits along the way — so you keep the ISMS running, or you lose it.

Production patterns you'll master

ISMSScope DefinitionRisk AssessmentStatement of ApplicabilityAnnex A ControlsCertification & Surveillance

Synthetic data included

  • ISO 27001 vs SOC 2 compare
  • Annex A four themes
  • Statement of Applicability example
  • The certification cycle

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your iso 27001?

First course free. $20 per course after that.