Karka

Free course

ISO/IEC 27001 — Information Security (Implementer)

Implementer-level training on building and running an information security management system, from scoping and risk treatment to audit readiness.

What this course does not do

This is internal recognition from this platform only. Completing it does not make you a certified lead implementer or auditor, and it does not make your organisation ISO 27001 certified — organisational certification is issued solely by an accredited certification body after a successful audit. Any externally recognised personal credential must be obtained from the relevant awarding body.

Internal recognition onlyCoreISO Compliance
8 modules 51 lessons 3 enrolled ~30h of material

First three lessons free. Full access with Founding Annual Access, ₹3,999 for your first year.

ISO/IEC 27001 — Information Security (Implementer)

By the end

What you'll build

  • Define an information security management system scope and defend the boundary you drew
  • Run a risk assessment that produces prioritised, traceable risk treatment decisions
  • Draft a statement of applicability in which each control is justified against a specific risk
  • Design an evidence trail that survives an internal or external audit
  • Plan and run an internal audit cycle and a management review with real inputs
  • Diagnose a control that is documented but not operating, and correct it

Curriculum

What's inside

8 modules · 51 lessons

  1. 01

    Scope, context and mandate

    6 lessons
    • Drawing a defensible ISMS scope and writing the boundary statement
    • Context of the organisation and interested parties
    • Getting a real mandate from leadership, not a signature
    • Interfaces and dependencies: cloud, suppliers, group companies
    • Common scoping mistakes and what they cost at audit
    • + 1 more lesson
  2. 02

    Risk assessment and treatment

    7 lessons
    • Running a risk assessment that produces decisions, not a spreadsheet
    • Choosing a risk methodology and documenting the criteria
    • Asset, threat and vulnerability identification that stays finite
    • Risk owners, appetite and acceptance
    • Building and maintaining the risk treatment plan
    • + 2 more lessons
  3. 03

    Controls and the statement of applicability

    7 lessons
    • Writing a statement of applicability with justifications that hold up
    • Reading the control set as design guidance, not a checklist
    • Organisational, people, physical and technological control themes
    • Justifying an exclusion safely
    • Mapping controls to existing practices you already run
    • + 2 more lessons
  4. 04

    Policies, roles and documented information

    6 lessons
    • A policy set people actually follow: structure, ownership and review
    • Topic-specific policies versus one giant document
    • Assigning control ownership that survives reorganisation
    • Version control, approval and communication
    • Awareness and competence records
    • + 1 more lesson
  5. 05

    Operating the system

    7 lessons
    • Turning controls into a repeatable operating rhythm
    • Access reviews, change control and secure development touchpoints
    • Supplier and third-party security in practice
    • Incident management and lessons learned
    • Business continuity interfaces with the ISMS
    • + 2 more lessons
  6. 06

    Monitoring, audit and review

    7 lessons
    • Planning and running an internal audit programme
    • Audit evidence: what counts and what does not
    • Writing findings that lead to real correction
    • Corrective action and effectiveness checks
    • Management review inputs and outputs
    • + 2 more lessons
  7. 07

    Continual improvement

    6 lessons
    • Diagnosing a control that exists on paper but not in practice
    • Nonconformity handling and root cause discipline
    • Improving without endless documentation churn
    • Maintaining the system through growth and change
    • Sustaining the system after the first audit
    • + 1 more lesson
  8. 08

    Practice and check

    5 lessons
    • Which document answers which questionmatch pairs
    • Building the system in the order that holds upsequence order
    • Implementer terms that get mixed upfill blank
    • Six weeks to the certification auditscenario
    • Course quizquiz

The shape of it

How this course works

Short lessons

51 lessons across 8 modules, each small enough to finish in one sitting.

Practice as you go

Every lesson ends with a small space for what you noticed — the doing is the learning.

Progress you can see

Your progress is saved lesson by lesson, ready whenever you come back.

Ready when you are.

Make an account and this course opens up — your progress is saved from the very first lesson.