By the end
What you'll build
- Define an information security management system scope and defend the boundary you drew
- Run a risk assessment that produces prioritised, traceable risk treatment decisions
- Draft a statement of applicability in which each control is justified against a specific risk
- Design an evidence trail that survives an internal or external audit
- Plan and run an internal audit cycle and a management review with real inputs
- Diagnose a control that is documented but not operating, and correct it
Curriculum
What's inside
8 modules · 51 lessons
- 01
Scope, context and mandate
6 lessons- Drawing a defensible ISMS scope and writing the boundary statement
- Context of the organisation and interested parties
- Getting a real mandate from leadership, not a signature
- Interfaces and dependencies: cloud, suppliers, group companies
- Common scoping mistakes and what they cost at audit
- + 1 more lesson
- 02
Risk assessment and treatment
7 lessons- Running a risk assessment that produces decisions, not a spreadsheet
- Choosing a risk methodology and documenting the criteria
- Asset, threat and vulnerability identification that stays finite
- Risk owners, appetite and acceptance
- Building and maintaining the risk treatment plan
- + 2 more lessons
- 03
Controls and the statement of applicability
7 lessons- Writing a statement of applicability with justifications that hold up
- Reading the control set as design guidance, not a checklist
- Organisational, people, physical and technological control themes
- Justifying an exclusion safely
- Mapping controls to existing practices you already run
- + 2 more lessons
- 04
Policies, roles and documented information
6 lessons- A policy set people actually follow: structure, ownership and review
- Topic-specific policies versus one giant document
- Assigning control ownership that survives reorganisation
- Version control, approval and communication
- Awareness and competence records
- + 1 more lesson
- 05
Operating the system
7 lessons- Turning controls into a repeatable operating rhythm
- Access reviews, change control and secure development touchpoints
- Supplier and third-party security in practice
- Incident management and lessons learned
- Business continuity interfaces with the ISMS
- + 2 more lessons
- 06
Monitoring, audit and review
7 lessons- Planning and running an internal audit programme
- Audit evidence: what counts and what does not
- Writing findings that lead to real correction
- Corrective action and effectiveness checks
- Management review inputs and outputs
- + 2 more lessons
- 07
Continual improvement
6 lessons- Diagnosing a control that exists on paper but not in practice
- Nonconformity handling and root cause discipline
- Improving without endless documentation churn
- Maintaining the system through growth and change
- Sustaining the system after the first audit
- + 1 more lesson
- 08
Practice and check
5 lessons- Which document answers which questionmatch pairs
- Building the system in the order that holds upsequence order
- Implementer terms that get mixed upfill blank
- Six weeks to the certification auditscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
51 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
