Global searching is not enabled.
Skip to main content

This course includes:

  • 365 days of study
  • 9 Quize(s).
  • 35 Assignment(s).
  • Access on mobile and Desktop
  • Certificate of completion

Learn ISO/IEC 27001:2022 by doing it. In this hands-on Project Platform you are hired as the ISO 27001 Lead Implementer for Meridian Specialist Hospital — a realistic healthcare organization — and build its Information Security Management System (ISMS) from kickoff to certification readiness.

Across 9 milestones you will: frame the ISMS context and scope (Clause 4); establish leadership, policy and governance (Clause 5); run a risk assessment, risk treatment plan and Statement of Applicability over the 93 Annex A controls, and set objectives (Clause 6); resource the ISMS (Clause 7); operate it and implement controls with evidence (Clause 8); evaluate it through monitoring, internal audit and management review (Clause 9); improve it through corrective action and continual improvement (Clause 10); and finally assemble the mandatory documentation and judge Stage 1 / Stage 2 certification readiness with a go / no-go recommendation to the Board.

What you get: a real business simulation with realistic data, professional fillable templates (Excel & Word) for every deliverable, and a portfolio of genuine ISMS artefacts you can show an employer.

Outcome: by the final milestone you will have taken an organization from zero to certification-ready — the full A-to-Z experience of implementing ISO/IEC 27001:2022 in a real environment.

Top companies offer this course to their employees

This course was selected for our collection of top-rated courses trusted by businesses worldwide.

Certified Partners

scrum scaledagile icagile scrumalliance kanban

Course content

9 section(s)

  • Welcome to the ISO/IEC 27001:2022 Implementation Project Platform. This is not a lecture course. It is a hands-on, end-to-end business simulation in which you take on the role of an ISO/IEC 27001:2022 Lead Implementer hired by a hospital to build its Information Security Management System (ISMS) and take it all the way to certification.

    1. Introduction

    Meridian Specialist Hospital (MSH), a 250-bed private hospital in Dubai, has just had a security scare and its board has approved an ISO/IEC 27001:2022 project. They have hired you. Over the coming milestones you will walk into this organization exactly as a real Lead Implementer would: you will study the business, meet the stakeholders, discover the systems and data, assess the risks, write the policies, implement the controls, audit the results, and stand in front of a certification body.

    Each section gives you real working materials — the hospital's profile and org chart, asset inventories, network information, interview notes, and the document templates and checklists you need to produce genuine ISMS deliverables. By the final milestone you will have completed a full A-to-Z implementation using realistic data, and you will hold a portfolio of the actual documents an ISMS requires.

    2. Scope of this Project Platform

    This platform covers the complete lifecycle of an ISO/IEC 27001:2022 ISMS implementation, structured around the standard's management-system clauses (4–10) and its Annex A control set:

    • Understanding organizational context and defining the ISMS scope (Clause 4).
    • Leadership, information-security policy and governance (Clause 5).
    • Risk assessment & risk treatment and the Statement of Applicability (Clause 6).
    • Support — resources, competence, awareness, communication and documented information (Clause 7).
    • Operation — implementing the Annex A controls across the Organizational, People, Physical and Technological themes (Clause 8).
    • Performance evaluation — monitoring, measurement, internal audit and management review (Clause 9).
    • Improvement — nonconformity and corrective action (Clause 10).
    • Certification — Stage 1 and Stage 2 audit readiness and the certification decision.

    What this platform is not: it is not a substitute for the ISO/IEC 27001:2022 standard text itself, and it does not cover unrelated frameworks except where they help (e.g., ISO/IEC 27002:2022 implementation guidance and the relevant UAE regulations).

    3. Objectives

    By enrolling in and completing this project platform, you will be able to:

    • Interpret every requirement of ISO/IEC 27001:2022 and explain what evidence an auditor expects for each clause.
    • Define an ISMS scope and document the context of a real organization.
    • Perform an information-security risk assessment and build a defensible risk-treatment plan and Statement of Applicability.
    • Draft the full ISMS documentation set — policies, procedures, registers and records — from professional templates.
    • Implement, operate and provide evidence for the Annex A controls in a live environment.
    • Plan and conduct an internal audit and a management review, and manage corrective actions.
    • Prepare an organization for, and take it through, a Stage 1 and Stage 2 certification audit.

    4. Who this is for & how you will work

    This platform is designed for aspiring GRC and information-security professionals, IT and quality staff, and anyone preparing for the ISO/IEC 27001 Lead Implementer certification. In each section you will: (1) receive the scenario and the client materials, (2) study the relevant clause(s) of the standard, (3) produce the required deliverable using the supplied templates, and (4) submit it for assessment. Deliverables build on one another — the output of one milestone becomes the input of the next — so the ISMS grows exactly as it would in a real project.

    5. Your journey — milestone roadmap

    Section Milestone ISO 27001:2022 focus Key deliverable
    1 Project kickoff — the client, your role, scope & objectives Orientation Understand the mandate (this section)
    2 Context of the organization Clause 4 Context analysis & documented ISMS scope
    3 Leadership, policy & governance Clause 5 Information Security Policy & ISMS roles
    4 Risk assessment & treatment Clause 6 Risk methodology, asset register, RTP & Statement of Applicability
    5 Support & awareness Clause 7 Competence, awareness programme & document control
    6 Operation — implementing controls Clause 8 & Annex A Implemented controls with evidence
    7 Performance evaluation Clause 9 Internal audit & management review
    8 Improvement Clause 10 Nonconformity & corrective-action management
    9 Capstone — certification readiness Stage 1 & 2 audit Certification-readiness pack & audit simulation

    6. What's in this section

    Before you begin the work, get to know your client and your role. This section contains:

    • Client Organization Profile — everything you need to know about Meridian Specialist Hospital, including its regulatory context, IT environment and current security gaps.
    • Organization Chart — the hospital's structure and where your new Information Security Office sits.
    • Job Description — ISO/IEC 27001:2022 Lead Implementer — your official appointment and the deliverables expected of you.

    What you will produce in this section

    Section 1 has two deliverables. Together they turn your appointment letter into a working mandate and an honest starting point for the whole project.

    # Deliverable ISO 27001:2022 What it establishes
    1 ISMS Project Charter & Manual Outline Clause 5.1 & 5.3 (preview) Your objective, sponsor and mandate, and a skeleton of the future ISMS Manual
    2 ISO/IEC 27001:2022 Gap Analysis (Baseline) Clauses 4–10 An honest maturity baseline against every clause, before any control work begins

    Why this matters

    Every later milestone in this platform references the charter and the baseline you set here. A vague mandate or an overly generous baseline will make Sections 2–9 harder, not easier – exactly as it would on a real engagement. Take the time to get these two right before moving on.

    How to work

    Both assignments include instructions, the exact structure to follow, assessment criteria and a downloadable template. Base your baseline ratings on the Client Organization Profile and your own judgement, not wishful thinking – a realistic "where we actually stand" is far more useful than an optimistic one.

    Start here: read the three resources above in order, then proceed to Section 2 where you will begin the real work by analysing the context of the organization.

  • 1 Quizes.
  • 2 Assignments.
  • Now that you have been appointed as Meridian Specialist Hospital's ISO/IEC 27001:2022 Lead Implementer, your first task is to understand the organization before you build anything on top of it. Section 2 covers Clause 4 – Context of the Organization: the internal and external issues, the interested parties, and the scope that every later decision in this ISMS has to trace back to. An ISMS that isn't grounded in MSH's real context and obligations will not survive an audit – and, more importantly, it will not actually protect patient data.

    What you will do in this section

    Read the Business Context & Background Information Pack first – it is your primary source of evidence – then complete the four Clause 4 deliverables below, in order.

    # Deliverable ISO 27001:2022 What it establishes
    1 Internal & External Issues Register Clause 4.1 The internal and external issues relevant to the ISMS
    2 Interested Parties – Needs & Expectations Register Clause 4.2 Who has a stake in information security and what they require
    3 ISMS Scope Statement Clause 4.3 The boundaries of the ISMS, including cloud boundaries and justified exclusions
    4 SWOT Analysis Clause 4 (supporting) The hospital's information-security strengths, weaknesses, opportunities and threats

    Why this matters

    Clause 4 is the foundation the entire management system stands on. Your issues (4.1) and interested-party requirements (4.2) feed directly into the ISMS scope (4.3), the risk assessment in Clause 6, and the Statement of Applicability. Auditors trace every later decision back to this analysis – so build it thoroughly and back it with evidence. A thin Clause 4 undermines everything that follows it.

    How to work

    Each assignment gives you detailed instructions, the exact structure to follow, the assessment criteria, and a downloadable template. Base every entry on evidence from the Information Pack – and where the pack doesn't give you a fact, make a reasonable, clearly-stated assumption exactly as you would on a real engagement, and note it as such. Submit each deliverable for assessment before moving on to Section 3.

    Start here: open the Business Context & Background Information Pack, read it in full, then begin Assignment 1.

  • 1 Quizes.
  • 4 Assignments.
  • An ISMS lives or dies by leadership. Section 3 covers Clause 5 – Leadership: top management has to demonstrate real commitment, establish an information security policy, and assign clear roles, responsibilities and authorities. Here you convert the Board's mandate into the governance backbone of Meridian Specialist Hospital's ISMS.

    What you will do in this section

    Read the Leadership Context & Board Mandate brief, then produce the three Clause 5 deliverables below. They build directly on the context work you completed in Section 2.

    # Deliverable ISO 27001:2022 What it establishes
    1 Information Security Policy Clause 5.2 The top-level policy that sets direction and commitment
    2 ISMS Roles, Responsibilities & Authorities (RACI) Clause 5.3 Who is responsible and accountable for each ISMS activity
    3 ISMS Governance – Steering Committee Charter & Leadership Commitment Clause 5.1 Evidence of top-management leadership and the governance body

    Why this matters

    Auditors open Stage 1 by testing leadership: is there a signed, communicated policy? Can people describe their ISMS responsibilities? Is there evidence top management actually drives the system – a chartered steering committee, allocated resources, defined objectives? Weak leadership is the single most common reason ISMS implementations fail. Your Clause 5 outputs need to be concrete, signed off, and consistent with the context and interested-party requirements you documented in Section 2.

    How to work

    Each assignment gives you instructions, the required structure, the assessment criteria, and a downloadable template. Ground your policy commitments and roles in the actual MSH context: the regulatory obligations, the interested parties, and the organization chart from Section 1. Submit each deliverable before moving on to Section 4.

    Start here: open the Leadership Context & Board Mandate brief, then begin Assignment 1.

  • 1 Quizes.
  • 3 Assignments.
  • This is the heart of the ISMS. Section 4 covers Clause 6 – Planning: you define how information-security risks and opportunities are handled, assess the risks, decide how to treat them, select controls, and record your applicability decisions in the Statement of Applicability. Everything you built in Sections 2 and 3 – context, interested parties, scope, policy – feeds directly into this work.

    What you will do in this section

    Read the Risk Context & Asset Inventory brief, then produce the four Clause 6 deliverables below, in order – each one is an input to the next.

    # Deliverable ISO 27001:2022 What it establishes
    1 Risk Assessment Methodology Clause 6.1.2 How MSH identifies, analyses, evaluates and accepts risk
    2 Risk Assessment & Treatment Register Clause 6.1.2 & 6.1.3 The identified risks, their levels, treatment decisions and residual risk
    3 Statement of Applicability (SoA) Clause 6.1.3(d) The applicability decision and justification for all 93 Annex A controls
    4 Information Security Objectives & Plan Clause 6.2 Measurable objectives and how they will be achieved

    Why this matters

    The risk assessment and the SoA are the two documents an auditor scrutinises most closely, and both are mandatory documented information. A weak or generic risk assessment, or an SoA whose applicability decisions can't be justified against your risks, will stop certification in its tracks. Your methodology has to be repeatable, your risks have to be real and tied to the MSH context, and every one of the 93 Annex A controls needs a clear applicable/not-applicable decision with a stated reason.

    How to work

    Work the assignments in sequence: your methodology (1) sets the scales you use in the register (2); the controls you select to treat risks in (2) justify the "applicable" decisions in the SoA (3); and (4) turns the whole picture into measurable objectives. Ground everything in the asset inventory and threat scenarios provided, and in your Section 2 and 3 outputs. Each assignment includes instructions, structure, assessment criteria and a downloadable template.

    Start here: open the Risk Context & Asset Inventory brief, then begin Assignment 1.

  • 1 Quizes.
  • 5 Assignments.
  • An ISMS only works if the organization resources it, builds the right competencies, raises awareness, communicates effectively, and controls its documented information. Section 5 covers Clause 7 – Support, where the governance you built in Sections 3 and 4 becomes part of everyday hospital life.

    What you will do in this section

    Read the Support Context brief, then produce the four Clause 7 deliverables below.

    # Deliverable ISO 27001:2022 What it establishes
    1 Competence & Training Plan Clause 7.1 & 7.2 The resources and competencies the ISMS needs, and how gaps are closed
    2 Security Awareness Programme Clause 7.3 How all staff are made aware of the policy, their role and the risks
    3 ISMS Communication Plan Clause 7.4 What is communicated about the ISMS, to whom, when and how
    4 Control of Documented Information (procedure + master register) Clause 7.5 How ISMS documents and records are created, approved, versioned and controlled

    Why this matters

    Clause 7 failures are common audit findings: staff who can't describe the policy, no evidence of awareness training, uncontrolled documents with no version history, or no record of competence. Auditors will ask employees what they know and will inspect your document control directly. The recent phishing incident and the risks you identified in Section 4 make the awareness programme (7.3) especially important here.

    How to work

    Ground each deliverable in the MSH context: the org chart and RACI from Section 3, the risks and objectives from Section 4, and the Support Context brief. Each assignment includes instructions, structure, assessment criteria and a downloadable template. Submit each before moving on to Section 6.

    Start here: open the Support Context brief, then begin Assignment 1.

  • 1 Quizes.
  • 4 Assignments.
  • This is where the ISMS stops being paperwork and starts running. Section 6 covers Clause 8 – Operation: planning and controlling the processes needed to meet your requirements, implementing the risk-treatment plan, and keeping the risk assessment current. In practice, this is where the Annex A controls you selected in your Statement of Applicability get implemented and start generating evidence.

    What you will do in this section

    Read the Operations & Implementation Context brief, then produce the four Clause 8 deliverables below. These operationalise the risk treatment and SoA you built in Section 4.

    # Deliverable ISO 27001:2022 What it establishes
    1 Operational Planning & Control Plan Clause 8.1 How ISMS processes are planned, controlled, changed and outsourced
    2 Risk Treatment Plan – Implementation Tracker Clause 8.3 Execution of the risk-treatment plan to completion, with evidence
    3 Operational Security Policies & Procedures Pack Clause 8.1 & Annex A The supporting policies and procedures that implement the Annex A controls
    4 Control Implementation Evidence Log Clause 8 & Annex A Proof that each applicable control is implemented and operating

    Why this matters

    At Stage 2, the auditor tests whether controls actually operate – not just whether policies exist. They will sample controls from your SoA and ask for evidence: records, logs, screenshots, tickets, minutes. A control marked "implemented" in the SoA with no operating evidence becomes a nonconformity. Clause 8.1 also requires you to control planned changes and the processes you outsource – for example, the HIS vendor and the cloud provider.

    How to work

    Drive everything from your Statement of Applicability and risk-treatment plan (Section 4). Your policies pack (3) provides the "how", your implementation tracker (2) drives the work, and your evidence log (4) proves it happened. Each assignment includes instructions, structure, assessment criteria and a downloadable template. Submit each before moving on to Section 7.

    Start here: open the Operations & Implementation Context brief, then begin Assignment 1.

  • 1 Quizes.
  • 6 Assignments.
  • A management system has to prove it is working. Section 7 covers Clause 9 – Performance Evaluation: monitoring and measuring the ISMS, auditing it independently, and having top management review it. This is where you generate the evidence that the ISMS is effective – and find the gaps before the certification body does.

    What you will do in this section

    Read the Performance-Evaluation Context brief, then produce the four Clause 9 deliverables below.

    # Deliverable ISO 27001:2022 What it establishes
    1 Monitoring, Measurement, Analysis & Evaluation Plan Clause 9.1 What is measured, how, when, by whom, and how results are evaluated
    2 Internal Audit Programme & Plan (+ checklist) Clause 9.2 The audit programme, scope, criteria, schedule and independence
    3 Internal Audit Report Clause 9.2 Audit findings, nonconformities and observations, with evidence
    4 Management Review pack (inputs + minutes) Clause 9.3 Top management's review of the ISMS, with all required inputs and outputs

    Why this matters

    These three processes are mandatory and heavily audited. The certification body expects defined metrics with real results and analysis (9.1); a completed internal audit covering the whole ISMS, run by competent and independent auditors (9.2); and management-review minutes that cover every required input and produce decisions on improvement and resources (9.3). Running a genuine internal audit now lets you fix nonconformities before Stage 2 finds them for you.

    How to work

    Measure against the objectives you set in Section 4 and the controls you implemented in Section 6. Your internal audit (2/3) tests the whole ISMS you have built across Sections 2–6, and its results – together with your metrics – become inputs to the management review (4). Each assignment includes instructions, structure, assessment criteria and a downloadable template. Submit each before moving on to Section 8.

    Start here: open the Performance-Evaluation Context brief, then begin Assignment 1.

  • 1 Quizes.
  • 4 Assignments.
  • The ISMS has been measured and audited; now you make it better. Section 8 covers Clause 10 – Improvement: you take the nonconformities from your Section 7 internal audit and drive them to proper closure, and you establish how MSH will keep improving its ISMS going forward, not just react when something breaks.

    What you will do in this section

    Read the Improvement Context brief, then produce the three Clause 10 deliverables below. They build directly on your Section 7 audit findings.

    # Deliverable ISO 27001:2022 What it establishes
    1 Nonconformity & Corrective Action Log Clause 10.2 A running, traceable record of every audit finding, its correction and its corrective action
    2 Root-Cause & Corrective Action Report Clause 10.2 A full root-cause analysis (5 Whys / fishbone) for one real finding, proving the cause – not just stating it
    3 Continual Improvement Register Clause 10.1 Improvement opportunities the ISMS pursues on purpose, not only in reaction to failure

    Why this matters

    Clause 10.2 requires more than fixing the immediate symptom: you have to evaluate the need for action to eliminate the cause, implement it, and review whether it actually worked. Auditors specifically look for the difference between a "correction" (fixing this instance) and a "corrective action" (stopping it recurring) – and they will sample your CAPA log for exactly that distinction. A perfectly clean audit with nothing to improve is itself a red flag: it suggests the review wasn't rigorous, not that the ISMS is flawless.

    How to work

    Transfer every finding from your MSH-24 Internal Audit Report into the CAPA log (1), then pick your single worst finding and run a genuine root-cause analysis for it in (2) – don't stop at the first plausible answer. Populate the improvement register (3) with items from varied sources: audit findings, near-misses, staff suggestions, and management-review outputs. Each assignment includes instructions, structure, assessment criteria and a downloadable template. Submit each before moving on to Section 9.

    Start here: open the Improvement Context brief, then begin Assignment 1.

  • 1 Quizes.
  • 3 Assignments.
  • This is the finish line. Meridian Specialist Hospital's ISMS has been designed, implemented, measured, audited and improved. Section 9 is the Capstone – Certification Readiness milestone, where you prove the ISMS is actually ready for the certification body, exactly as a real Lead Implementer would before inviting an auditor in.

    What you will do in this section

    Read the Certification Readiness Context brief, then produce the four capstone deliverables below, in order – each one draws on every artefact you have produced since Section 1.

    # Deliverable ISO 27001:2022 What it establishes
    1 ISMS Documentation & Records Index Mandatory documentation, Clauses 4–10 Every mandatory document/record exists, is current, and is controlled
    2 Stage 1 Readiness Self-Assessment Full standard, Stage 1 scope A documentation review – playing the Stage 1 auditor against your own work
    3 Stage 2 Certification-Readiness Assessment Annex A + Clauses 9–10 Objective evidence that a sample of controls are actually implemented and effective
    4 Executive Certification-Readiness Report & Board Presentation All prior deliverables as evidence base A Board-ready go/no-go recommendation on certification

    Why this matters

    Stage 1 and Stage 2 are different tests, and confusing them is a common first-time mistake: Stage 1 checks whether the ISMS is documented and internally consistent; Stage 2 checks whether it actually operates, using objective evidence rather than policy citations. A self-assessment that scores every requirement "Ready" is itself a warning sign to an experienced auditor – a real ISMS at this stage almost always has some genuinely partial areas, and disclosing them honestly is a sign of a mature, functioning management system, not a weakness to hide.

    How to work

    Build the documentation index (1) first – it is your master cross-reference to every deliverable from Sections 1–8. Use it to run the Stage 1 self-assessment (2), then sample controls across all four Annex A themes plus Clauses 9 and 10 for the Stage 2 assessment (3). Finally, synthesise all three into the Executive Report (4): an honest, evidence-based recommendation the Board can actually act on. Each assignment includes instructions, structure, assessment criteria and a downloadable template.

    Start here: open the Certification Readiness Context brief, then begin Assignment 1. Completing this milestone means you have taken an organization from zero to certification-ready, A to Z, using realistic data.

  • 1 Quizes.
  • 4 Assignments.

Frequently Bought Courses

CSS

Cyber Security Specialist Workshop

Mohamed Atef

Bestseller

$1000

Cyber Security Certifications Practice Questions 2023

Cyber Security Certifications Practice Questions 2023

Samer Kilani

Bestseller

$

Cyber Security Certifications Practice Questions 2022_1

Cyber Security Certifications Practice Questions 2022 copy 1

InfoSec4TC Support

Bestseller

$

Instructor :

Eman Reda

Developer and Lead Instructor

  • 1544 Students
  • 35 Course(s)