Welcome, Guest

ISO 27001: The Inheritance

Overview

A 4-module decision-based scenario course on ISO/IEC 27001:2022 surveillance audits and Annex A 2022 controls. The learner plays Iris Hartnell, the new ISMS Manager at an Amsterdam-headquartered managed-cloud firm, eight weeks into a role inherited without a handover. The first surveillance audit lands in week 8. Approximately 100 minutes total. Course delivered in English.

Target Audience:

ISMS managers, security managers, CISOs, and compliance officers at mid-size B2B SaaS, fintech, healthtech, and managed-cloud firms holding live ISO 27001:2022 certification with a surveillance audit booked.

Features and USPs:

The course helps learners to understand the scope and impact of the legislation and also to work through the regulation as it appears in the workplace. Learners experience the cause?and?effect of their decisions and are supported with immediate feedback. The course helps to build situational awareness, practical judgment, confidence and real?world problem?solving skills.

This interactive and adaptive online course is designed to turn a complex legislative topic into a memorable, actionable learning experience. Using a dynamic “choose your own adventure” format, the course adapts to the learner’s choices within a relatable workplace scenario.

Learning Objectives:

  • Distinguish documented controls from operating controls (ISO 17021-1)
  • Triage Annex A 2022 control exceptions and minor / major NCs
  • Manage evidence collection under audit-window time pressure
  • Calibrate customer disclosure under cert-lapse contractual penalties
  • Hold the audit position without conceding substance to the auditor