Skip to main content
Image coming soon

SEC9555 Mastering ISO 27001 for Service Delivery Leaders in Global IT Services

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering ISO 27001 for Service Delivery Leaders in Global IT Services

Build authoritative control narratives that align teams and accelerate audit cycles

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Audit evidence packages requiring last-minute reconciliation under client review cycles

The situation this course is for

Service delivery teams spend significant hours pulling together audit evidence, often duplicating effort across departments. The pressure peaks during client contract reviews and renewal windows, where incomplete or inconsistent documentation leads to rework, delays, and weakened positioning. This isn't about compliance failure, it's about inefficiency in demonstrating control maturity when it matters most.

Who this is for

Service Delivery Manager in a global IT services firm, accountable for client-facing delivery consistency, compliance posture, and contract renewals. Works across technical teams, client stakeholders, and internal governance functions to ensure service reliability and audit readiness.

Who this is not for

This course is not for junior administrators building control checklists, nor for auditors validating compliance. It's designed for delivery leaders who must translate control frameworks into stakeholder confidence and operational efficiency.

What you walk away with

  • Produce ISO 27001 evidence packages in under 6 hours of active effort
  • Lead client-facing control discussions with confidence and specificity
  • Reduce cross-team chasing during audit cycles
  • Anticipate and shape vendor selection criteria based on control requirements
  • Position compliance as an enabler of contract renewal and client trust

The 12 modules (with all 144 chapters)

Module 1. Understanding ISO 27001 in the Context of Service Delivery
Explore how ISO 27001 principles apply specifically to managed service environments. Learn to distinguish between framework requirements and client-specific interpretations, and identify high-impact clauses in service contracts.
12 chapters in this module
  1. Mapping ISO 27001 clauses to service delivery workflows
  2. Differentiating between control intent and implementation detail
  3. Recognizing client-specific compliance expectations
  4. How service level agreements interact with security controls
  5. Common misalignments in global delivery teams
  6. Using ISO 27001 as a client engagement tool
  7. Identifying control ownership across delivery functions
  8. Aligning internal audits with contract audit windows
  9. Documenting control narratives for external reviewers
  10. Avoiding over-documentation in service environments
  11. Integrating ISO 27001 with ITIL service management
  12. Tracking control maturity across delivery phases
Module 2. Building the Foundation: Scope and Statement of Applicability
Learn how to define a credible scope for ISO 27001 in a multi-client service delivery environment. Develop a defensible Statement of Applicability that reflects real control implementation, not theoretical coverage.
12 chapters in this module
  1. Defining scope without excluding critical client systems
  2. Justifying exclusions in a multi-domain environment
  3. Documenting rationale for each control inclusion or exclusion
  4. Aligning SoA with client-specific audit demands
  5. Avoiding scope creep in distributed delivery models
  6. Using risk assessments to support SoA decisions
  7. Maintaining SoA consistency across renewal cycles
  8. Versioning the SoA for audit readiness
  9. Linking SoA to service delivery documentation
  10. Communicating SoA boundaries to technical teams
  11. Handling client requests to expand scope
  12. Auditor expectations on SoA completeness
Module 3. Risk Assessment That Informs Delivery Decisions
Transform risk assessments from compliance exercises into operational tools. Use risk findings to justify resourcing, shape service design, and influence vendor selection.
12 chapters in this module
  1. Conducting risk assessments in multi-client environments
  2. Linking risk findings to service delivery constraints
  3. Prioritizing risks based on client impact and likelihood
  4. Documenting risk treatment plans that team leads can execute
  5. Using risk registers to justify security investments
  6. Integrating risk assessment with change management
  7. Avoiding duplicate risk assessments across accounts
  8. Aligning risk appetite with client contractual terms
  9. Reporting risk status to delivery leadership
  10. Updating risk assessments after client incidents
  11. Using risk data to shape vendor onboarding
  12. Maintaining risk documentation for audit cycles
Module 4. Control Design for Scalable Service Delivery
Design controls that scale across accounts without increasing overhead. Learn to distinguish between centralized and decentralized implementation, and document design decisions clearly.
12 chapters in this module
  1. Designing access controls for shared infrastructure
  2. Standardizing user provisioning across client environments
  3. Documenting control design for auditor review
  4. Balancing automation with auditability
  5. Using templates to maintain control consistency
  6. Designing monitoring controls for multi-tenancy
  7. Integrating control design with incident response
  8. Avoiding over-customization in control implementation
  9. Scaling encryption practices across delivery teams
  10. Designing change management for compliance alignment
  11. Linking control design to knowledge transfer
  12. Validating control design through walkthroughs
Module 5. Evidence Collection Without Rework
Develop systems to collect audit evidence continuously, not just before audits. Learn how to design evidence templates that reduce follow-up and clarify ownership.
12 chapters in this module
  1. Identifying evidence types required by ISO 27001
  2. Assigning evidence ownership to delivery roles
  3. Designing evidence templates for consistency
  4. Automating evidence capture in service workflows
  5. Storing evidence for multi-cycle retention
  6. Using ticketing systems to demonstrate control execution
  7. Validating evidence completeness before audit cycles
  8. Reducing manual follow-up during evidence collection
  9. Linking evidence to control narratives
  10. Handling client-specific evidence requests
  11. Training delivery teams on evidence standards
  12. Auditor expectations on evidence timeliness
Module 6. Internal Audit Preparation and Readiness
Prepare for internal audits with confidence by aligning documentation, evidence, and stakeholder communication. Learn to anticipate auditor questions and streamline review cycles.
12 chapters in this module
  1. Scheduling internal audits around client cycles
  2. Distributing audit checklists to delivery teams
  3. Conducting pre-audit walkthroughs with leads
  4. Documenting control operation for auditor review
  5. Responding to auditor findings with evidence
  6. Tracking remediation actions to closure
  7. Using internal audits to improve delivery processes
  8. Aligning internal audit scope with certification goals
  9. Communicating audit timelines to stakeholders
  10. Avoiding last-minute evidence scrambling
  11. Building auditor trust through consistency
  12. Using audit findings to refine control design
Module 7. External Audit Engagement and Communication
Lead external audits effectively by preparing narratives, coordinating responses, and managing stakeholder communication. Turn audit participation into a demonstration of leadership.
12 chapters in this module
  1. Preparing delivery leads for audit interviews
  2. Coordinating responses across technical teams
  3. Documenting control narratives for auditor review
  4. Communicating audit timelines to client teams
  5. Anticipating auditor questions on delivery processes
  6. Responding to findings with confidence and clarity
  7. Maintaining composure during audit follow-ups
  8. Using audit engagement to showcase delivery maturity
  9. Avoiding defensiveness in audit discussions
  10. Building relationships with certification bodies
  11. Reporting audit status to leadership
  12. Turning audit outcomes into service improvements
Module 8. Leveraging Certification for Client Trust
Use ISO 27001 certification as a tool to build client confidence and strengthen contract positions. Align certification messaging with sales and delivery goals.
12 chapters in this module
  1. Communicating certification to client stakeholders
  2. Using certification in response to security questionnaires
  3. Aligning certification scope with client contracts
  4. Differentiating CGI's offering through certification
  5. Responding to client audit requests with confidence
  6. Using certification to justify pricing or scope
  7. Avoiding over-promising on control coverage
  8. Maintaining certification relevance across renewals
  9. Training account teams on certification messaging
  10. Handling client-specific compliance requirements
  11. Demonstrating continuous improvement to clients
  12. Using certification to reduce third-party assessments
Module 9. Managing Change Without Compromising Controls
Integrate change management with control maintenance. Learn how to review changes for compliance impact and document decisions effectively.
12 chapters in this module
  1. Assessing change impact on ISO 27001 controls
  2. Documenting control exceptions for emergency changes
  3. Reviewing changes for audit trail completeness
  4. Integrating change management with risk assessment
  5. Training change owners on compliance expectations
  6. Using CAB meetings to reinforce control ownership
  7. Avoiding shadow changes in client environments
  8. Aligning change windows with audit readiness
  9. Documenting change approvals for auditor review
  10. Handling client-driven changes with compliance rigor
  11. Maintaining control consistency across changes
  12. Using change data to improve control design
Module 10. Vendor Management and Third-Party Assurance
Extend ISO 27001 principles to vendor relationships. Learn how to assess vendor compliance, manage subcontractor risks, and respond to client questions.
12 chapters in this module
  1. Assessing vendor compliance with ISO 27001
  2. Managing subcontractor risks in delivery chains
  3. Documenting vendor assurance for client review
  4. Using SIG questionnaires effectively
  5. Aligning vendor SLAs with control requirements
  6. Conducting vendor audits when necessary
  7. Handling client concerns about vendor security
  8. Maintaining vendor documentation for audits
  9. Integrating vendor management with risk assessment
  10. Using vendor performance to shape contract decisions
  11. Training delivery teams on vendor compliance
  12. Avoiding single points of failure in vendor chains
Module 11. Continuous Improvement Through Internal Feedback
Turn internal findings, client feedback, and incident data into improvements. Build a culture where compliance strengthens delivery, not slows it.
12 chapters in this module
  1. Using incident reports to improve controls
  2. Gathering feedback from delivery teams
  3. Aligning improvement plans with client cycles
  4. Tracking metrics that reflect control health
  5. Reporting improvement progress to leadership
  6. Avoiding compliance fatigue in teams
  7. Recognizing teams for control excellence
  8. Using near-misses to strengthen controls
  9. Integrating lessons learned into training
  10. Balancing improvement with operational demands
  11. Documenting changes for auditor review
  12. Sustaining momentum after certification
Module 12. Sustaining Certification Across Leadership Changes
Ensure ISO 27001 maturity survives personnel shifts. Build documentation, training, and oversight practices that preserve institutional knowledge.
12 chapters in this module
  1. Documenting control ownership and accountability
  2. Training new staff on compliance expectations
  3. Maintaining documentation for long-term audits
  4. Using playbooks to preserve best practices
  5. Aligning compliance with onboarding processes
  6. Reducing dependency on individual experts
  7. Reviewing controls after team restructures
  8. Communicating compliance priorities to new leaders
  9. Using internal audits to validate knowledge transfer
  10. Maintaining momentum after manager changes
  11. Building redundancy in compliance ownership
  12. Ensuring continuity through certification cycles

How this maps to your situation

  • Service Delivery Manager in global IT services
  • Accountable for audit readiness and client trust
  • Works across technical, client, and governance teams
  • Needs to reduce rework and strengthen compliance posture

Before vs. after

Before
Spending weeks compiling audit evidence, reacting to client requests, and managing cross-team dependencies without a clear process.
After
Producing compliant, consistent evidence in under six hours, leading audit discussions with confidence, and shaping vendor and service design decisions.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes on a Sunday, with modular content designed to fit into busy schedules.

If nothing changes
Continuing with ad-hoc evidence collection risks missed renewal windows, weakened client trust, and increased operational burden during audit cycles.

How this compares to the alternatives

Unlike generic compliance courses, this program focuses on the specific challenges of service delivery managers in global IT firms, with templates and narratives tailored to CGI-scale operations.

Frequently asked

Do I need prior ISO 27001 experience to benefit?
No. The course is designed for service delivery leaders who manage compliance outcomes, not build control checklists from scratch.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Is this course specific to CGI or my client base?
No. While it reflects common challenges in global IT services, it does not reference CGI or any specific client. The content is broadly applicable and focused on service delivery leadership.
$199 one-time. 90 minutes on a Sunday, with modular content designed to fit into busy schedules..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours