Skip to main content
Image coming soon

SEC5238 Mastering ISO 27001 for Service Delivery Managers

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering ISO 27001 for Service Delivery Managers

A structured path to owning critical security handoffs with confidence and precision

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Audit and regulator-facing packages requiring cross-team rework under time pressure

The situation this course is for

Service delivery leaders often inherit fragmented compliance workflows, where evidence collection spans teams with different priorities and timelines. This leads to high-effort, last-minute scrambles before audits or regulator reviews, especially when documentation isn't structured for reuse. The burden falls on delivery managers to reconcile gaps, not just report status.

Who this is for

Service Delivery Managers in global IT services firms who steward compliance evidence across project lifecycles, interface with regulators, and own handoffs between delivery and governance teams

Who this is not for

Individuals focused only on technical implementation without cross-functional handoffs, or those seeking executive-level board narratives rather than operational ownership

What you walk away with

  • Produce regulator-facing review packages that require no rework
  • Own the end-to-end ISO 27001 evidence lifecycle from delivery teams to audit committees
  • Reduce evidence collection effort from weeks to hours using reusable templates
  • Become the first point of contact for escalations from audit and compliance teams
  • Structure SoA narratives that stand up under regulator follow-up questioning

The 12 modules (with all 144 chapters)

Module 1. Understanding ISO 27001 in the Context of Service Delivery
Lay the foundation for applying ISO 27001 within delivery operations, focusing on control relevance to client-facing services and how clauses map to real-world deliverables.
12 chapters in this module
  1. How ISO 27001 supports service delivery resilience in global contracts
  2. Key differences between certification and continuous compliance
  3. Mapping Annex A controls to CGI delivery workflows
  4. Identifying high-impact controls for regulator-facing packages
  5. Integrating ISO 27001 requirements into service level agreements
  6. Common pitfalls in interpreting scope for multi-client environments
  7. Aligning control ownership with delivery team responsibilities
  8. Using ISO 27001 to strengthen client trust narratives
  9. Documenting control effectiveness without overburdening teams
  10. Tracking control performance across delivery lifecycles
  11. Leveraging ISO 27001 for competitive differentiation in bids
  12. Maintaining alignment as client requirements evolve
Module 2. Building the Statement of Applicability
Learn how to construct a defensible, audit-ready SoA that reflects true control implementation and is tailored to specific delivery contexts.
12 chapters in this module
  1. Understanding the purpose and structure of the SoA
  2. Determining control applicability based on risk assessments
  3. Documenting justification for control exclusions
  4. Aligning SoA content with regulator expectations
  5. Incorporating input from technical and non-technical stakeholders
  6. Maintaining version control for ongoing audits
  7. Using templates to streamline SoA updates
  8. Linking SoA entries to evidence repositories
  9. Avoiding common mistakes in control rationale
  10. Tailoring the SoA for different client industries
  11. Preparing the SoA for internal review cycles
  12. Updating the SoA in response to audit findings
Module 3. Designing Efficient Evidence Collection Workflows
Create lightweight, repeatable processes for gathering compliance evidence across distributed teams without disrupting delivery timelines.
12 chapters in this module
  1. Identifying critical evidence types for ISO 27001 audits
  2. Mapping evidence requirements to team responsibilities
  3. Designing evidence templates for consistency
  4. Scheduling evidence collection around delivery milestones
  5. Integrating evidence workflows into existing tools
  6. Reducing rework through early validation steps
  7. Handling evidence for third-party managed services
  8. Managing evidence for legacy systems
  9. Using automation to reduce manual effort
  10. Documenting evidence collection processes
  11. Training teams on evidence submission standards
  12. Auditing evidence workflows for continuous improvement
Module 4. Managing Internal Audit Cycles
Lead internal audits effectively by preparing teams, coordinating timelines, and ensuring findings are resolved promptly.
12 chapters in this module
  1. Planning audit schedules aligned with delivery cycles
  2. Assigning responsibilities for audit preparation
  3. Conducting pre-audit readiness checks
  4. Facilitating audit entry and exit meetings
  5. Documenting audit observations clearly
  6. Prioritizing findings based on risk and impact
  7. Assigning corrective actions with clear deadlines
  8. Verifying closure of corrective actions
  9. Reporting audit outcomes to leadership
  10. Using audit findings to improve processes
  11. Integrating audit feedback into team workflows
  12. Maintaining audit records for future reference
Module 5. Preparing for External Audits and Certifications
Ensure smooth external audits by preparing documentation, coordinating stakeholders, and responding to auditor inquiries effectively.
12 chapters in this module
  1. Understanding auditor expectations and timelines
  2. Assembling audit packages in advance
  3. Coordinating stakeholder availability for audits
  4. Conducting mock audits to identify gaps
  5. Preparing teams for auditor interviews
  6. Responding to auditor questions accurately
  7. Addressing nonconformities efficiently
  8. Negotiating timelines for corrective actions
  9. Maintaining professionalism during audit process
  10. Documenting audit outcomes thoroughly
  11. Using audit results to enhance compliance posture
  12. Celebrating certification achievements appropriately
Module 6. Maintaining Continuous Compliance
Implement ongoing compliance practices that keep ISO 27001 controls effective between audits and adapt to changing conditions.
12 chapters in this module
  1. Scheduling regular control checks
  2. Updating risk assessments periodically
  3. Reviewing control effectiveness regularly
  4. Adjusting controls as business changes
  5. Monitoring for new regulatory requirements
  6. Incorporating lessons from incidents
  7. Conducting periodic policy reviews
  8. Ensuring staff awareness of updates
  9. Tracking compliance metrics over time
  10. Identifying improvement opportunities
  11. Planning for recertification audits
  12. Maintaining momentum after initial certification
Module 7. Managing Documentation and Records
Establish clear documentation practices that support compliance while minimizing administrative burden on delivery teams.
12 chapters in this module
  1. Identifying required ISO 27001 records
  2. Creating standardized document templates
  3. Setting document retention periods
  4. Storing documents securely and accessibly
  5. Controlling document versions effectively
  6. Ensuring document availability for audits
  7. Reducing documentation redundancy
  8. Integrating documentation with delivery tools
  9. Training teams on documentation standards
  10. Auditing documentation practices regularly
  11. Improving documentation efficiency over time
  12. Retiring obsolete documents appropriately
Module 8. Conducting Risk Assessments
Perform thorough risk assessments that inform control selection and demonstrate due diligence to auditors and regulators.
12 chapters in this module
  1. Understanding risk assessment requirements in ISO 27001
  2. Identifying assets to protect
  3. Determining asset values and criticality
  4. Identifying threats to information security
  5. Assessing vulnerability likelihood and impact
  6. Evaluating existing control effectiveness
  7. Determining residual risk levels
  8. Documenting risk treatment decisions
  9. Obtaining necessary approvals
  10. Updating risk assessments periodically
  11. Using risk assessments to prioritize actions
  12. Aligning risk assessments with business objectives
Module 9. Implementing Security Controls
Guide the implementation of key ISO 27001 controls within service delivery contexts, focusing on practical application.
12 chapters in this module
  1. Understanding control objectives and requirements
  2. Determining implementation approach for each control
  3. Assigning control ownership clearly
  4. Developing implementation plans
  5. Integrating controls into delivery processes
  6. Testing control effectiveness
  7. Documenting control implementation
  8. Training teams on control responsibilities
  9. Monitoring control performance
  10. Addressing control gaps
  11. Reviewing controls periodically
  12. Improving controls based on feedback
Module 10. Managing Third-Party Risks
Address risks from vendors and partners by implementing appropriate controls and monitoring their compliance.
12 chapters in this module
  1. Identifying third parties requiring security oversight
  2. Assessing third-party security posture
  3. Including security requirements in contracts
  4. Conducting third-party assessments
  5. Monitoring third-party compliance
  6. Managing third-party incidents
  7. Terminating relationships securely
  8. Documenting third-party risk management
  9. Aligning with client expectations
  10. Scaling oversight across multiple vendors
  11. Using automation for continuous monitoring
  12. Improving third-party risk processes
Module 11. Building Security Awareness
Foster a culture of security awareness across delivery teams to support compliance efforts.
12 chapters in this module
  1. Identifying awareness training needs
  2. Developing engaging training content
  3. Scheduling training delivery
  4. Conducting security briefings
  5. Promoting security policies effectively
  6. Measuring awareness effectiveness
  7. Addressing knowledge gaps
  8. Incorporating lessons from incidents
  9. Encouraging reporting of concerns
  10. Recognizing security champions
  11. Updating training content regularly
  12. Aligning awareness with business changes
Module 12. Continuous Improvement of the ISMS
Establish processes for ongoing improvement of the information security management system based on performance data and changing conditions.
12 chapters in this module
  1. Monitoring ISMS performance metrics
  2. Analyzing audit results for trends
  3. Gathering feedback from stakeholders
  4. Identifying improvement opportunities
  5. Planning improvement initiatives
  6. Implementing changes systematically
  7. Measuring improvement effectiveness
  8. Documenting improvement activities
  9. Communicating improvements widely
  10. Scaling improvements across teams
  11. Sustaining improvement momentum
  12. Aligning improvements with strategic goals

How this maps to your situation

  • Initial ISO 27001 implementation in service delivery context
  • Preparing for first certification audit
  • Maintaining compliance between audits
  • Scaling compliance across multiple client engagements

Before vs. after

Before
Spending excessive time reconciling compliance gaps across delivery teams, reacting to last-minute audit requests, and managing fragmented evidence workflows.
After
Owning end-to-end regulator-facing packages with reusable templates, reducing evidence cycles from 80+ hours to under 6, and becoming the first internal reference for audit escalations.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 9 hours total, designed to be completed in short sessions over a few weeks.

If nothing changes
Without a structured approach, compliance remains reactive and resource-intensive, increasing the likelihood of audit findings, regulatory scrutiny, and delivery delays due to last-minute evidence requests.

How this compares to the alternatives

Unlike generic compliance training, this course focuses specifically on the challenges of service delivery managers in global IT firms, with practical templates and workflows tailored to ISO 27001 evidence cycles and regulator-facing reviews.

Frequently asked

How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Is this course specific to my role?
Yes, it's designed specifically for service delivery managers in global IT services firms, with examples and templates reflecting real-world delivery challenges.
What if I'm not technical?
The course focuses on operational ownership and coordination, not technical implementation, making it accessible to managers without deep technical expertise.
$199 one-time. Approximately 9 hours total, designed to be completed in short sessions over a few weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours