Skip to main content
Image coming soon

SEC5073 Mastering ISO 27001 for Transition and Transformation Leaders

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering ISO 27001 for Transition and Transformation Leaders

Build trusted, reusable compliance artefacts that scale across programs and stakeholders

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Audit packages that demand last-minute fixes and cross-program coordination

The situation this course is for

In complex transformation environments, compliance evidence is often rebuilt from scratch each cycle, creating duplication, stakeholder fatigue, and review delays. The lack of standardized, reusable artefacts means teams restart instead of scaling what works.

Who this is for

Senior project leader in consulting or systems integration, managing multi-phase transitions with compliance dependencies across regions or clients

Who this is not for

Entry-level auditors, standalone security specialists not tied to transformation delivery, or practitioners focused only on technical implementation without cross-functional coordination

What you walk away with

  • Produce ISO 27001-compliant evidence packages in under 10 hours using reusable templates
  • Standardize control mappings across transformation programs to reduce rework by 70%
  • Become the go-to integrator for compliance readiness in multi-vendor delivery
  • Reduce stakeholder follow-up cycles by pre-validating evidence with auditor-grade precision
  • Scale assurance practices across regions without adding headcount

The 12 modules (with all 144 chapters)

Module 1. Understanding ISO 27001 in Transformation Contexts
Lay the foundation for applying ISO 27001 principles specifically within transition and transformation programs, focusing on integration with existing project governance and stakeholder alignment.
12 chapters in this module
  1. Defining information security scope in multi-client environments
  2. Aligning ISO 27001 with CGI’s transformation delivery lifecycle
  3. Mapping compliance requirements to program milestones
  4. Integrating risk assessments into change planning phases
  5. Identifying key stakeholders across business units and regions
  6. Establishing baseline security controls for new systems
  7. Documenting asset inventories in hybrid environments
  8. Setting measurable objectives for information security
  9. Linking transformation goals to ISO 27001 clauses
  10. Creating evidence trails that satisfy auditor expectations
  11. Avoiding common gaps in transformation-related SoA documents
  12. Using ISO 27001 to strengthen client trust during transitions
Module 2. Scoping Information Security Across Programs
Learn how to define and justify the scope of information security management systems when multiple transformation initiatives overlap across departments and geographies.
12 chapters in this module
  1. Determining boundaries for integrated transformation projects
  2. Excluding systems with valid justification and documentation
  3. Handling shared infrastructure across client engagements
  4. Documenting scope decisions for internal and external review
  5. Aligning scope with contractual security obligations
  6. Managing scope changes during program evolution
  7. Using architecture diagrams to support scoping decisions
  8. Ensuring cloud assets are appropriately scoped
  9. Avoiding over-scoping that increases audit burden
  10. Leveraging past audits to streamline current scoping
  11. Securing leadership sign-off on scope statements
  12. Presenting scope rationale to compliance reviewers
Module 3. Risk Assessment Tailored to Transformation
Adapt ISO 27001 risk assessment methods to the dynamic nature of transition projects, ensuring risks are identified early and managed proactively.
12 chapters in this module
  1. Integrating risk identification into project kickoffs
  2. Using threat modeling for new system deployments
  3. Assessing third-party risks in vendor-led transformations
  4. Documenting risk treatment plans with clear ownership
  5. Prioritizing risks based on business impact and likelihood
  6. Linking risk outcomes to control implementation timelines
  7. Validating risk assessments with cross-functional input
  8. Updating risk registers during program pivots
  9. Aligning risk criteria with organizational risk appetite
  10. Producing auditor-ready risk assessment reports
  11. Avoiding generic risk statements in favor of specifics
  12. Using historical data to inform current risk judgments
Module 4. Building Reusable Control Frameworks
Develop standardized, repeatable control implementations that can be deployed across multiple transformation programs and clients.
12 chapters in this module
  1. Identifying common control requirements across projects
  2. Creating modular control implementation guides
  3. Standardizing access control configurations
  4. Documenting control evidence for reuse
  5. Designing templates for policy exception tracking
  6. Ensuring controls meet ISO 27001 Annex A requirements
  7. Integrating control testing into QA cycles
  8. Using automation to maintain control consistency
  9. Versioning control documentation for audit trails
  10. Training teams on standardized control application
  11. Reducing control setup time through reuse
  12. Validating controls against auditor checklists
Module 5. Managing Vendor and Third-Party Risks
Apply ISO 27001 controls to third-party relationships common in transformation projects, ensuring compliance extends beyond internal teams.
12 chapters in this module
  1. Assessing vendor security posture during selection
  2. Incorporating ISO 27001 requirements into RFPs
  3. Monitoring vendor compliance throughout engagement
  4. Managing subcontractor access and controls
  5. Conducting vendor security assessments remotely
  6. Documenting third-party risk treatment decisions
  7. Ensuring cloud providers meet control obligations
  8. Using SIG questionnaires effectively
  9. Tracking vendor exceptions and remediation
  10. Aligning vendor SLAs with security requirements
  11. Reporting vendor risks to program leadership
  12. Maintaining oversight without direct control
Module 6. Documenting the Statement of Applicability
Create a robust, defensible SoA that clearly justifies control selection and exclusions, tailored to transformation program needs.
12 chapters in this module
  1. Structuring the SoA for multi-program clarity
  2. Justifying exclusions with evidence and rationale
  3. Linking controls to risk treatment decisions
  4. Using tables to enhance readability for auditors
  5. Maintaining version history for compliance tracking
  6. Incorporating feedback from internal reviewers
  7. Aligning SoA content with organizational policies
  8. Ensuring all Annex A controls are addressed
  9. Avoiding vague or boilerplate language
  10. Using color coding to highlight changes across versions
  11. Preparing SoA for external audit scrutiny
  12. Training team members to update the SoA accurately
Module 7. Internal Audit and Readiness Testing
Prepare for certification audits by conducting realistic internal reviews that simulate external assessor behavior.
12 chapters in this module
  1. Scheduling internal audits around program milestones
  2. Selecting audit samples across diverse projects
  3. Using checklists aligned with certification bodies
  4. Conducting remote evidence collection efficiently
  5. Interviewing team members on control understanding
  6. Identifying gaps before external audit begins
  7. Prioritizing findings based on severity and effort
  8. Assigning remediation tasks with deadlines
  9. Tracking closure of audit observations
  10. Simulating stage 1 and stage 2 audit formats
  11. Preparing leadership for auditor Q&A
  12. Building confidence through mock audit cycles
Module 8. Evidence Collection at Scale
Implement systems to gather, organize, and validate compliance evidence across multiple programs and regions.
12 chapters in this module
  1. Defining evidence requirements by control
  2. Automating evidence capture from IT systems
  3. Organizing files for auditor accessibility
  4. Using metadata to streamline search and retrieval
  5. Validating evidence completeness before submission
  6. Standardizing naming conventions across teams
  7. Securing evidence storage with access controls
  8. Integrating evidence workflows into project plans
  9. Reducing manual follow-ups with status dashboards
  10. Training local teams on evidence submission
  11. Auditing evidence processes for continuous improvement
  12. Scaling evidence collection without adding staff
Module 9. Stakeholder Communication and Alignment
Develop communication strategies that keep executives, clients, and technical teams aligned on compliance progress and expectations.
12 chapters in this module
  1. Tailoring messages to different stakeholder groups
  2. Reporting progress using ISO 27001 metrics
  3. Holding compliance sync meetings with program leads
  4. Addressing resistance to security requirements
  5. Using dashboards to visualize control coverage
  6. Escalating blockers with clear context
  7. Integrating compliance updates into program reports
  8. Managing expectations around audit timelines
  9. Sharing success stories across teams
  10. Building trust through transparency
  11. Responding to stakeholder inquiries promptly
  12. Maintaining momentum between audit cycles
Module 10. Continuous Improvement and Surveillance
Establish routines to maintain ISO 27001 compliance between audits and adapt to evolving transformation needs.
12 chapters in this module
  1. Scheduling regular management reviews
  2. Updating risk assessments with new threats
  3. Incorporating lessons from past audits
  4. Measuring control effectiveness over time
  5. Adjusting policies based on feedback
  6. Tracking key performance indicators for security
  7. Conducting periodic internal audits
  8. Engaging leadership in continuous improvement
  9. Updating documentation after system changes
  10. Monitoring compliance across remote teams
  11. Using feedback loops to refine processes
  12. Planning for recertification efficiently
Module 11. Cross-Regional Compliance Coordination
Coordinate ISO 27001 implementation across multiple geographies, accounting for regional differences while maintaining consistency.
12 chapters in this module
  1. Identifying regional regulatory overlaps
  2. Standardizing core controls with local adaptations
  3. Managing time zone challenges in evidence collection
  4. Training regional teams on central requirements
  5. Using centralized templates with local inputs
  6. Resolving conflicts between regional practices
  7. Ensuring language differences don’t impact clarity
  8. Auditing remote sites effectively
  9. Leveraging regional champions for engagement
  10. Sharing best practices across locations
  11. Maintaining consistency in documentation
  12. Scaling compliance leadership across regions
Module 12. Sustaining Compliance Beyond Certification
Ensure ISO 27001 remains embedded in transformation culture long after initial certification, preventing regression.
12 chapters in this module
  1. Integrating compliance into onboarding
  2. Updating playbooks with new learnings
  3. Recognizing teams for compliance excellence
  4. Building internal expertise through mentoring
  5. Reinforcing expectations in performance reviews
  6. Using compliance as a differentiator in proposals
  7. Sharing maturity metrics with leadership
  8. Avoiding compliance fatigue through efficiency
  9. Celebrating audit successes publicly
  10. Linking compliance to career development
  11. Institutionalizing lessons in knowledge bases
  12. Making ISO 27001 a core part of delivery identity

How this maps to your situation

  • Transition program governance
  • Multi-client compliance alignment
  • Vendor-led transformation oversight
  • Global stakeholder coordination

Before vs. after

Before
Rebuilding compliance evidence from scratch for each transformation program, facing rework and stakeholder delays
After
Producing auditor-ready ISO 27001 packages in 10 hours using reusable, standardized frameworks across clients and regions

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes of focused learning, structured to fit within a single Sunday morning.

If nothing changes
Without a standardized approach, teams will continue rebuilding compliance artefacts from scratch, increasing cycle time, stakeholder fatigue, and audit risk, especially as regulatory scrutiny intensifies across transformation initiatives.

How this compares to the alternatives

Unlike generic ISO 27001 courses focused on policy writing or checklist compliance, this course is tailored to transformation leaders who must deliver assurance across programs, stakeholders, and regions, without slowing down delivery.

Frequently asked

Is this course relevant if I’m not directly responsible for certification?
Yes. This course is designed for project leaders who must integrate compliance into delivery, whether or not they own final certification.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will the templates work for multiple clients?
Yes. Templates are designed to be adaptable across engagements while maintaining compliance integrity.
$199 one-time. 90 minutes of focused learning, structured to fit within a single Sunday morning..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours