Training

    Cybersecurity certification training

    The ISO/IEC 27001 track for security practitioners, from Foundation through to building an ISMS or auditing one. Taught by people who implement these systems for a living, so the examples are real rather than illustrative.

    Three levels, one standard, and a choice most organisations get wrong

    The ISO/IEC 27001 track has three levels and they are not a ladder everyone climbs. Foundation establishes the vocabulary. Lead Implementer is for the person who will build and run the management system. Lead Auditor is for the person who will assess one. They are different jobs, and sending someone on the wrong one is the most common and most expensive mistake in this catalogue.

    The error we see most often is sending the future ISMS owner on Lead Auditor, usually because it sounds more senior. It is not more senior; it is a different discipline. An auditor is trained to assess conformity and to remain independent of what they assess — which means, if they then build the system, they cannot audit it. Organisations discover this at the worst possible moment, in the run-up to certification.

    The reverse error is subtler. An internal audit function staffed by people trained only as implementers tends to audit towards what it would have built, which a certification body notices. If you intend to run a proper clause 9.2 internal audit, someone has to hold the auditor training.

    A PECB certification is issued under ISO/IEC 17024, the international standard for bodies that certify persons, which is why it travels: a Lead Implementer certificate earned in Amsterdam means the same thing to a client in Casablanca or Riyadh. The credential is also graded by documented professional experience rather than by exam mark — the same examination can lead to a Provisional, Lead or Senior Lead credential depending on the experience you can evidence. We tell candidates before they book where their experience is likely to place them.

    The exam is included in every seat price, sat at the end of the course while the material is current. Courseware and examination are in English; sessions are facilitated in English or French.

    Which level

    LevelWho it is forWhat they can do afterwards
    ISO/IEC 27001 FoundationAnyone who needs the vocabulary — project members, auditees, managers whose teams are in scopeRead the standard, understand what an ISMS is, and take part in an implementation without slowing it down
    ISO/IEC 27001 Lead ImplementerThe person who will actually build and run the management systemScope, design, document and operate an ISMS, and take an organisation through certification
    ISO/IEC 27001 Lead AuditorInternal audit, assurance functions, and anyone auditing suppliersPlan and lead an audit, gather and evaluate evidence, and write findings that withstand challenge

    Courses in this track

    Foundation · 2 days

    ISO/IEC 27001 Foundation

    The two-day entry point to ISO/IEC 27001. It gives you the vocabulary, the structure of the standard and a working understanding of what an information security management system actually is, which is what most people are missing when they are asked to contribute to one.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €1,150–1,450 per seat

    Lead · 5 days

    ISO/IEC 27001 Lead Implementer

    Five days on implementing an information security management system end to end, using PECB's implementation methodology. It is the course to take if certification is a commitment rather than an ambition, and it is our highest-volume track.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €2,350–2,850 per seat

    Lead · 5 days

    ISO/IEC 27001 Lead Auditor

    Five days on auditing an information security management system to ISO/IEC 27001, following the audit principles of ISO 19011 and the certification-body requirements of ISO/IEC 17021-1. A different discipline from implementation, and usually a different person.

    Delivery:
    Classroom, In-company, Live online, Self-paced
    Exam:
    Included
    Price:
    €2,350–2,850 per seat

    All prices exclude VAT. Classroom sessions held in the Netherlands are subject to 21% Dutch VAT for all attendees, regardless of the attendee's country — EU rules tax admission to an educational event where the event takes place. Online and in-company delivery to businesses elsewhere in the EU is reverse-charged.

    Courseware and examination in English. Sessions facilitated in English or French.

    GSNA Solutions is a PECB Certified Partner and authorised reseller. PECB personnel certifications are issued under ISO/IEC 17024. Course participants who complete a certificate programme hold a certificate; they are not thereby certified, licensed, accredited or registered to practise an occupation. Certification follows successful examination and verification of professional experience against PECB's published requirements.

    See every course in one table

    Questions

    Should the same person do Lead Implementer and Lead Auditor?

    They can, and many practitioners hold both, but they cannot then audit the system they built — independence is a requirement your certification body will check. In a small team the usual answer is to train the implementer properly and bring in an independent auditor for clause 9.2.

    Is Foundation a prerequisite?

    No. Lead Implementer and Lead Auditor can be taken directly, and experienced practitioners usually should. Foundation earns its place when a wider group needs the vocabulary — a project team, or the people who will be audited.

    What determines which credential we receive?

    Documented professional experience, assessed by PECB after a successful examination, not the exam mark. That is why the same course can produce a Provisional, a Lead or a Senior Lead credential, and why we discuss experience before a booking rather than after.

    Can we run this in-company?

    Yes, with the accredited courseware and examination delivered exactly as PECB requires. What changes is the discussion around it, which uses your systems and your risk register.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.