
Cybersecurity certification
ISO/IEC 27001 Lead Implementer
Five days on implementing an information security management system end to end, using PECB's implementation methodology. It is the course to take if certification is a commitment rather than an ambition, and it is our highest-volume track.
Duration
5 days
Languages
English, French
Delivery
Classroom, In-company, Live online, Self-paced
Exam
Included in the price
CPD credits
31 Continuing Professional Development credits
Accreditation
PECB
Courseware and examination in English. Sessions facilitated in English or French.
Who it is for
The person who will actually build the ISMS, security managers, consultants and IT leads accountable for reaching certification.
Prerequisites
A general knowledge of ISMS concepts and of ISO/IEC 27001.
What you will be able to do
- 01Plan and scope an ISMS against real organisational boundaries.
- 02Run a gap analysis and turn it into a costed treatment plan.
- 03Conduct a risk assessment and produce a defensible Statement of Applicability.
- 04Build the documentation an auditor will ask for, without building more than that.
- 05Prepare the organisation for stage 1 and stage 2 audits.
- 06Maintain the system after certification rather than rebuilding it before each surveillance visit.
What is covered
Initiating the ISMS
Scope, boundaries, leadership commitment and the business case.
Gap analysis and planning
Where the organisation actually stands.
Risk assessment and treatment
Method, criteria, and the Statement of Applicability.
Implementation
Controls, documentation, competence and awareness.
Monitoring and internal audit
Measurement, internal audit and management review.
Certification audit preparation
What stage 1 and stage 2 examine.
Exam
Sat at the end of the course and included in the price.
The exam and the certificate
The exam is sat at the end of the course and is included in the price. Certification is issued by PECB following successful examination and verification of professional experience against PECB’s published requirements, which vary by credential level. We tell candidates in advance where their experience may fall short of the credential they are aiming at.
The same examination leads to a graded credential, from Provisional through to Senior, and the grade you receive depends on your documented professional experience and project involvement, not on your exam mark. We tell candidates before they book which grade their experience currently supports.
The exam is sat at the end of the course and is included in the price. Certification is issued by PECB following successful examination and verification of professional experience against PECB's published requirements, which vary by credential level. We tell candidates in advance where their experience may fall short of the credential they are aiming at.Price
€2,350–2,850 per seat
All prices exclude VAT. Classroom sessions held in the Netherlands are subject to 21% Dutch VAT for all attendees, regardless of the attendee's country — EU rules tax admission to an educational event where the event takes place. Online and in-company delivery to businesses elsewhere in the EU is reverse-charged.
GSNA Solutions is a PECB Certified Partner and authorised reseller. PECB personnel certifications are issued under ISO/IEC 17024. Course participants who complete a certificate programme hold a certificate; they are not thereby certified, licensed, accredited or registered to practise an occupation. Certification follows successful examination and verification of professional experience against PECB's published requirements.
Other courses on this track
2 days
ISO/IEC 27001 Foundation
The two-day entry point to ISO/IEC 27001. It gives you the vocabulary, the structure of the standard and a working understanding of what an information security management system actually is, which is what most people are missing when they are asked to contribute to one.
5 days
ISO/IEC 27001 Lead Auditor
Five days on auditing an information security management system to ISO/IEC 27001, following the audit principles of ISO 19011 and the certification-body requirements of ISO/IEC 17021-1. A different discipline from implementation, and usually a different person.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.