Key details

Cost: $1,650 GST exempt

Duration: 3 Days

CPD Points: 24

Qualifications: Exemplar Global IS

About the course

With cyber attacks and data security breaches on the rise, keeping your organisation’s data secure has never been more important. The ISO standard for Information Security, ISO/IEC 27001:2022 Information Security Management Systems, provides the framework to ensure your business has the tools to manage information security risk effectively.

Aligned with a risk-based approach, ISO/IEC 27001 provides organisations with a structured framework to build their information security management system, understand their threats and vulnerabilities, and determine which controls are required to keep their information assets secure. Incorporating the reference set of information security controls outlines in ISO/IEC 27002:2022, effective implementation and auditing of an information security management system helps organisations to strike a balance between confidentiality, integrity, and availability of information.

Our 3-day Information Security Management Systems course covers the key changes to the Annex A controls and management system clauses, and explains the requirements of ISO/IEC 27001:2022. You’ll learn the most current risk assessment processes and methods for protecting information assets and strengthening information security across your organisation.

This course is equivalent to 24 Continuing Professional Development (CPD) points.

Plus, you receive a complimentary licensed copy of:

  • ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

After successful completion of the course, you’ll gain access to a suite of downloadable resources, including templates and checklists

Logo of the Australian Association for Quality


AOQ Certified Quality Practitioner Recognition

This course has been recognised by the Australian Organisation for Quality (AOQ) as contributing towards the AOQ Certified Quality Practitioner (CQP) programme.

Successful completion may contribute recognised learning hours towards your CQP pathway.

Learn more about AOQ-CQP →


 

Save more when you bundle your courses

Available bundles:

No other discounts apply.

Learn more and save!

Explore our bundles

Our training is different because

Streamlined assessment process with support available.

We offer nationally and internationally recognised courses and qualifications.

Trainers are practising risk, audit, and systems experts.

Access a suite of downloadable resources and refresher learning bursts upon completion of the course.

Certificates are issued promptly.

We never cancel a course - enrol with confidence.

Secure your place now and give your organisation a competitive edge

Course overview

This course will guide you through the key elements of an ISMS, equipping you with the knowledge to strengthen your organisation’s approach to information security responsibilities and managing risk.

You will learn how to:

  • Understand the structure and requirements of an ISMS in alignment with ISO/IEC 27001:2022 and its relationship with ISO/IEC 27002:2022
  • Identify and evaluate the application of Information Security controls from ISO/IEC 27002:2022, considering an organisation’s threat and risk environment, including:
    • Organisational controls
    • People controls
    • Physical controls
    • Technological controls
  • Apply the ISO/IEC 27001 and 27002 standards to design and assess ISMS controls and processes within an organisational context.

This course is delivered as a single 3-day module covering the requirements of ISO/IEC 27001:2022. This course can be joined to an additional module: Becoming a Skilled Lead Internal/External Auditor, where participants learn how to conduct management systems audits in accordance with ISO 19011:2018 Guidelines for Auditing Management Systems.

To complete these modules together, see our Information Security Management Systems Lead Auditor course.

Timetable

Day 1 – Wednesday 

Information security management systems 

  • Introduction to information security 
  • Context of information security 
  • Information security management systems requirements 
  • Risk-based approach to information security 
  • Structure of information security controls and control attributes. 

Day 2 – Thursday 

Information security controls 

  • Information security controls – organisational, people, physical, technological
  • Information classification 
  • Documentation requirements of an information security management system. 

Day 3 – Friday 

Application of information security management systems  

  • Statement of applicability 
  • Information security audit scenarios 
  • Course review. 

Upon successful completion of the course, you will receive a Certificate of Attainment with one Exemplar Global competency:

  • Exemplar Global IS Auditing Information Security management systems

If you also complete our Becoming a Skilled Lead Internal/External Auditor course, you may also be eligible to complete the BSBSS00128 Lead Auditor Skill Set to attain four Nationally Recognised Training Units of Competency.

There are no prerequisites for this course.

You will complete a series of workshops during the course, which form part of the assessment. Upon the completion of each module, there is a short multiple-choice certification exam. You will receive continual assistance and feedback from the facilitator.

You should attend if you:

  • Are looking to conduct internal audits for information security management systems
  • Are developing or improving security measures for an information security management system
  • Hold responsibility for auditing or managing information security within your organisation 
  • Want to formalise your existing experience with a recognised qualification. 

A business background is preferred; however, prior experience in auditing and management systems is not essential.

To become a registered third-party auditor under the Exemplar Global scheme, you’ll need this course plus the units of competency awarded in our Becoming a Skilled Lead Internal/External Auditor course – Exemplar Global AU26 Auditing management systems and Exemplar Global TL26 Lead audit teams.

Visit the Exemplar Global website for full certification requirements and current fees.   

If you wish to obtain the four nationally recognised training units, you’ll need to complete the Becoming a Skilled Lead Internal/External Auditor course and undertake the additional assessment.

Expand your qualifications with the following courses: 

During the Information Security Management Systems training week:

Training available in a separate week: 

If you’re looking for a foundation-level understanding of ISO standards and auditing skills, check out our library of eLearns, which includes our self-paced 45-minute Introduction to ISO/IEC 27001 module.  

Price

The price of this course is $1,650 GST exempt.

Discounts for multiple attendees are available – please contact us to find out what discounts can be applied.

How to enrol

We offer an easy, streamlined enrolment process – you can either enrol directly into your course online or call us on 1300 95 96 92 to enrol over the phone.

How to pay

We offer a variety of payment methods:

  • Bank transfer
  • Credit card
  • Payment plans.

Payment plans

We can arrange flexible payment plans on an individual basis. Please be aware that your certificate will be held until full payment has been received.

Public – Virtual/Online

This course is delivered online via our virtual training platform. Our virtual courses are available to participants in Australia and New Zealand. They provide the same premium learning experience as our face-to-face sessions, with the added convenience of online learning. The virtual platform mimics in-person learning and aims to be engaging and interactive, with real-time group exercises, Q&A sessions, and online assessments. No matter your location, you can benefit from our expert-led training and become proficient in understanding the requirements of an information security management system.

Please note: Due to licensing restrictions, our virtual courses are open to participants from Australia and NZ only.

In-house – Face-to-face or virtual

In-house training can provide a cost-effective training solution for organisations with a number of staff who require training. We can also customise a course to suit your own individual needs, and include your own audit documentation. Call us on 1300 95 96 92 or complete the form below to request a quote. 

Request an In-house quote

Training Course Locations

Course Dates

Sort Location Start Finish Duration
Virtual - AEST (AUST & NZ participants only) Wed 09 Sep 2026 Fri 11 Sep 2026 3 Days Enrol now

There are no search results in your chosen search.
Register and we'll be in touch when courses are available.

Register Now

FAQs

Do I need prior experience in information security to attend this course?

No. A business background is helpful, but the course is designed to support participants with varying levels of experience. You’ll be guided through ISMS concepts, control implementation and risk management principles step-by-step.

What roles is this course suited for?

This course is well-suited to professionals involved in maintaining the security of organisational information. If you contribute to developing ISMS documentation, support a risk treatment plan, or work with key personnel and senior management on security-related decisions, this course will be of benefit.

It’s also useful for those managing day-to-day ISMS activities, conducting internal audits, overseeing information security programs, or contributing to broader risk processes across the organisation. IT teams and cyber security practitioners will also gain practical insights they can apply immediately.

Is ISO 27001 mandatory for businesses?

ISO 27001 isn’t mandated by regulation, but it is widely recognised across the industry as proof that an organisation manages information security in a structured and reliable way. It demonstrates that you have clear procedures in place to identify and respond to security threats, protect information assets and maintain consistent practices across the business.

Some organisations may expect suppliers to hold ISO 27001 certification as part of their procurement requirements, particularly in sectors where trust and data protection are a priority.

What is the difference between ISO 27002:2013 and 2022?

ISO 27002:2013 and ISO 27002:2022 share the same purpose, but the 2022 update introduces a cleaner structure and modernised controls. The new version reduces the number of controls, groups them into fewer categories, and adds new controls to address today’s security threats, including cloud use, data leakage and updated procedures.

How will this course help my organisation manage growing security threats?

The course gives you a practical way to understand current risk trends and respond to them with clearer, more consistent security practices. You’ll learn how to assess threats, map them to suitable controls and develop a risk treatment plan that supports your organisation’s priorities.

You’ll also gain the skills to identify ISMS issues early and build a continual improvement cycle into your security processes. This helps your organisation adjust to new challenges, strengthen procedures over time, and stay ahead as security threats evolve.

Can't find course dates in your city?

Register and we'll be in touch when courses are available

Register Now

What our students say about our courses

“The virtual classroom coupled with an enthusiastic trainer made the course easy to run through and as good as any face-to-face courses I have ever attended.”

“Honestly thought it was gonna be boring. I was very wrong! Very engaging and informative. Loved all 5 days and will be back for more courses!”

“Let’s be honest – ISO standards aren’t exactly edge-of-your-seat material. But this course proved that with the right coach, even clauses and compliance can be compelling! Packed with real-world examples, well-paced sessions, and just the right amount of workshops, it was surprisingly enjoyable. Highly recommended!”

“It was clearly evident that the lead auditor trainer had significant industry-related experience in auditing. He was able to keep the class fully engaged with personal interaction and reinforce learnings. Getting full copies of the standards was amazing, the catering and the training location in Brisbane was perfect.”

“The trainer’s experience and real-life examples gave great context to the course material. The 5 days allowed the material to be digested in a way that was not overwhelming. I’d definitely recommend the course to others.”

Need help finding a course?

Speak directly with a member of the RTP team to decide which course is right for you.

×