ISO 27001 Lead Implementer
A two-day working session for whoever has been handed the ISO 27001 project. Implementation fails in predictable places: a scope drawn too wide to defend, a risk methodology invented on the spot and abandoned by the second cycle, a document set written for an auditor rather than for the people doing the work, and a certification date agreed before anyone counted the effort. This programme is organised around avoiding exactly those.
Participants build the artefacts rather than review them. Over the two days each team produces a scope statement, a risk assessment methodology, a populated risk register, a control selection rationale, a draft Statement of Applicability and an implementation roadmap with a defensible timeline, all against a case organisation and then transferred to their own. This is a competency workshop rather than a certified lead implementer qualification. It pairs directly with the internal auditor programme, and organisations that want the work done alongside them rather than taught should look at the vCISO and certification readiness services instead.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Project Framing
Objectives, the case organisation, and each participant's real implementation context, constraints and deadline.
Day 1, 9:15 AM - 10:30 AM
Getting the Mandate Right
Why implementations stall, and how many of the causes are governance rather than technical. Securing leadership commitment under clause 5 in a form that survives budget season. Business case and drivers: tender eligibility, customer security review, group mandate, regulatory pressure. Assembling the project team and defining roles. Understanding the organisation and interested parties under clause 4, including customers, regulators, group entities and suppliers, and turning that into requirements.
Day 1, 10:30 AM - 10:45 AM
Break
Day 1, 10:45 AM - 12:15 PM
Scoping the ISMS
The decision that determines cost, timeline and credibility. Scoping by business unit, service, location, or the whole organisation. Interfaces and dependencies, including shared services, group IT and outsourced functions. Handling cloud and third-party processing inside a scope. Writing a scope statement an auditor will accept and a customer will find meaningful. Workshop: teams draft and then defend a scope statement under challenge, which is where most first attempts fall apart.
Day 1, 12:15 PM - 1:15 PM
Lunch
Day 1, 1:15 PM - 2:45 PM
Risk Assessment Methodology
Designing a methodology you can repeat next year with the same results, which is the actual test. Asset-based versus scenario-based approaches. Identifying risks, owners, and the consequence and likelihood scales. Qualitative and semi-quantitative scoring. Setting risk acceptance criteria that the board has actually agreed. Documenting the methodology under clause 6.1.2 and aligning with ISO 27005. Workshop: teams design and document a methodology for the case organisation.
Day 1, 2:45 PM - 3:00 PM
Break
Day 1, 3:00 PM - 4:45 PM
Running the Risk Assessment
Asset and information inventory at a workable granularity. Threat and vulnerability identification. Populating the risk register and assigning owners who can actually accept a risk. Evaluating against criteria and prioritising. Risk treatment options: modify, retain, avoid, share. Workshop: teams complete a risk assessment for the case organisation and produce a prioritised register.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Day 2, 9:15 AM - 10:45 AM
Control Selection and the Statement of Applicability
Selecting controls from Annex A against treatment decisions, and adding controls from outside Annex A where the risk requires it. Justifying inclusion and exclusion. Building the Statement of Applicability as a working document rather than a compliance artefact. Mapping controls already in place, which in most organisations is more than the team expects. Workshop: teams produce a draft Statement of Applicability from their risk register.
Day 2, 10:45 AM - 11:00 AM
Break
Day 2, 11:00 AM - 12:30 PM
Documentation and Implementation
The documented information clause 7.5 actually requires, and the far larger set organisations write out of anxiety. Policy hierarchy: policy, standard, procedure, record. Writing for the person who has to follow it. Version control, approval and availability. Implementing organisational, people, physical and technological controls in a sequence that produces evidence early. Competence and awareness under clause 7.2 and 7.3, and using the training catalogue to discharge it.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 2:45 PM
Operating the ISMS and Measuring It
Turning the standard into a recurring calendar: risk review, internal audit, management review, corrective action, awareness cycle and supplier review. Monitoring and measurement under clause 9.1, and choosing metrics that mean something rather than metrics that are easy to collect. Management review inputs and outputs under clause 9.3. Nonconformity and continual improvement under clause 10. Incident management and its interface with the PDPA breach notification duty and, for NCII entities, the Cyber Security Act 2024.
Day 2, 2:45 PM - 3:00 PM
Break
Day 2, 3:00 PM - 4:15 PM
The Certification Roadmap
Selecting a certification body and what accreditation means. Stage 1 and stage 2, surveillance and recertification. Building a realistic timeline from mandate to certificate for a Malaysian organisation of the participants' size, with the effort estimate that supports it. What must exist before stage 1, including a completed internal audit and management review. Preparing people for the audit. What certification auditors most often raise, and closing those gaps in advance.
Day 2, 4:15 PM - 4:45 PM
Own-Organisation Roadmap
Participants transfer the work from the case organisation to their own: a scope statement, the top risks, the control gaps, and a phased roadmap with dates and owners they can take back to their sponsor.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Secure a leadership mandate and define interested-party requirements that hold up under audit
- Draft and defend an ISMS scope statement, and explain how scope drives cost and timeline
- Design a repeatable risk assessment methodology and run an assessment to a prioritised register
- Select controls against treatment decisions and produce a defensible Statement of Applicability
- Build the documentation set clause 7.5 requires without writing the set nobody reads
- Operate the ISMS as a recurring calendar with meaningful measurement and management review
- Build a realistic certification roadmap with effort, sequence and owners
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Advanced. Suitable for ISMS project leads, information security and IT managers, compliance and risk officers, and consultants. ISO 27001 awareness or equivalent working knowledge is assumed.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A completed artefact set for the case organisation comprising scope statement, risk methodology, risk register, draft Statement of Applicability and implementation roadmap, plus a transferred roadmap for the participant's own organisation
Certificate Certificate of Completion issued to all participants upon full attendance