SCC accredited ISO 27001 and CyberSecure Canada certification. Get an instant estimate and manage your application online.
Disclaimer
Complade provides these resources as a free service to enhance understanding of ISO 27001 and CyberSecure Canada. These resources are not a substitute for tailored implementation guidance. For customized support, we recommend working with qualified ISO consultants.
Complade is accredited by the Standards Council of Canada to provide ISO/IEC 27001 and CyberSecure Canada certification services. To protect impartiality, Complade does not provide consulting, implementation, or internal audit services.
These free educational resources introduce the terminology and requirements of ISO/IEC 27001. They are general information only and are not implementation guidance tailored to a specific organization.
For questions about these resources, contact your Complade account manager or email info@complade.com.
This pathway is designed to guide individuals from no prior experience to becoming certified implementers and auditors of ISO 27001.
Prerequisite:
Basic understanding of information security.
Complade is accredited under ISO 17021-1 to certify organizations, not individuals.
To certify individuals, organizations must comply with ISO 17024. The following options are available for individual certification in ISO 27001 implementation or auditing:
ISO 17024-accredited ISO27001 foundation exam (Option 1 - Option 2)
ISO 17024-accredited ISO 27005 certification (Option 1)
ISO 17024-accredited internal auditor certification (Option 1)
ISO 17024-accredited Lead auditor certification (Option 1
Below videos are intended to be used alongside the standard. Please purchase the standard first.
The videos are presented in sequence and should be watched in order.
If you have questions or comments, please email us at info@complade.com.
Overview of frameworks such as ISO, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and System and Organization Controls 2 (SOC 2)
Clause 4.1
Mandatory Input
Brief Implementation
Apply PESTLE (Political, Economic, Social, Technological, Legal, and Environmental) for External: Legal, Tech, Threat, Market) and SWOT (Internal: Tech Stack, Culture, Resources).
Document internal information flows and dependencies.
Review context at least annually during Management Reviews.
What Auditors Ask For
"How did you identify internal/external issues (and parties) impacting your ISMS outcomes?"
"How do tech trends or regulatory changes feed into your risk management?"
Audit Evidence to Show
Document: Context Matrix, PESTLE & SWOT Reports.
Records: Management Review Minutes (Clause 9.3) reviewing context.
Diagrams: System Architecture & Data Flow Diagrams.
🗣️ Example Auditee Response:
"We systematically review internal and external context using our Context Matrix (combining PESTLE & SWOT). External drivers like privacy laws and cloud security trends are mapped against internal factors like tech stack and staffing. These directly feed our Risk Asses
Clause 4.2
Mandatory Input
Super Brief Implementation
Map external stakeholders (Regulators, Clients, Suppliers) and internal stakeholders (Board, Staff, IT).
List mandatory legal/regulatory requirements and voluntary contractual SLAs.
Account for adversary interests (e.g., threat actors trying to exploit weaknesses).
What Auditors Ask For
"Who are your key interested parties and what security requirements do they have?"
"How do you ensure customer contractual security commitments are met?"
Audit Evidence to Show
Document: Interested Parties Matrix / Stakeholder Register.
Contracts: Customer SLAs, NDAs, Supplier Security Agreements.
Compliance: Legal & Regulatory Requirements Register.
🗣️ Example Auditee Response:
"We maintain an Interested Parties Matrix detailing internal and external stakeholders. Legal obligations are tracked in our Compliance Register, while customer expectations are pulled from MSAs and SLAs, directly translating into controls in our Statement of Applicability."
Clause 4.3
Mandatory Document
Super Brief Implementation
Define physical (offices, data centers), logical (cloud, networks), and organizational boundaries.
Include all supporting functions (HR, IT, Procurement) and account for outsourced dependencies.
Obtain formal top management sign-off on the scope document.
What Auditors Ask For
"What are the precise physical and technical boundaries of your ISMS?"
"Are any business units or physical sites excluded, and why?"
Audit Evidence to Show
Document: Approved ISMS Scope Document.
Controls: Statement of Applicability (SoA).
Diagrams: Network Topology & Physical Office Locations.
🗣️ Example Auditee Response:
"Our ISMS Scope Document is approved by leadership and covers all SaaS production infrastructure, corporate offices, and core operational units. All interfaces, dependencies, and third-party interactions are mapped, and 100% of this scope is covered in our SoA."
Clause 5.1
Executive Pillar
Super Brief Implementation
Top management must demonstrate active ownership (not delegation without oversight).
Ensure security policy and objectives align with business strategic direction.
Integrate ISMS requirements directly into standard business processes.
Provide adequate resources (budget, staffing, tech) and direct/support personnel.
What Auditors Ask For
"How does top management demonstrate active commitment to the ISMS?"
"How do you ensure information security is integrated into business operations?"
Auditor interview request directly with C-suite / executive management.
Audit Evidence to Show
Executive Minutes: Board/Executive meeting minutes approving security budget & policy.
Reviews: Signed Management Review Minutes (Clause 9.3).
Resources: Approved annual security operational and capital budgets.
🗣️ Ideal Auditee Response Script:
"Top management demonstrates commitment by establishing security objectives aligned with corporate goals, approving dedicated security budgets, leading scheduled Management Reviews, and actively communicating security importance across all departments."
Clause 5.2
Mandatory Policy
Super Brief Implementation
Draft a high-level Information Security Policy appropriate to the organization's purpose.
Include explicit commitments to satisfy applicable requirements and continual improvement.
Provide a framework for establishing information security objectives.
Formally approve, publish, communicate to staff, and make available to interested parties.
What Auditors Ask For
"Show me your overarching Information Security Policy and evidence of executive sign-off."
"How is the policy communicated to internal staff and external interested parties?"
Audit Evidence to Show
Policy Document: Executive-approved Information Security Policy with version history.
Communication: Intranet/portal publication, email broadcast records, LMS onboarding sign-offs.
External Sharing: Public website policy summary or vendor trust center link.
🗣️ Ideal Auditee Response Script:
"Our Information Security Policy is formally approved by our CEO. It establishes our commitment to compliance and continual improvement while providing the framework for our security objectives. It is published on our intranet, required for employee onboarding, and accessible externally via our Trust Portal."
Clause 5.3
Governance Structure
Super Brief Implementation
Assign and communicate responsibilities and authorities for all security-relevant roles.
Assign explicit responsibility for ensuring ISMS conforms to ISO 27001 requirements.
Assign explicit responsibility for reporting ISMS performance directly to top management (e.g., CISO / Security Lead).
What Auditors Ask For
"Who is specifically responsible for ensuring ISMS compliance and reporting performance to leadership?"
"How are security responsibilities defined and communicated across different departments?"
Audit Evidence to Show
Org Chart & RACI: ISMS Organizational Chart, RACI Matrix.
Job Descriptions: Formal Job Descriptions with security responsibilities included.
Appointment Letters: Formal designation records for CISO / ISO / Security Steering Committee.
🗣️ Ideal Auditee Response Script:
"Security roles and authorities are defined in our ISMS RACI Matrix and job descriptions. Our CISO holds explicit authority to maintain ISO 27001 compliance and reports performance directly to top management during quarterly steering committee meetings and annual Management Reviews."
Clauses 6.1.1, 6.1.2, 6.1.3
Mandatory Framework
Super Brief Implementation
6.1.1: Address context risks/opportunities to ensure ISMS delivers intended outcomes.
6.1.2: Define repeatable risk assessment criteria (impact, likelihood, CIA, risk owner assigned).
6.1.3: Select treatment options (Avoid, Modify, Share, Retain), build SoA (justifying inclusions/exclusions), and get risk owner sign-off.
What Auditors Ask For
"Show me your risk assessment methodology and how risk levels are calculated."
"How do you justify excluded Annex A controls in your Statement of Applicability?"
Audit Evidence to Show
Methodology: Risk Assessment & Treatment Policy.
Register: Risk Register with Risk Owner Sign-offs.
SoA: Statement of Applicability with detailed inclusion/exclusion justifications.
Plan: Approved Risk Treatment Plan (RTP).
🗣️ Ideal Auditee Response Script:
"We follow a 5x5 impact/likelihood risk methodology. Every identified risk has an assigned Risk Owner. Treatment actions feed our Risk Treatment Plan, and all controls—standard, sector-specific, or custom—are documented with clear rationale in our Statement of Applicability."
lauses 6.2 & 6.3
Mandatory Targets
Super Brief Implementation
6.2: Set SMART, measurable security objectives aligned with Security Policy. Map What, Who, Resources, When, and Evaluation metrics.
6.3: Execute changes to the ISMS in a planned manner, evaluating potential security impacts and role re-assignments.
What Auditors Ask For
"How do you measure progress against your security objectives?"
"Show me how a major organizational change was evaluated for security risks before execution."
Audit Evidence to Show
Objectives: Documented Objectives Tracker & Action Plans.
Change Control: Change Management Procedure & Request Forms.
Reviews: Pre-change risk evaluations and post-implementation sign-offs.
🗣️ Ideal Auditee Response Script:
"Our security objectives are SMART, assigned to specific owners with dedicated budgets, and tracked quarterly. Major ISMS modifications go through our formal Change Management process, assessing risk impacts before leadership sign-off."
Clauses 7.1 & 7.2
Operational Support
Super Brief Implementation
7.1: Determine & allocate budget, staffing, infrastructure, and tools needed for ISMS.
7.2: Define role competency requirements, evaluate skills, conduct training/hiring, and evaluate training effectiveness.
What Auditors Ask For
"How do you determine that personnel in security-affecting roles are competent?"
"Show me how you measure the effectiveness of security training programs."
Audit Evidence to Show
Resources: Approved Security Budgets & Staffing Headcount Plans.
Competence: Job Descriptions, Resumes, Industry Certifications (CISSP, CISM, ISO LA).
Training: Training Plans, Attendance Logs, Quiz Results, Post-Training Evaluations.
🗣️ Ideal Auditee Response Script:
"We map role competencies in job descriptions. Qualifications are verified via certifications and CVs upon hire. Training needs are executed annually, and effectiveness is verified via post-training quizzes and manager performance sign-offs."
Clauses 7.3 & 7.4
Culture & Outreach
Super Brief Implementation
7.3: Train staff/contractors on Policy awareness, personal security contribution, and non-compliance consequences.
7.4: Build a Communication Matrix covering What, When, With Whom, How, and Who communicates.
What Auditors Ask For
"Random staff sample: Are you aware of the security policy and where to find it?"
"Who is authorized to communicate externally during a security breach?"
Audit Evidence to Show
Awareness: LMS Onboarding Logs, Phishing Simulation Results, Policy Sign-offs.
Communication: ISMS Communication Plan, Authorized Spokesperson Matrix.
🗣️ Ideal Auditee Response Script:
"Awareness starts during onboarding and continues via monthly security tips and phishing tests. Our Communication Matrix specifies authorized channels and roles for routine updates as well as crisis/incident alerts."
Clauses 7.5.1, 7.5.2, 7.5.3
Mandatory Governance
Super Brief Implementation
7.5.1: Maintain all mandatory ISO documents plus necessary operational SOPs.
7.5.2: Enforce standard document metadata (Title, Author, Date, Version, ID) and approval workflows.
7.5.3: Protect document access (RBAC), legibility, retention schedules, and secure disposal.
What Auditors Ask For
"How do you ensure only approved document versions are available to staff?"
"Show me your retention schedule and secure disposal logs for expired records."
Audit Evidence to Show
Policy: Document Control & Retention Procedure.
Registry: Master Document Index with Version History.
Controls: System Access Control Lists (RBAC) & Disposal Certificates.
🗣️ Ideal Auditee Response Script:
"Documents are controlled in a centralized library with strict RBAC permissions. Templates enforce standardized headers, version logs, and management sign-offs. Outdated documents are archived per our retention schedule."
Clause 8.1
Execution Pillar
Super Brief Implementation
Establish operational process criteria (SOPs, patch baselines, access workflows).
Govern planned operational changes and mitigate unintended changes.
Control outsourced processes (contracts, SLAs, right-to-audit, vendor reviews).
What Auditors Ask For
"Show evidence that daily security procedures operate as specified."
"How do you monitor third-party suppliers to ensure they meet security requirements?"
Audit Evidence to Show
Operations: System Logs, Ticket Sign-offs, Backup Verification Reports.
Changes: CAB Meeting Minutes & Change Request Tickets.
Suppliers: Vendor Security Risk Assessments, SOC 2 Reports, Contracts with SLAs.
🗣️ Ideal Auditee Response Script:
"Operational controls are driven by approved SOPs and logged in ticketing systems. Changes undergo CAB risk evaluation. Outsourced vendors are vetted annually, bound by contractual security terms, and monitored via SOC reports."
Clauses 8.2 & 8.3
Risk Cycle
Super Brief Implementation
8.2: Conduct risk assessments at planned intervals (annually) or when major changes/incidents occur.
8.3: Execute treatment actions in the Risk Treatment Plan (RTP) and retain evidence of outcomes.
What Auditors Ask For
"Show me the latest completed risk assessment report and execution schedule."
"What evidence shows that planned risk treatments were actually implemented?"
Audit Evidence to Show
Assessment: Completed Risk Assessment Reports & Updated Risk Registers.
Treatment: Live Risk Treatment Plan (RTP) progress logs.
Sign-off: Formal Risk Owner Residual Risk Acceptance Sign-offs.
🗣️ Ideal Auditee Response Script:
"We run scheduled annual risk assessments, as well as ad-hoc assessments triggered by system changes. Treatment tasks are tracked in our active RTP, and technical implementation evidence is verified by Risk Owners before sign-off."
Clause 9.1
Metrics & Assurance
Super Brief Implementation
Define "information needs" and track Performance Metrics (% tasks completed) & Effectiveness Metrics (impact on security goals).
Assign clear collector vs. evaluator roles to ensure valid, reproducible results.
What Auditors Ask For
"How do you measure whether security controls are actually performing effectively?"
"Show me your security KPI dashboard and trend reports."
Audit Evidence to Show
Dashboard: ISMS Monitoring & Measurement Framework / KPI Tracker.
Logs: Incident Trend Reports, SLA Compliance Reports, Patch Metrics.
🗣️ Ideal Auditee Response Script:
"We track performance metrics (e.g., SLA achievement, patch rates) and effectiveness metrics (e.g., incident response times, phishing rates) in our KPI Dashboard. These results feed directly into our Management Reviews."
Clauses 9.2 & 9.3
Governance Loop
Super Brief Implementation
9.2: Conduct risk-based internal audits using independent, competent auditors. Track corrective action plans.
9.3: Hold executive management reviews at planned intervals covering all mandatory inputs (a-g) and recording decision outputs.
What Auditors Ask For
"Show me your multi-year internal audit programme and latest audit report."
"Provide signed meeting minutes demonstrating top management participation in management reviews."
Audit Evidence to Show
Audit: Internal Audit Schedule, Audit Plans, Audit Reports, Auditor Independence Certificates.
Management Review: Signed Minutes, Agendas, Action Item Trackers.
🗣️ Ideal Auditee Response Script:
"Our multi-year internal audit programme uses independent auditors to evaluate ISO 27001 compliance. Findings are reported to top management during scheduled Management Reviews, where decisions on resources and improvements are formally recorded."
lauses 10.1 & 10.2
Evolution & Remediation
Super Brief Implementation
10.1: Continuously enhance ISMS suitability, adequacy, and effectiveness proactively.
10.2 (Immediate): Take swift short-term Correction (containment) when nonconformities occur.
10.2 (Long-term): Perform 5-Whys/Fishbone Root Cause Analysis (RCA), deploy Corrective Action Plans (CAP), and verify long-term effectiveness.
What Auditors Ask For
"How do you differentiate between an immediate correction and long-term corrective action?"
"Show me evidence of an impartial review verifying a corrective action prevented recurrence."
Audit Evidence to Show
Improvement: Continual Improvement Register / Opportunity Log.
Nonconformity: Nonconformity Log (NCR), Root Cause Analysis (RCA) Worksheets (5-Whys).
Verification: Corrective Action Plans (CAP) & Post-Remediation Effectiveness Verification Records.
🗣️ Ideal Auditee Response Script:
"When a nonconformity is logged, we apply immediate containment first. We then perform a 5-Whys root-cause analysis to deploy a long-term Corrective Action Plan. After 60–90 days, we conduct an impartial effectiveness evaluation to confirm the root cause was eliminated."