ISMS Academy: ISO 27001 lessons for first-time certification
Ten lessons in three tracks: ISMS foundations, Australia and the Essential Eight, and choosing and running a platform. Each takes about 3 minutes and links to the terms and tools it mentions.
Track A: ISMS foundations
What ISO 27001 asks for and how the pieces fit.
What an ISMS is and what ISO 27001 certifies
An information security management system in plain terms: what ISO/IEC 27001:2022 requires, what a certificate says, and what a compliance platform can and cannot do.
Lesson 02 · 3 min readISO 27001 clauses 4 to 10, one at a time
The seven requirement clauses of ISO/IEC 27001:2022 in plain language, what evidence an auditor expects for each, and which ones compliance platforms describe.
Lesson 03 · 3 min readRisk assessment and risk treatment in ISO 27001
How ISO 27001 risk assessment and treatment work: a repeatable method, a risk register, four treatment options, owners and the link to the Statement of Applicability.
Lesson 04 · 3 min readThe Statement of Applicability, explained
What an ISO 27001 Statement of Applicability contains, how it links risks to Annex A controls, how auditors use it, and how to keep it current.
Track B: Australia and the Essential Eight
The ASD baseline and how it sits next to ISO 27001.
The Essential Eight strategies and the evidence behind them
Each of the ASD Essential Eight strategies in plain terms, with the kind of evidence an assessor or an Australian customer is likely to ask to see.
Lesson 06 · 3 min readChoosing an Essential Eight maturity target
How the ASD Essential Eight maturity model works, why it was introduced in June 2017 and updated since, and how to choose and evidence a maturity target.
Lesson 07 · 3 min readRunning ISO 27001 and the Essential Eight together
How an Australian-facing company can run ISO 27001 and the ASD Essential Eight in one program: shared evidence, separate outcomes, and what to ask a platform.
Track C: Choosing and running a platform
The audit, the second framework and who does the work.
The ISO 27001 certification audit, from stage 1 to surveillance
How an ISO 27001 certification audit usually runs: choosing a certification body, stage 1 and stage 2, findings, the certificate cycle, and what platforms offer.
Lesson 09 · 3 min readAdding a second framework: cross-mapping in practice
What happens when you add SOC 2, the Essential Eight or ISO 42001 to an ISO 27001 program, how cross-mapping works, and how to read vendor framework counts.
Lesson 10 · 3 min readExpert-led, partner-led or self-serve: who does the ISMS work
Three service models behind ISO 27001 platforms: a dedicated in-house expert, a partner network, or support plus AI agents. What each vendor describes and how to choose.