Skip to main content
Aegentra

Official PECB training partner · Partner ID 232290

ISO 27001 Foundation Course Australia

Understand how an organisation protects its information through an information security management system—not just security software. This beginner-friendly PECB course introduces ISO/IEC 27001:2022, information-security risks, responsibilities and controls. Choose independent Self-Study or recorded eLearning, with the official PECB examination included. Study online at your own pace and build the knowledge to contribute to an ISMS team.

Prefer private teaching? Explore one-to-one training.

  • No formal prerequisites
  • Online, self-paced learning
  • Official PECB exam included
  • ISO/IEC 27001:2022

Delivered online through myPECB, with Aegentra Academy assistance for enrolment, access and examination-voucher enquiries.

On this page

Choose how you want to learn

Both options follow the official PECB ISO/IEC 27001 Foundation course and lead to the same Foundation certificate application process. The difference is how you study: work independently through the materials with Self-Study, or choose eLearning for recorded explanations alongside the materials. Neither self-paced option includes scheduled live teaching.

Your learning format

Included with either option

Your enrolment includes the official Foundation course materials, 12 months of myPECB access from purchase, the official examination voucher and the initial Foundation certificate application fee. The initial examination and one retake must both be completed within 12 months of purchase, subject to PECB conditions. Aegentra Academy assists with enrolment, access and voucher enquiries.

Important dates

For both Self-Study and eLearning, your 12-month myPECB access starts when you purchase the course. The examination voucher covers the initial attempt and one retake if needed; both attempts must be completed within 12 months of purchase. First login or the first examination attempt does not restart that period. The certificate application also has a separate 12-month-from-purchase deadline.

Read the separate certificate deadline

Need an employer invoice or help choosing a format? Contact Aegentra Academy.

Personal teaching · Build your foundations

One-to-one ISO 27001 Foundation training

Learn privately with Dr Harbir Singh, a PECB Certified Trainer for this course. Build your understanding of ISO 27001 through explanation, discussion and questions at each stage.

A$1,299 + GSTA$1,428.90 including Australian GST.

Flexible one-to-one teaching
Two days of private teaching. Weekday and weekend options are available. Teaching dates and session times are mutually agreed before booking confirmation.
Official PECB eLearning
Recorded PECB learning material alongside the live teaching, so you can revisit concepts within your agreed access period.
One month of Labs practice included
One month of Aegentra Labs access for ISO 27001 Foundation, with unlimited attempts at the available practice questions during your access period. This is included in the private package and is separate from the optional A$89 + GST add-on for 12 months.

The Foundation package does not include a separate one-to-one consultant session.

Aegentra Labs is independently authored supplementary practice, not official PECB examination questions. Unlimited attempts apply to Labs practice, not the PECB examination.

Before payment, we confirm your assigned instructor and applicable trainer authorisation, eLearning and Labs access arrangements, examination arrangements and booking terms. This is private online training, not a scheduled group classroom course.

Why study through Aegentra Academy?

Aegentra Academy is a PECB training partner, with a public partnership record you can check before enrolling. PECB supplies the official course and determines the examination and certificate requirements. Aegentra maintains the published learning options and provides assistance with enrolment, course access and examination-voucher enquiries.

You can also inspect Aegentra's own learning examples and free study resources before you buy. They explain how course concepts connect to responsibilities, risk decisions and evidence in an organisation. These resources supplement the official course; they are not presented as PECB-authored material or a substitute for the standard.

Is ISO 27001 Foundation right for you?

Foundation is designed for people who need to understand an ISMS before taking on more specialised implementation or auditing work. It is a useful starting point for new governance, risk and compliance team members, IT professionals supporting security processes, project coordinators, managers and staff whose responsibilities sit inside an organisation's ISMS.

There are no formal prerequisites. You do not need programming or penetration-testing skills: the course concerns how information security is organised, managed and improved. Familiarity with everyday business processes and information handling will help you relate the concepts to your work.

Already responsible for designing an entire ISMS or leading audits? Compare the Lead Implementer and Lead Auditor courses below. Foundation develops introductory understanding; it does not by itself establish the experience or competence required to lead every implementation or audit engagement.

What you will learn about ISO 27001

An information security management system is the combination of responsibilities, processes, decisions and evidence an organisation uses to manage information-security risk. It connects business needs with appropriate protections and regular review. ISO/IEC 27001 sets requirements for that system; it is not simply a list of security products to install.

Understand the information you need to protect

Explore confidentiality, integrity and availability through everyday business examples. Recognise why information can need protection whether it is held in a cloud service, a document, a conversation or a physical record.

Understand how an ISMS is organised

Learn how organisational context, interested parties, scope, leadership and policy shape the management system. See why clear ownership and objectives matter before an organisation starts producing large numbers of security documents.

Connect risk decisions to controls

Learn the relationship between risk assessment, risk treatment, security controls and the Statement of Applicability. Understand that applicability decisions depend on the organisation's risks and requirements, rather than treating every reference control as an identical task for every business.

Understand operation, review and improvement

Examine how competence, communication, documented information and operating processes support the ISMS. Learn the purpose of monitoring, internal audit, management review and corrective action, and why a written policy alone is not evidence that a process works.

Course structure and study time

PECB publishes a two-day Foundation agenda: an introduction to ISMS concepts, followed by management-system requirements and the certificate examination. Self-Study and recorded eLearning let you work through the content on your own schedule. Allow additional time to revisit unfamiliar concepts, practise and prepare for the examination.

PECB's published course information describes more than 200 pages of material and an attendance attestation worth 14 CPD credits, subject to its completion conditions. CPD credits, recorded-video length, independent study time and the examination duration are different measures.

Try a Foundation lesson: when a sharing link becomes a security risk

An Aegentra-authored learning example. No registration required.

Imagine a small Australian professional-services business sharing client reports through a cloud document library. A team member creates a link that can be forwarded outside the intended recipient group. Nothing has been hacked, but confidential information could reach the wrong person.

A purely technical response might be to change the sharing setting. An ISMS asks a wider set of questions: which information needs protection, who is responsible for it, what level of risk is acceptable, which safeguards are appropriate, and how will the organisation know those safeguards are working?

Information and business activity

Client reports shared with approved recipients

Risk

An unrestricted link exposes a report to someone who should not receive it

Possible treatment

Restrict the permitted sharing method and establish appropriate approval and access-review arrangements

Responsibility

A nominated owner approves the process and reviews whether it remains suitable

Evidence

Relevant access settings, sharing records, approvals and completed reviews

The policy describes the expected behaviour. The control changes how sharing is managed. The evidence helps show whether the arrangement operates in practice. A risk register records the risk and treatment decision; a Statement of Applicability explains the necessary controls and the organisation's applicability decisions. Those documents have different purposes.

The lesson is not that every organisation must use this exact configuration. It is that information-security decisions need a business reason, an accountable owner and evidence of operation. That connection is central to understanding an ISMS.

Check your understanding

These optional questions were written by Aegentra for this example. They are not official, recalled or confidential PECB examination questions.

Question 1 — What is the clearest risk in this scenario?

  • A. The business has not created enough policy documents.
  • B. Someone outside the intended recipient group could obtain a client report.
  • C. The business is using a cloud service.
Show answer and explanation

Answer: B. The risk concerns an unwanted event and its effect on information. Using a cloud service is not, by itself, evidence that information is insecure.

Question 2 — Which item best shows whether the sharing process is operating?

  • A. A statement that the organisation takes security seriously.
  • B. An unused template for an approval form.
  • C. A sample of actual sharing approvals and completed access reviews.
Show answer and explanation

Answer: C. Completed records can show what happened in practice. A policy or blank template can describe an intention without demonstrating that the process was followed.

Question 3 — What should happen after a sharing restriction is introduced?

  • A. The responsible owner should check whether it works and remains suitable.
  • B. The risk can be ignored permanently.
  • C. The organisation automatically becomes ISO 27001 certified.
Show answer and explanation

Answer: A. A treatment decision needs follow-through. Changes in people, information or business activity may require the arrangement to be reviewed.

Understand the Foundation examination

The PECB ISO/IEC 27001 Foundation examination assesses your understanding of ISMS principles and requirements. It is a closed-book multiple-choice assessment, unlike the open-book format associated with some advanced PECB courses. Prepare to understand and apply the concepts rather than depend on looking up answers during the examination.

Questions

40 multiple-choice questions

Duration

One hour

Format

Closed-book

Passing score

70%

Coverage

Two competency domains: ISMS principles/concepts and the ISMS

First examination

Included with the course

Included retake

One retake if needed; initial attempt and retake within 12 months of purchase

The current handbook describes both stand-alone and scenario-based questions. Check PECB's current language, delivery, identity-verification and examination rules before booking. Any permitted accommodation or alternate arrangement must be confirmed with PECB; it is not guaranteed by this page.

What happens if you do not pass?

One free examination retake is included if needed. Both the initial attempt and the retake must be completed within 12 months of purchase. PECB's current general policy requires a 15-day wait before the first retake. Plan your first attempt early enough to leave time for revision, booking availability and the applicable deadline. The included retake is not an unlimited-resit offer.

Which certificate can you apply for?

After completing the required training, passing the examination and meeting PECB's application and ethics requirements, you can apply for the PECB Certificate Holder in ISO/IEC 27001:2022 Foundation credential. No professional-experience or management-system project-hour threshold applies to Foundation. PECB reviews the application and issues the certificate when its requirements are met.

This is a Foundation certificate for an individual. It is not a Lead Implementer or Lead Auditor credential, does not establish that you can lead any engagement without further development, and does not certify your employer's or customer's organisation to ISO 27001.

Certificate application and maintenance

PECB's current Foundation handbook gives Self-Study and eLearning candidates a certificate-application period of 12 months from purchase. For instructor-led training, it describes 12 months from course completion. This is a separate condition from access to learning materials and examination-retake eligibility. Check the current handbook and your package dates before booking late in the period.

Under PECB's current maintenance policy, Foundation holders are exempt from ongoing CPD reporting and Annual Maintenance Fees. Do not confuse that exemption with unlimited course access, an indefinitely valid examination voucher or the maintenance requirements of a later advanced credential.

Foundation, Lead Implementer or Lead Auditor?

Choose according to the work you need to understand or perform—not simply the most senior-sounding title. Foundation establishes the vocabulary and structure of an ISMS. The advanced courses focus on implementation or auditing and have their own examination and credential requirements.

Foundation

Understand ISMS concepts, requirements, responsibilities and the risk-based approach

You are new to ISO 27001 or contribute to an ISMS team

Lead Implementer

Develop an approach to planning, implementing, operating and improving an ISMS

Your work involves implementation leadership or substantial implementation responsibilities

Lead Auditor

Develop an approach to planning, conducting and reporting ISMS audits

Your work involves evaluating management systems and audit evidence

Foundation is not a compulsory prerequisite for the PECB Lead Implementer or Lead Auditor course. It can be a useful preparation step when the concepts are unfamiliar. Completing an advanced course and examination does not automatically remove the experience requirements for a particular professional credential tier.

Explore free Foundation study resources

Use these Aegentra-authored resources to connect the terminology to an example you can inspect. They are educational aids, not official PECB course materials, a licensed copy of the ISO standard or a ready-made ISMS for every organisation.

Clauses 4–10 study map ↗

See how context, leadership, planning, support, operation, performance evaluation and improvement fit together. Use the map to organise your notes instead of treating each clause as an isolated definition.

ISO 27001 terminology glossary ↗

Build your understanding of recurring terms such as risk owner, control, documented information and corrective action. Return to the glossary when a familiar word has a specific management-system meaning.

Worked risk-register example ↗

Follow the connection between information, an unwanted event, its consequences and a treatment decision. Notice how responsibility and review make the register useful beyond the initial assessment.

Statement of Applicability example ↗

Inspect how an organisation can record control applicability, reasons and implementation information. Compare its purpose with the risk register rather than treating the two documents as interchangeable.

Free practice in Aegentra Labs

Try the available Foundation practice questions and read the examination guide before deciding whether you need full preparation access. The free resources and paid Labs preparation are independently authored, separate from official PECB content and optional for course learners.

Buying for a team or studying outside Australia?

Online delivery lets colleagues study without travelling to a classroom. Contact Aegentra Academy about multiple learners, an employer invoice or a training requirement that needs separate scoping. Any instructor-led delivery is arranged and confirmed separately; this page does not advertise a guaranteed public classroom date or venue.

Learners outside Australia can enquire about the available format, examination language, billing arrangements and support needs. Confirm the arrangements that apply to you before purchasing rather than assuming every country, language or examination method has identical conditions.

Download the study resources

Questions before you enrol

Is ISO 27001 Foundation suitable for a complete beginner?

Yes. The PECB Foundation course has no formal prerequisites and introduces the main ISMS concepts and requirements. It is particularly relevant when you need to understand information-security responsibilities or contribute to an ISMS team without yet leading the whole system.

How much does ISO 27001 Foundation cost through Aegentra?

Self-Study is A$379 excluding GST, or A$416.90 including Australian GST. Recorded eLearning is A$399 excluding GST, or A$438.90 including Australian GST. Both include the official examination and the initial certificate application fee. Optional Labs preparation is priced separately.

What is the difference between Self-Study and eLearning?

Self-Study is independent learning from the official course materials. eLearning adds recorded PECB instruction and learning activities. Neither format includes scheduled live teaching, and the official Foundation certificate requirements do not change with the learning format.

How long does the Foundation course take?

The official PECB Foundation programme uses a two-day agenda. With the self-paced options, you choose when to study and how much revision you need. Course duration, video runtime, CPD credits, the access period and the one-hour examination are different measures.

Is the Foundation examination open-book?

No. The published PECB Foundation examination is closed-book. The current handbook does not permit reference materials during the examination. Check PECB's examination instructions before your sitting rather than assuming the open-book conditions of a different course apply.

What is the Foundation examination passing score?

The current PECB Foundation examination has a 70% passing score and 40 multiple-choice questions. A published pass mark is the standard required for the examination; it is not a claim about Aegentra learners' pass rates.

Do I need work experience to receive the Foundation certificate?

There is no professional-experience or project-hour requirement for this Foundation certificate. You must complete the required training, pass the examination, fulfil the application and ethics requirements, and have your application approved by PECB.

Does Foundation make my organisation ISO 27001 certified?

No. This course leads to an individual Foundation certificate application. Organisational certification requires an organisation to establish and operate its ISMS and undergo an independent certification process. Buying a course or passing its examination does not complete that process.

Must I complete Foundation before Lead Implementer or Lead Auditor?

No. Foundation is not a mandatory prerequisite for those PECB courses. It may be a sensible starting point when ISMS terminology is new to you. Choose an advanced course according to your responsibilities, prior understanding and its separate credential requirements.

Are there annual maintenance fees or CPD reporting requirements?

Under PECB's current maintenance policy, Foundation holders are exempt from Annual Maintenance Fees and ongoing CPD reporting. This does not extend the course-access period or examination deadlines, and the rules for a later advanced credential may be different.

Are the examination and a retake included?

The official examination is included with either learning format. One free retake is included if needed. The initial attempt and retake must both be completed within 12 months of purchase, subject to PECB conditions and its current 15-day first-retake waiting period. It is not an unlimited-retake offer.

Is this a free ISO 27001 Foundation course?

No. The official PECB course and examination are paid products. Aegentra provides the sample lesson, selected study resources and access to available free Labs practice separately. When comparing a free course with a paid package, check the awarding body, examination charge and exactly which credential is included.

Do I have to buy Aegentra Labs preparation?

No. Labs preparation is optional and separate from the official PECB course. You can complete the course and examination without purchasing it. Labs questions are independently authored practice, not official or confidential PECB examination questions.

Is a copy of the ISO 27001 standard included?

Official PECB course materials are included. A separate licensed copy of ISO/IEC 27001 is not promised as part of this package. The educational examples on this page and the free resources are not a replacement for the published standard.

Can my employer pay, or can we enrol several people?

Yes. Contact Aegentra Academy about an employer invoice or multiple learners. We will confirm the selected format and billing arrangements. Any private or instructor-led training needs a separate confirmed scope and quotation.

Is the certificate useful for employment in Australia?

It can demonstrate introductory knowledge of ISO 27001 and may support a role involving ISMS responsibilities. Employers decide which qualifications and experience they require. Foundation is not a job guarantee, a licence to practise or evidence that every Australian employer or government agency accepts it for every role.

Course sources and review

PECB sets the official course, examination and certificate requirements. Aegentra Academy maintains the learning options, prices and support information on this page. The links below let you check the requirements with the organisations that publish them.

Editorial owner: Harry Sidhu, Aegentra Academy. Page updated .

Build your understanding of ISO 27001

Choose official PECB Self-Study or recorded eLearning, with the examination included. Start by comparing the formats, or explore the free sample lesson before deciding.