Statement of Applicability example ↗
See how applicability decisions and their reasons are recorded.
Official PECB training
The PECB ISO 27001 Lead Implementer course teaches you to plan, implement and improve an ISO/IEC 27001:2022 information security management system. Aegentra Academy, an official PECB training partner in Australia, offers it as Self-Study at A$829, PECB eLearning at A$849, or one-to-one live online training at A$4,299, all excluding GST. The official examination and one free resit are included.
Official PECB course materials · Examination voucher included · 12-month access · Typical self-paced effort: 30–40 hours
Choose Self-Study, recorded PECB eLearning or one-to-one live online training. Purchase Self-Study or eLearning through Aegentra Academy, then access the course through myPECB. Choose your currency and review the total before payment. One-to-one teaching dates, trainer authorisation and booking terms are confirmed by enquiry before payment.
Allow approximately 30–40 hours for self-paced learning. This is an estimated workload, not the video runtime, examination duration or a guaranteed completion time.
Explore the one-to-one teaching package and implementation guidance →
“Completed iso 9001 and 27001 course pretty impressive with overall support.”
Feedback on previous ISO 9001 and ISO 27001 course experience. Name abbreviated with permission.
Private online training
One-to-one live online training combines individual teaching with practical implementation guidance. Discuss the ISO/IEC 27001 methodology, ask questions as you learn and connect the requirements to the work of establishing an ISMS.
One-to-one package
A$4,299 excluding GST
A$4,728.90 including Australian GST
Enquire about your teaching scheduleWeekday and weekend teaching dates and session times are mutually agreed before booking; no public group classes or classroom delivery are offered.
The one-to-one package includes one month of Aegentra Labs practice for this qualification, with unlimited attempts at the available practice questions during that month. This included month is separate from the optional A$89 excluding GST add-on for 12 months of full Labs access. Unlimited practice attempts do not mean unlimited official examination attempts.
Bring an implementation question or discuss a learning example. Explore how organisational scope connects to a risk assessment, how a treatment decision informs the Statement of Applicability, and what evidence shows a control is operating. The focus is understanding the approach and identifying sensible next steps.
This is a focused educational session, not a complete ISMS implementation, document pack or certification audit. Please do not include confidential client information in the enquiry form.
Tell us your preferred timing, time zone and learning goal. Aegentra Academy confirms the four-day or eight-day timetable, trainer and consultant assignments, relevant ISO/IEC 27001 Lead Implementer trainer authorisation, eLearning and Labs access, examination arrangements and booking terms in writing before payment.
The 24 hours cover teaching. The examination and consultant session are arranged separately; completing the class does not itself award a PECB credential.
Implementation is more than completing templates. You need to understand the organisation, decide what the management system covers, assess information security risks, select appropriate treatments and establish responsibilities. The course then connects operating evidence, review and corrective action so the ISMS can be maintained and improved.
Identify the organisation’s activities, interested parties and information security requirements. Examine scope boundaries, leadership responsibilities, policy, objectives and the implementation plan. A useful scope explains what is covered and why, rather than copying another organisation’s wording.
Work through risk criteria, assessment and treatment. Understand how selected controls support treatment decisions and how the Statement of Applicability records applicability and justification. It accounts for the Annex A reference set; it is not a claim that every control is equally relevant to every organisation.
Consider how controls become part of normal work: who owns them, how they operate, what records are retained and how exceptions are handled. Connect documented information with evidence of actual performance, not simply a policy that says an activity should happen.
Explore how measurement, internal audit and management review help an organisation evaluate the ISMS. Distinguish collecting evidence from evaluating it, and link findings to appropriate corrective action and improvement.
Organise the scope, risk and treatment records, operating evidence and review outputs needed to explain the ISMS to an independent certification body. Understand why certification readiness is an ongoing management activity rather than a last-minute document exercise.
Practise applying the implementation method to scenarios and locating relevant information within the permitted references. Review the current competency domains and examination instructions. The examination tests understanding; memorising a template is not a substitute for reasoning through the scenario.
450+ pages of official course materials. An attestation of course completion worth 31 CPD credits is issued to participants who attend the training course, under PECB’s completion conditions.
The official agenda lists four teaching days and a separate examination entry. Check the official syllabus for its full agenda.
Official PECB syllabusThe PECB ISO/IEC 27001 Lead Implementer examination lasts three hours and contains 80 multiple-choice questions, including scenario-based questions. It is open-book under PECB’s permitted-reference rules, with a 70% passing score. Check your current candidate handbook and examination instructions before booking.
Passing the examination allows you to apply for the PECB credential that matches your experience. It does not automatically award the Lead Implementer tier. PECB assesses your application, professional experience, ISMS project experience and ethical requirements before making the credential decision.
| Credential tier | Professional experience | ISMS project activity |
|---|---|---|
| Provisional Implementer | No professional experience required | No project hours required |
| Implementer | Two years, including one year in information security management | 200 hours |
| Lead Implementer | Five years, including two years in information security management | 300 hours |
| Senior Lead Implementer | Ten years, including seven years in information security management | 1,000 hours |
All applicants must meet PECB’s applicable examination, application and Code of Ethics requirements. A personal credential is separate from certification of an organisation’s ISMS.
Every option includes one free examination retake within the applicable PECB cycle. PECB’s current rules count the 12-month examination cycle from purchase for Self-Study and eLearning, or course completion for instructor-led training. Check the examination and retake deadline recorded in myPECB; a failed attempt does not start a new 12-month entitlement.
Credential maintenance depends on the tier. Provisional credentials are exempt from PECB’s CPD and maintenance-fee requirements. Other tiers have applicable renewal, professional-development and fee requirements. Check PECB’s current maintenance policy before applying.
Over each three-year cycle: Implementer, 60 CPD hours; Lead Implementer, 90 CPD hours; Senior Lead Implementer, 180 CPD hours. Check the current PECB maintenance policy.
Aegentra publishes worked ISO 27001 examples so you can inspect the work before choosing a course. Use them to understand how risks, treatment decisions, responsibilities and evidence connect. They are learning aids, not ready-made proof that your organisation complies with the standard.
See how applicability decisions and their reasons are recorded.
Follow risks through assessment, treatment, ownership and review.
Explore related evidence considerations for APRA CPS 234 and DISP, without treating a cross-reference as regulatory assurance.
These are Aegentra-authored resources, not official PECB course content.
Illustrative learning scenario, not a client outcome
A growing business has an offboarding policy, but some former staff accounts remain active. An implementer needs to understand the access risk, decide how it will be treated, assign an owner and define an operating process. Useful evidence might include approved leaver records, account-disablement records and checks for exceptions. The question is not only “Do we have a policy?” but “How do we know the process happens, and what do we do when it does not?”
This is a starting point for discussion, not a complete risk assessment or prescribed control design.
Try the free ISO 27001 Lead Implementer questions and exam guide in Aegentra Labs. Use the explanations to examine your reasoning, then return to the relevant learning material. Full Labs access is optional and can be added in the purchase section.
Aegentra also works on ISO 27001 implementation and separately scoped internal audits. Read a published engagement record to see how requirements, evidence and professional judgement connect in practice. This demonstrates the wider practice behind the Academy; it does not guarantee a learner’s examination result or an organisation’s certification.
A Clause 9.2 internal audit, met with evidence ↗
| Your decision | Lead Auditor | Lead Implementer |
|---|---|---|
| What you do | Plan and lead first-, second- and third-party audits; sample evidence; classify and write nonconformities | Scope and build an ISMS; run the risk assessment; write the Statement of Applicability |
| Reference standard | ISO/IEC 27001:2022 plus ISO 19011 auditing guidelines | ISO/IEC 27001:2022 and the 93 Annex A controls |
| Typical roles | Internal auditor, supplier assurance, IT audit consultant, certification-body assessor | ISMS manager, security manager, GRC lead, compliance consultant |
| Take it if | You will check that a management system works | You will get an organisation audit-ready |
PECB supplies the recorded eLearning through myPECB. Its recorded faculty is separate from the trainer assigned to one-to-one live online training.
A highly experienced cybersecurity professional and penetration tester with deep expertise across regulated environments — CMMC, HIPAA, PCI, FFIEC, CCPA, and GDPR. A certified auditor and instructor holding ISO/IEC 27001 Senior Lead Auditor, CISA, CISM, and PCI-QSA, and a Cisco, Microsoft, CompTIA, and PECB-certified specialist.
ISO/IEC 27001 Senior Lead Auditor · CISA · CISM · PCI-QSA
View Carl Carpenter’s profile ↗A Security, Technology, Risk, and Compliance professional with vast experience across private and public sector roles spanning financial services, government, manufacturing, healthcare, and retail. A certified PECB trainer delivering ISO/IEC 27001, ISO 22301, ISO/IEC 42001, CISSP, CISM, and CISA courses globally across the UK, USA, Canada, and Europe.
PECB Certified Trainer · ISO 27001 · ISO 22301 · ISO 42001
View Graeme Parker’s profile ↗A Security Governance expert and management consultant with over a decade of international experience leading complex security projects. She delivers CISO-as-a-service, senior compliance and risk management, and DPO services, and coaches organisations through growth and restructuring to build resilient, future-ready teams.
CISO-as-a-Service · Compliance & Risk · DPO
View Nathalie Claes’s profile ↗ISO 27001 Lead Auditor develops a different perspective: evaluating a management system and its evidence. ISO 27005 develops information security risk skills, while ISO 27701 and ISO 42001 extend management-system work into privacy and AI governance. Existing CISA, CISM or CISSP knowledge may make some concepts familiar, but it does not waive PECB’s examination or experience requirements.
Self-Study is A$829 excluding GST and PECB eLearning is A$849 excluding GST. One-to-one live online training is A$4,299 excluding GST. Australian billing addresses add 10% GST, making the self-paced totals A$911.90 and A$933.90. Every option includes the official PECB examination voucher and one free resit.
All options include the official PECB course materials, 12 months of myPECB access from course assignment, the examination voucher, the certification application fee, and one free retake within the applicable PECB examination cycle. The course materials run to more than 450 pages. Completion carries an attestation worth 31 CPD credits under PECB's conditions.
Self-Study gives you the official PECB course materials to work through independently. eLearning costs A$20 more and adds recorded PECB instruction and interactive learning activities. Both are self-paced through myPECB, both lead to the same examination and credential, and both include the same examination package.
Allow approximately 30 to 40 hours of self-paced study. PECB's official instructor-led agenda lists four teaching days and a fifth examination entry; Aegentra arranges the examination separately from the private teaching sessions. This is an estimated workload, not video runtime or a completion guarantee, and it is separate from your 12-month access period.
Yes. The official PECB examination voucher is included in every course price, so there is no separate exam fee afterwards. The certification application fee and one free retake are included, subject to PECB's conditions and the applicable examination deadline.
The examination runs for three hours and contains 80 multiple-choice questions, including scenario-based questions. It is open-book under PECB's permitted-reference rules, with a 70% pass mark. Questions test whether you can apply the implementation method to a scenario, so locating information is not a substitute for understanding it.
No. ISO 27001 Foundation is not a mandatory prerequisite. The course does expect general familiarity with information security and management-system concepts, so Foundation is a sensible starting point if the terminology is new to you. It does not change the examination or experience requirements for your credential.
Lead Implementer is the build-side credential: scoping an ISMS, running the risk assessment and writing the Statement of Applicability. Lead Auditor is the verification side: planning audits, sampling evidence and classifying nonconformities. Neither is a prerequisite for the other, and PECB assesses each credential separately.
Passing the examination lets you apply for the tier your experience supports. Provisional Implementer requires none. Implementer requires two years including one in information security management, plus 200 project hours. Lead Implementer requires five years including two in information security management, plus 300 hours. PECB decides each application.
One free retake is included if you fail the first examination, subject to PECB's examination deadline and waiting periods. PECB's current policy requires the included examination cycle to be completed within 12 months of purchase for Self-Study and eLearning, or course completion for instructor-led training. Aegentra does not publish a pass-rate claim without an audited cohort dataset.
Aegentra includes 12 months of myPECB course access from the date the course is assigned to you. Course-material access and PECB's examination and retake deadlines are separate; check the applicable examination deadline in myPECB. The access period is separate from the 30 to 40 hours of typical study effort and from PECB's credential requirements.
Yes. Self-Study and eLearning are delivered online through myPECB, so you can study from Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra or anywhere else. One-to-one live online training is scheduled around your timezone by agreement. There is no classroom attendance and no venue to travel to.
One-to-one live online training is A$4,299 excluding GST, or A$4,728.90 including Australian GST. It provides 24 teaching hours, taken as four six-hour days or eight three-hour days at your choosing, official PECB eLearning, a 60-minute session with an Aegentra implementation consultant, one month of free Aegentra Labs access, and the examination voucher with a free resit.
Yes. Complete the checkout yourself and forward the Stripe tax invoice for reimbursement, or contact Academy@aegentra.com.au to arrange employer billing. Tax invoices showing Aegentra's ABN and GST where applicable are issued through checkout. For multiple individual enrolments, request a written quote confirming price, payment terms and inclusions before purchase. Live online teaching remains one-to-one.
The PECB credential is an international personnel certification, not an Australian government licence or a VET qualification. PECB is accredited by IAS and UKAS under ISO/IEC 17024. Australian employers and clients decide its relevance for a given role.
Study independently with the self-paced options, or talk to Aegentra Academy about private one-to-one training and practical implementation guidance.