Skip to main content
Aegentra
On this page

Official PECB training

ISO 27001 Lead Implementer Course Australia

The PECB ISO 27001 Lead Implementer course teaches you to plan, implement and improve an ISO/IEC 27001:2022 information security management system. Aegentra Academy, an official PECB training partner in Australia, offers it as Self-Study at A$829, PECB eLearning at A$849, or one-to-one live online training at A$4,299, all excluding GST. The official examination and one free resit are included.

Official PECB course materials · Examination voucher included · 12-month access · Typical self-paced effort: 30–40 hours

Standard
ISO/IEC 27001:2022
Provider
PECB
Self-paced access
12 months
Typical self-paced effort
30–40 hours
Read learner feedback

Choose how you want to learn

Choose Self-Study, recorded PECB eLearning or one-to-one live online training. Purchase Self-Study or eLearning through Aegentra Academy, then access the course through myPECB. Choose your currency and review the total before payment. One-to-one teaching dates, trainer authorisation and booking terms are confirmed by enquiry before payment.

Choose your learning format

Included with both self-paced options

  • Official PECB course materials and 12 months of myPECB access from course assignment
  • Official PECB examination voucher and certification application fee
  • One free examination retake within the applicable PECB cycle

Allow approximately 30–40 hours for self-paced learning. This is an estimated workload, not the video runtime, examination duration or a guaranteed completion time.

Explore the one-to-one teaching package and implementation guidance →

ISO 27001 learner feedback

“Completed iso 9001 and 27001 course pretty impressive with overall support.”
Div KaurISO 9001 and ISO 27001 course learnerView the Google review profile ↗

Feedback on previous ISO 9001 and ISO 27001 course experience. Name abbreviated with permission.

One-to-one learning, connected to real implementation

Private online training

One-to-one live online training combines individual teaching with practical implementation guidance. Discuss the ISO/IEC 27001 methodology, ask questions as you learn and connect the requirements to the work of establishing an ISMS.

One-to-one package

A$4,299 excluding GST

A$4,728.90 including Australian GST

Enquire about your teaching schedule
  • 24 teaching hours — four days of six-hour sessions, or eight days of three-hour sessions; the learner chooses
  • Official PECB eLearning alongside the live sessions
  • One 60-minute session with an Aegentra implementation consultant
  • One month of free Aegentra Labs access for this qualification
  • Official PECB exam voucher and one free resit within the applicable 12-month PECB examination cycle

Weekday and weekend teaching dates and session times are mutually agreed before booking; no public group classes or classroom delivery are offered.

The one-to-one package includes one month of Aegentra Labs practice for this qualification, with unlimited attempts at the available practice questions during that month. This included month is separate from the optional A$89 excluding GST add-on for 12 months of full Labs access. Unlimited practice attempts do not mean unlimited official examination attempts.

How the consultant session connects the pieces

Bring an implementation question or discuss a learning example. Explore how organisational scope connects to a risk assessment, how a treatment decision informs the Statement of Applicability, and what evidence shows a control is operating. The focus is understanding the approach and identifying sensible next steps.

This is a focused educational session, not a complete ISMS implementation, document pack or certification audit. Please do not include confidential client information in the enquiry form.

Contact us for one-to-one training

Tell us your preferred timing, time zone and learning goal. Aegentra Academy confirms the four-day or eight-day timetable, trainer and consultant assignments, relevant ISO/IEC 27001 Lead Implementer trainer authorisation, eLearning and Labs access, examination arrangements and booking terms in writing before payment.

The 24 hours cover teaching. The examination and consultant session are arranged separately; completing the class does not itself award a PECB credential.

Call +61 3 9956 9399 or email Academy@aegentra.com.au

We use these details to respond to your training enquiry. Read our privacy policy.

Learn the decisions behind an effective ISMS

Implementation is more than completing templates. You need to understand the organisation, decide what the management system covers, assess information security risks, select appropriate treatments and establish responsibilities. The course then connects operating evidence, review and corrective action so the ISMS can be maintained and improved.

  • Define an ISMS scope and implementation approach that fit the organisation.
  • Connect risk assessment, treatment decisions and the Statement of Applicability.
  • Establish responsibilities, documented information and evidence of operation.
  • Prepare for internal review, continual improvement and an independent certification audit.
Context, scope and implementation planning

Identify the organisation’s activities, interested parties and information security requirements. Examine scope boundaries, leadership responsibilities, policy, objectives and the implementation plan. A useful scope explains what is covered and why, rather than copying another organisation’s wording.

Risk assessment, treatment and the Statement of Applicability

Work through risk criteria, assessment and treatment. Understand how selected controls support treatment decisions and how the Statement of Applicability records applicability and justification. It accounts for the Annex A reference set; it is not a claim that every control is equally relevant to every organisation.

Controls, responsibilities and operating evidence

Consider how controls become part of normal work: who owns them, how they operate, what records are retained and how exceptions are handled. Connect documented information with evidence of actual performance, not simply a policy that says an activity should happen.

Monitoring, internal audit and management review

Explore how measurement, internal audit and management review help an organisation evaluate the ISMS. Distinguish collecting evidence from evaluating it, and link findings to appropriate corrective action and improvement.

Certification readiness and continual improvement

Organise the scope, risk and treatment records, operating evidence and review outputs needed to explain the ISMS to an independent certification body. Understand why certification readiness is an ongoing management activity rather than a last-minute document exercise.

Examination preparation

Practise applying the implementation method to scenarios and locating relevant information within the permitted references. Review the current competency domains and examination instructions. The examination tests understanding; memorising a template is not a substitute for reasoning through the scenario.

Official course details

450+ pages of official course materials. An attestation of course completion worth 31 CPD credits is issued to participants who attend the training course, under PECB’s completion conditions.

The official agenda lists four teaching days and a separate examination entry. Check the official syllabus for its full agenda.

Official PECB syllabus

Understand the exam and the credential you can apply for

The PECB ISO/IEC 27001 Lead Implementer examination lasts three hours and contains 80 multiple-choice questions, including scenario-based questions. It is open-book under PECB’s permitted-reference rules, with a 70% passing score. Check your current candidate handbook and examination instructions before booking.

Passing the examination allows you to apply for the PECB credential that matches your experience. It does not automatically award the Lead Implementer tier. PECB assesses your application, professional experience, ISMS project experience and ethical requirements before making the credential decision.

PECB credential experience requirements
Credential tierProfessional experienceISMS project activity
Provisional ImplementerNo professional experience requiredNo project hours required
ImplementerTwo years, including one year in information security management200 hours
Lead ImplementerFive years, including two years in information security management300 hours
Senior Lead ImplementerTen years, including seven years in information security management1,000 hours

All applicants must meet PECB’s applicable examination, application and Code of Ethics requirements. A personal credential is separate from certification of an organisation’s ISMS.

Retakes and maintaining your credential

Every option includes one free examination retake within the applicable PECB cycle. PECB’s current rules count the 12-month examination cycle from purchase for Self-Study and eLearning, or course completion for instructor-led training. Check the examination and retake deadline recorded in myPECB; a failed attempt does not start a new 12-month entitlement.

Credential maintenance depends on the tier. Provisional credentials are exempt from PECB’s CPD and maintenance-fee requirements. Other tiers have applicable renewal, professional-development and fee requirements. Check PECB’s current maintenance policy before applying.

Over each three-year cycle: Implementer, 60 CPD hours; Lead Implementer, 90 CPD hours; Senior Lead Implementer, 180 CPD hours. Check the current PECB maintenance policy.

See what implementation work looks like

Aegentra publishes worked ISO 27001 examples so you can inspect the work before choosing a course. Use them to understand how risks, treatment decisions, responsibilities and evidence connect. They are learning aids, not ready-made proof that your organisation complies with the standard.

These are Aegentra-authored resources, not official PECB course content.

A simple implementation example

Illustrative learning scenario, not a client outcome

A growing business has an offboarding policy, but some former staff accounts remain active. An implementer needs to understand the access risk, decide how it will be treated, assign an owner and define an operating process. Useful evidence might include approved leaver records, account-disablement records and checks for exceptions. The question is not only “Do we have a policy?” but “How do we know the process happens, and what do we do when it does not?”

This is a starting point for discussion, not a complete risk assessment or prescribed control design.

Practise before you buy

Try the free ISO 27001 Lead Implementer questions and exam guide in Aegentra Labs. Use the explanations to examine your reasoning, then return to the relevant learning material. Full Labs access is optional and can be added in the purchase section.

Practitioner evidence from Aegentra

Aegentra also works on ISO 27001 implementation and separately scoped internal audits. Read a published engagement record to see how requirements, evidence and professional judgement connect in practice. This demonstrates the wider practice behind the Academy; it does not guarantee a learner’s examination result or an organisation’s certification.

A Clause 9.2 internal audit, met with evidence ↗
Aegentra ISO 27001 internal audit case study cover

Lead Implementer or Lead Auditor?

Lead Auditor and Lead Implementer comparison
Your decisionLead AuditorLead Implementer
What you doPlan and lead first-, second- and third-party audits; sample evidence; classify and write nonconformitiesScope and build an ISMS; run the risk assessment; write the Statement of Applicability
Reference standardISO/IEC 27001:2022 plus ISO 19011 auditing guidelinesISO/IEC 27001:2022 and the 93 Annex A controls
Typical rolesInternal auditor, supplier assurance, IT audit consultant, certification-body assessorISMS manager, security manager, GRC lead, compliance consultant
Take it ifYou will check that a management system worksYou will get an organisation audit-ready
Explore the ISO 27001 Lead Auditor course →
Recorded PECB eLearning faculty

PECB supplies the recorded eLearning through myPECB. Its recorded faculty is separate from the trainer assigned to one-to-one live online training.

Carl Carpenter

A highly experienced cybersecurity professional and penetration tester with deep expertise across regulated environments — CMMC, HIPAA, PCI, FFIEC, CCPA, and GDPR. A certified auditor and instructor holding ISO/IEC 27001 Senior Lead Auditor, CISA, CISM, and PCI-QSA, and a Cisco, Microsoft, CompTIA, and PECB-certified specialist.

ISO/IEC 27001 Senior Lead Auditor · CISA · CISM · PCI-QSA

View Carl Carpenter’s profile ↗
Graeme Parker

A Security, Technology, Risk, and Compliance professional with vast experience across private and public sector roles spanning financial services, government, manufacturing, healthcare, and retail. A certified PECB trainer delivering ISO/IEC 27001, ISO 22301, ISO/IEC 42001, CISSP, CISM, and CISA courses globally across the UK, USA, Canada, and Europe.

PECB Certified Trainer · ISO 27001 · ISO 22301 · ISO 42001

View Graeme Parker’s profile ↗
Nathalie Claes

A Security Governance expert and management consultant with over a decade of international experience leading complex security projects. She delivers CISO-as-a-service, senior compliance and risk management, and DPO services, and coaches organisations through growth and restructuring to build resilient, future-ready teams.

CISO-as-a-Service · Compliance & Risk · DPO

View Nathalie Claes’s profile ↗
Qualifications that complement implementation work

ISO 27001 Lead Auditor develops a different perspective: evaluating a management system and its evidence. ISO 27005 develops information security risk skills, while ISO 27701 and ISO 42001 extend management-system work into privacy and AI governance. Existing CISA, CISM or CISSP knowledge may make some concepts familiar, but it does not waive PECB’s examination or experience requirements.

ISO 27001 Lead Implementer course questions

How much does the ISO 27001 Lead Implementer course cost in Australia?

Self-Study is A$829 excluding GST and PECB eLearning is A$849 excluding GST. One-to-one live online training is A$4,299 excluding GST. Australian billing addresses add 10% GST, making the self-paced totals A$911.90 and A$933.90. Every option includes the official PECB examination voucher and one free resit.

What is included in the course price?

All options include the official PECB course materials, 12 months of myPECB access from course assignment, the examination voucher, the certification application fee, and one free retake within the applicable PECB examination cycle. The course materials run to more than 450 pages. Completion carries an attestation worth 31 CPD credits under PECB's conditions.

What is the difference between Self-Study and eLearning?

Self-Study gives you the official PECB course materials to work through independently. eLearning costs A$20 more and adds recorded PECB instruction and interactive learning activities. Both are self-paced through myPECB, both lead to the same examination and credential, and both include the same examination package.

How long does the ISO 27001 Lead Implementer course take?

Allow approximately 30 to 40 hours of self-paced study. PECB's official instructor-led agenda lists four teaching days and a fifth examination entry; Aegentra arranges the examination separately from the private teaching sessions. This is an estimated workload, not video runtime or a completion guarantee, and it is separate from your 12-month access period.

Is the PECB exam included in the price?

Yes. The official PECB examination voucher is included in every course price, so there is no separate exam fee afterwards. The certification application fee and one free retake are included, subject to PECB's conditions and the applicable examination deadline.

What is the exam format, duration and pass mark?

The examination runs for three hours and contains 80 multiple-choice questions, including scenario-based questions. It is open-book under PECB's permitted-reference rules, with a 70% pass mark. Questions test whether you can apply the implementation method to a scenario, so locating information is not a substitute for understanding it.

Do I need ISO 27001 Foundation first?

No. ISO 27001 Foundation is not a mandatory prerequisite. The course does expect general familiarity with information security and management-system concepts, so Foundation is a sensible starting point if the terminology is new to you. It does not change the examination or experience requirements for your credential.

What is the difference between Lead Implementer and Lead Auditor?

Lead Implementer is the build-side credential: scoping an ISMS, running the risk assessment and writing the Statement of Applicability. Lead Auditor is the verification side: planning audits, sampling evidence and classifying nonconformities. Neither is a prerequisite for the other, and PECB assesses each credential separately.

What experience does the Lead Implementer credential require?

Passing the examination lets you apply for the tier your experience supports. Provisional Implementer requires none. Implementer requires two years including one in information security management, plus 200 project hours. Lead Implementer requires five years including two in information security management, plus 300 hours. PECB decides each application.

What happens if I fail the exam?

One free retake is included if you fail the first examination, subject to PECB's examination deadline and waiting periods. PECB's current policy requires the included examination cycle to be completed within 12 months of purchase for Self-Study and eLearning, or course completion for instructor-led training. Aegentra does not publish a pass-rate claim without an audited cohort dataset.

How long do I have access to the course?

Aegentra includes 12 months of myPECB course access from the date the course is assigned to you. Course-material access and PECB's examination and retake deadlines are separate; check the applicable examination deadline in myPECB. The access period is separate from the 30 to 40 hours of typical study effort and from PECB's credential requirements.

Can I take this course from Melbourne, Sydney or anywhere in Australia?

Yes. Self-Study and eLearning are delivered online through myPECB, so you can study from Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra or anywhere else. One-to-one live online training is scheduled around your timezone by agreement. There is no classroom attendance and no venue to travel to.

What does one-to-one training include, and what does it cost?

One-to-one live online training is A$4,299 excluding GST, or A$4,728.90 including Australian GST. It provides 24 teaching hours, taken as four six-hour days or eight three-hour days at your choosing, official PECB eLearning, a 60-minute session with an Aegentra implementation consultant, one month of free Aegentra Labs access, and the examination voucher with a free resit.

Can my employer pay or be invoiced?

Yes. Complete the checkout yourself and forward the Stripe tax invoice for reimbursement, or contact Academy@aegentra.com.au to arrange employer billing. Tax invoices showing Aegentra's ABN and GST where applicable are issued through checkout. For multiple individual enrolments, request a written quote confirming price, payment terms and inclusions before purchase. Live online teaching remains one-to-one.

Is the PECB credential recognised in Australia?

The PECB credential is an international personnel certification, not an Australian government licence or a VET qualification. PECB is accredited by IAS and UKAS under ISO/IEC 17024. Australian employers and clients decide its relevance for a given role.

Choose your next step

Study independently with the self-paced options, or talk to Aegentra Academy about private one-to-one training and practical implementation guidance.

Sources and factual review

Reviewed by Harry Sidhu on .

Last updated: .