GLOBAL AI CERTIFICATION COUNCIL
ISO/IEC 27001 Foundation Certification Training in Malaysia
- Earn 16 CPD/PDU hours on completion of the course
- Certification valid for three years and internationally recognised
- Self-paced learning, so you can start immediately and study on your own schedule
- Two packages available, either the full course or membership and exam only
- 16 CPD/PDU hours
- No experience required
- HRD Corp claimable

Issued by GAICC
Global AI Certification Council


ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)


OVERVIEW
What ISO/IEC 27001 is
Malaysian organisations are being asked — by customers, boards and regulators — to show how information is protected, not only that a firewall is in place. ISO/IEC 27001:2022 is the management system standard that sets out how that evidence is built: scope, leadership, risk, controls, and the cycle of audit and improvement.
Foundation is the entry point. It does not train you to implement or audit an ISMS. Across two self-paced days it covers the security ideas the standard uses, how Clauses 4 to 10 are arranged, what Annex A is for, and how certification audits run.
No prior background in information security or ISO standards is assumed. Completing the course meets the 16 contact hours GAICC require before you sit the Foundation examination.
WHO IT IS FOR
Who should take this certification
No prior experience of information security, standards or auditing is required.
People new to information security governance who need a first, structured reading of ISO/IEC 27001
IT, operations and business leads in Malaysia being asked to evidence how information is protected
Junior compliance, risk and security officers who will support an ISMS rather than run the audit
Engineers, data and infrastructure staff who need the governance vocabulary used in Clauses 4 to 10
Anyone planning to continue to ISO/IEC 27001 Lead Implementer or Lead Auditor
Holders of an ISO/IEC 42001 credential adding the information-security companion standard
OUTCOMES
What you will be able to do
By the end of the course you should be able to talk through the standard with security, risk and leadership without translating.
- Explain core security ideas — CIA, authenticity, non-repudiation, assets, threats, vulnerabilities, and risk.
- Outline the purpose and structure of ISO/IEC 27001 and the wider ISO/IEC 27000 family
- Describe Clauses 4 to 10 — context, leadership, planning and risk, support, operation, and evaluation.
- Explain the Statement of Applicability and how control selection links to risk treatment
- Describe what an ISMS is and why organisations adopt one, including drivers, and interested parties
- Explain the PDCA model and, at awareness level, the difference between certification and accreditation
- Identify the four Annex A themes and recognise common controls and their purpose
- Outline the certification lifecycle — Stage 1 and Stage 2, surveillance and recertification
WHY PROCERT
Why enrol through us
Claimable by your employer
HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.
Malaysian support
A local team handling enrolment, exam booking and any questions along the way.
Team enrolment
Group registration handled end to end, with a single invoice for the whole team.
| PackageSelf-paced course package | Through ProCertUS$498 | Typical listed priceUS$598 |
|---|---|---|
| HRD Corp levy, where the programme is approved | Included | Not included |
| Malaysian enrolment and exam-booking support | Included | Not included |
THE CREDENTIAL
GAICC Certified ISO/IEC 27001 Foundation
The GAICC certification programme is CPD accredited.

INCLUDED
This course includes
- 200+ pages of study material
- 16 CPD/PDU hours on completion. On renewal, 20 CPD required
- Certificate of completion Required for exam eligibility
- Two-day self-paced programme
- Exam simulator access
- Exam voucher included
Included resources to support your learning
- ISO/IEC 27001, 27000 and 27002 standards summary
- ISO/IEC 27001 case-study workbook
- Annex A controls quick-reference guide
- ISMS templates and checklists, including a Statement of Applicability
COURSE MODULES
Curriculum
Two days of self-paced study, mapped to the three exam domains and the tasks inside each.
Domains I and II
4 modules
Security concepts, the ISO/IEC 27000 family, then Clauses 4 to 10.
Information security and the ISMS
CIA, authenticity, non-repudiation, assets, threats, vulnerabilities, risk and controls; why organisations stand up an ISMS; interested parties and the benefits they expect
The standard and the ISO/IEC 27000 family
purpose and structure of ISO/IEC 27001 (Clauses 1–3 versus 4–10, Annex SL, Annex A); 27000 vocabulary; 27002, 27003 and 27005; how 27001 sits with ISO 9001 and ISO/IEC 42001; PDCA; certification versus accreditation
Context, leadership and planning (Clauses 4–6)
internal and external issues, including climate-change relevance; interested parties and scope; policy, roles and authorities; risk assessment and treatment; the Statement of Applicability; objectives and planning of changes
Support, operation, evaluation and improvement (Clauses 7–10)
resources, competence, awareness, communication and documented information; operational control; monitoring, internal audit and management review; nonconformity and corrective action
Domain III and exam prep
4 modules
Annex A themes, common controls, the SoA, then the audit route.
Annex A control themes
Organizational (A.5), People (A.6), Physical (A.7) and Technological (A.8), and the 93 controls in total
Common controls in practice
access control, classification, supplier and cloud security, incident management, backup and cryptography, and the purpose each control serves
Statement of Applicability
selecting controls, justifying inclusion and exclusion, and linking the SoA to risk treatment
Certification lifecycle and exam readiness
Stage 1 and Stage 2, surveillance and recertification, roles in an ISMS, plus the exam format and practice questions


CERTIFICATION DETAILS
Examination and certification
| Awarding body | Global AI Certification Council (GAICC) |
|---|---|
| Credential | GAICC Certified ISO/IEC 27001 Foundation |
| Exam format | 40 multiple-choice questions, online proctored |
| Exam duration | 60 minutes |
| Passing score | 70% |
| Validity | 3 years |
| Renewal | CPD credits required |
| CPD/PDU earned | 16 on completion |
| Eligibility | 16 contact hours of structured ISO/IEC 27001 training. The self-paced course package includes training that meets this requirement. |
HOW IT FITS
How it fits with standards you may already run
| Standard | What it governs | Relationship to ISO/IEC 27001 |
|---|---|---|
| ISO 9001 | What it governsQuality management | Relationship to ISO/IEC 27001Shares the same high-level structure (Annex SL). Where 9001 governs process quality, 27001 governs how information risk is treated. |
| ISO/IEC 42001 | What it governsArtificial intelligence management | Relationship to ISO/IEC 27001The same management-system shape. 42001 governs AI systems; 27001 governs information security. Organisations often run both. |
INSTRUCTOR
Dr Faiz Rasool
Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.
LinkedIn — Dr Faiz Rasool (opens in a new tab)ENROL
Enrol on ISO/IEC 27001 Foundation
Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.
Most popular
Self-paced course package
US$498
- Video lessons included
- Learning resources
- Exam simulator access
- Examination voucher
- Certificate of completion
Membership included
Membership and exam package
US$198
- Video lessons included (not included)
- Learning resources
- Exam simulator access
- Examination voucher
- One exam retake included
Membership included
FAQ
FAQ
What is the GAICC ISO/IEC 27001 Foundation certification?
It is GAICC’s entry-level credential for ISO/IEC 27001:2022, the international standard for an Information Security Management System. It confirms you understand the purpose of an ISMS, how the standard is structured, and the ideas behind risk, controls and certification. It does not assess whether you can implement or audit an ISMS.
Who is this training for in Malaysia?
Anyone who needs a first formal step into information security governance — IT and business staff being asked to evidence controls, junior compliance or risk officers, and people planning to continue to Lead Implementer or Lead Auditor. No prior information-security experience is required.
What are the eligibility requirements?
There is no education or work-experience requirement. You do need at least 16 contact hours of structured ISO/IEC 27001 training, completed with a GAICC-authorised provider or an equivalent recognised institution. GAICC self-paced courses also meet this. The self-paced course package on this page includes training that satisfies the hours requirement.
How is the exam set?
Forty scored, single-answer multiple-choice questions (A to D), in 60 minutes. It is closed book, sat online under proctoring or at a test centre. Items sit at Remember, Understand and Apply. The published pass mark is 70%.
Which version of the standard is examined?
ISO/IEC 27001:2022, with the ISO/IEC 27000 vocabulary and ISO/IEC 27002:2022 for the controls.
Does this let me implement or audit an ISMS?
No. Foundation is awareness-level. Implementation and audit are covered on the ISO/IEC 27001 Lead Implementer and Lead Auditor pathways.
What is the certification validity period?
The Foundation certification is valid for three years from the date it is issued.
How do I maintain or renew my certification?
In each three-year cycle you must complete at least 20 CPD hours, then submit a renewal application and the renewal fee.
What is the difference between the two packages?
The self-paced course package includes the full video course and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 training and only need the examination, membership and supporting resources.
Can I buy the exam package if I have not done the training?
No. Sixteen contact hours of structured ISO/IEC 27001 training are required before you can sit the examination. If you have not completed it, choose the self-paced course package.
Is the GAICC certification programme CPD accredited?
The GAICC certification programme is CPD accredited.
Can I enrol a team?
Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.
Certifying more than one person?
We handle group enrolment, consolidated billing and HRD Corp documentation.
