Next PMP® classroom cohort: 28 Sept - 2 Oct 2026, Kuala Lumpur. Reserve your seat

ProCert

GLOBAL AI CERTIFICATION COUNCIL

ISO/IEC 27001 Foundation Certification Training in Malaysia

  • Earn 16 CPD/PDU hours on completion of the course
  • Certification valid for three years and internationally recognised
  • Self-paced learning, so you can start immediately and study on your own schedule
  • Two packages available, either the full course or membership and exam only
  • 16 CPD/PDU hours
  • No experience required
  • HRD Corp claimable
openart gpt image 2 1 1788971265017 be0053c0

Issued by GAICC

Global AI Certification Council

WhatsApp Image 2026 08 29 at 16.01.23 removebg preview
Untitled design (27)

ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)

HRD Corp claimable
HRD Corp Registered Training Provider

OVERVIEW

What ISO/IEC 27001 is

Malaysian organisations are being asked — by customers, boards and regulators — to show how information is protected, not only that a firewall is in place. ISO/IEC 27001:2022 is the management system standard that sets out how that evidence is built: scope, leadership, risk, controls, and the cycle of audit and improvement.

Foundation is the entry point. It does not train you to implement or audit an ISMS. Across two self-paced days it covers the security ideas the standard uses, how Clauses 4 to 10 are arranged, what Annex A is for, and how certification audits run.

No prior background in information security or ISO standards is assumed. Completing the course meets the 16 contact hours GAICC require before you sit the Foundation examination.

WHO IT IS FOR

Who should take this certification

No prior experience of information security, standards or auditing is required.

OUTCOMES

What you will be able to do

By the end of the course you should be able to talk through the standard with security, risk and leadership without translating.

  • Explain core security ideas — CIA, authenticity, non-repudiation, assets, threats, vulnerabilities, and risk.
  • Outline the purpose and structure of ISO/IEC 27001 and the wider ISO/IEC 27000 family
  • Describe Clauses 4 to 10 — context, leadership, planning and risk, support, operation, and evaluation.
  • Explain the Statement of Applicability and how control selection links to risk treatment
  • Describe what an ISMS is and why organisations adopt one, including drivers, and interested parties
  • Explain the PDCA model and, at awareness level, the difference between certification and accreditation
  • Identify the four Annex A themes and recognise common controls and their purpose
  • Outline the certification lifecycle — Stage 1 and Stage 2, surveillance and recertification

WHY PROCERT

Why enrol through us

  1. Claimable by your employer

    HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.

  2. Malaysian support

    A local team handling enrolment, exam booking and any questions along the way.

  3. Team enrolment

    Group registration handled end to end, with a single invoice for the whole team.

Self-paced course package: Through ProCert US$498 versus typical listed price US$598
PackageSelf-paced course packageThrough ProCertUS$498Typical listed priceUS$598
HRD Corp levy, where the programme is approvedIncludedNot included
Malaysian enrolment and exam-booking supportIncludedNot included

THE CREDENTIAL

GAICC Certified ISO/IEC 27001 Foundation

The GAICC certification programme is CPD accredited.

27001 FOUNDATION

INCLUDED

This course includes

  • 200+ pages of study material
  • 16 CPD/PDU hours on completion. On renewal, 20 CPD required
  • Certificate of completion Required for exam eligibility
  • Two-day self-paced programme
  • Exam simulator access
  • Exam voucher included

Included resources to support your learning

  • ISO/IEC 27001, 27000 and 27002 standards summary
  • ISO/IEC 27001 case-study workbook
  • Annex A controls quick-reference guide
  • ISMS templates and checklists, including a Statement of Applicability

COURSE MODULES

Curriculum

Two days of self-paced study, mapped to the three exam domains and the tasks inside each.

  1. Domains I and II

    4 modules

    Security concepts, the ISO/IEC 27000 family, then Clauses 4 to 10.

    1. Information security and the ISMS

      CIA, authenticity, non-repudiation, assets, threats, vulnerabilities, risk and controls; why organisations stand up an ISMS; interested parties and the benefits they expect

    2. The standard and the ISO/IEC 27000 family

      purpose and structure of ISO/IEC 27001 (Clauses 1–3 versus 4–10, Annex SL, Annex A); 27000 vocabulary; 27002, 27003 and 27005; how 27001 sits with ISO 9001 and ISO/IEC 42001; PDCA; certification versus accreditation

    3. Context, leadership and planning (Clauses 4–6)

      internal and external issues, including climate-change relevance; interested parties and scope; policy, roles and authorities; risk assessment and treatment; the Statement of Applicability; objectives and planning of changes

    4. Support, operation, evaluation and improvement (Clauses 7–10)

      resources, competence, awareness, communication and documented information; operational control; monitoring, internal audit and management review; nonconformity and corrective action

  2. Domain III and exam prep

    4 modules

    Annex A themes, common controls, the SoA, then the audit route.

    1. Annex A control themes

      Organizational (A.5), People (A.6), Physical (A.7) and Technological (A.8), and the 93 controls in total

    2. Common controls in practice

      access control, classification, supplier and cloud security, incident management, backup and cryptography, and the purpose each control serves

    3. Statement of Applicability

      selecting controls, justifying inclusion and exclusion, and linking the SoA to risk treatment

    4. Certification lifecycle and exam readiness

      Stage 1 and Stage 2, surveillance and recertification, roles in an ISMS, plus the exam format and practice questions

GAICC ISO IEC 27001 Foundation Competence Triangle 1536x1261

CERTIFICATION DETAILS

Examination and certification

Awarding bodyGlobal AI Certification Council (GAICC)
CredentialGAICC Certified ISO/IEC 27001 Foundation
Exam format40 multiple-choice questions, online proctored
Exam duration60 minutes
Passing score70%
Validity3 years
RenewalCPD credits required
CPD/PDU earned16 on completion
Eligibility16 contact hours of structured ISO/IEC 27001 training. The self-paced course package includes training that meets this requirement.

HOW IT FITS

How it fits with standards you may already run

ISO 9001What it governsQuality managementRelationship to ISO/IEC 27001Shares the same high-level structure (Annex SL). Where 9001 governs process quality, 27001 governs how information risk is treated.
ISO/IEC 42001What it governsArtificial intelligence managementRelationship to ISO/IEC 27001The same management-system shape. 42001 governs AI systems; 27001 governs information security. Organisations often run both.

INSTRUCTOR

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

faiz

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

LinkedIn — Dr Faiz Rasool (opens in a new tab)

ENROL

Enrol on ISO/IEC 27001 Foundation

Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.

  • Self-paced course package

    US$498

    • Video lessons included
    • Learning resources
    • Exam simulator access
    • Examination voucher
    • Certificate of completion

    Membership included

  • Membership and exam package

    US$198

    • Video lessons included (not included)
    • Learning resources
    • Exam simulator access
    • Examination voucher
    • One exam retake included

    Membership included

FAQ

FAQ

What is the GAICC ISO/IEC 27001 Foundation certification?

It is GAICC’s entry-level credential for ISO/IEC 27001:2022, the international standard for an Information Security Management System. It confirms you understand the purpose of an ISMS, how the standard is structured, and the ideas behind risk, controls and certification. It does not assess whether you can implement or audit an ISMS.

Who is this training for in Malaysia?

Anyone who needs a first formal step into information security governance — IT and business staff being asked to evidence controls, junior compliance or risk officers, and people planning to continue to Lead Implementer or Lead Auditor. No prior information-security experience is required.

What are the eligibility requirements?

There is no education or work-experience requirement. You do need at least 16 contact hours of structured ISO/IEC 27001 training, completed with a GAICC-authorised provider or an equivalent recognised institution. GAICC self-paced courses also meet this. The self-paced course package on this page includes training that satisfies the hours requirement.

How is the exam set?

Forty scored, single-answer multiple-choice questions (A to D), in 60 minutes. It is closed book, sat online under proctoring or at a test centre. Items sit at Remember, Understand and Apply. The published pass mark is 70%.

Which version of the standard is examined?

ISO/IEC 27001:2022, with the ISO/IEC 27000 vocabulary and ISO/IEC 27002:2022 for the controls.

Does this let me implement or audit an ISMS?

No. Foundation is awareness-level. Implementation and audit are covered on the ISO/IEC 27001 Lead Implementer and Lead Auditor pathways.

What is the certification validity period?

The Foundation certification is valid for three years from the date it is issued.

How do I maintain or renew my certification?

In each three-year cycle you must complete at least 20 CPD hours, then submit a renewal application and the renewal fee.

What is the difference between the two packages?

The self-paced course package includes the full video course and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 training and only need the examination, membership and supporting resources.

Can I buy the exam package if I have not done the training?

No. Sixteen contact hours of structured ISO/IEC 27001 training are required before you can sit the examination. If you have not completed it, choose the self-paced course package.

Is the GAICC certification programme CPD accredited?

The GAICC certification programme is CPD accredited.

Can I enrol a team?

Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.

Certifying more than one person?

We handle group enrolment, consolidated billing and HRD Corp documentation.

Request a corporate quote