Next PMP® classroom cohort: 28 Sept - 2 Oct 2026, Kuala Lumpur. Reserve your seat

ProCert

GLOBAL AI CERTIFICATION COUNCIL

ISO/IEC 27001 Lead Implementer Certification Training in Malaysia

  • Earn 32 CPD/PDU hours on completion of the course
  • Certification valid for three years, renewable with CPD credits
  • Self-paced learning, so you can start immediately and study on your own schedule
  • Two packages available, either the full course or membership and exam only
  • 32 CPD/PDU hours
  • 4-day programme
  • HRD Corp claimable
openart gpt image 2 1 1788971265017 be0053c0

Issued by GAICC

Global AI Certification Council

WhatsApp Image 2026 08 29 at 16.01.23 removebg preview
Untitled design (27)

ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)

HRD Corp claimable
HRD Corp Registered Training Provider

OVERVIEW

What a Lead Implementer does

ISO/IEC 27001:2022 is the standard for an Information Security Management System. Lead Implementer is the credential for the person who takes that standard off the page and into a working programme — scope, leadership, risk assessment and treatment, a defensible Statement of Applicability across 93 Annex A controls, and readiness for the certification audit.

The four-day course follows the examination blueprint: four weighted domains and a nine-module path from governance through implementation to audit and improvement, including security culture, third-party and cloud risk, and the bridge to ISO/IEC 42001.

Foundation is how the standard is read. This page is how the system is built. Completing the self-paced course package includes the video course and two attempts at the 60-item examination.

WHO IT IS FOR

Who should take this certification

Built for people who will plan and operate an ISMS, not only describe the clauses.

OUTCOMES

What you will be able to do

By the end of the course you should be able to lead an ISMS implementation through to audit readiness.

  • Define ISMS context, scope and leadership commitments aligned with ISO/IEC 27001:2022
  • Conduct information security risk assessments and develop risk treatment plans
  • Select and justify Annex A controls and produce a Statement of Applicability
  • Plan and lead end-to-end ISMS implementation and operational control
  • Embed an information security culture and manage third-party and AI-era ISMS risks
  • Carry out performance evaluation, internal audit readiness and continual improvement

WHY PROCERT

Why enrol through us

  1. Claimable by your employer

    HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.

  2. Malaysian support

    A local team handling enrolment, exam booking and any questions along the way.

  3. Team enrolment

    Group registration handled end to end, with a single invoice for the whole team.

Self-paced course package: Through ProCert US$698 versus typical listed price US$798
PackageSelf-paced course packageThrough ProCertUS$698Typical listed priceUS$798
HRD Corp levy, where the programme is approvedIncludedNot included
Malaysian enrolment and exam-booking supportIncludedNot included

THE CREDENTIAL

GAICC Certified ISO/IEC 27001 Lead Implementer

The GAICC certification programme is CPD accredited.

GAICC ISOIEC 42001 Lead Implementer Certification (1)

INCLUDED

This course includes

  • 9 modules across four days
  • 32 CPD/PDU hours on completion
  • Certification exam included Two exam attempts included
  • 60-question exam 45 single-answer MCQ plus 15 multi-answer, 90 minutes, 70% pass mark
  • GAICC Certificate of Achievement and digital badge
  • Exam simulator access
  • Exam voucher

Included resources to support your learning

  • Structural Reference and Control Map (GAICC-REF-27001-001)
  • Annex A control implementation workbook
  • Risk assessment and Statement of Applicability templates
  • 27001 to 42001 bridge guide

COURSE MODULES

Curriculum

The nine-module learning path, structured across the four-day programme to mirror the examination blueprint.

  1. Governance

    4 modules

    1. Context and scope of the ISMS

      internal and external issues, interested parties, boundaries, interfaces and the scope statement (Clause 4)

    2. Leadership and policy

      top-management commitment, the information security policy, roles, responsibilities and authorities (Clause 5)

    3. Planning the programme

      measurable objectives, planning of changes, resourcing and the implementation plan (Clauses 6.2, 6.3)

    4. Governance and documented information

      competence, awareness, communication and the control of documents and records (Clause 7)

  2. Implementation

    3 modules

    1. Information security risk assessment

      risk criteria, asset, threat and vulnerability or scenario approaches, risk owners and ISO/IEC 27005 alignment

    2. Risk treatment and control selection

      treatment options, control selection from Annex A, residual risk acceptance and the risk treatment plan

    3. Statement of Applicability and Annex A

      inclusion and exclusion justification, mapping to 93 controls and evidence patterns across the four themes

  3. Audit and improvement

    2 modules

    1. Performance evaluation and audit

      metrics and KPIs, the internal audit programme and management review (Clauses 9.1 to 9.3)

    2. Improvement and AI-era ISMS

      nonconformity and corrective action, certification readiness, third-party risk and the 27001 to 42001 bridge (Clause 10)

GAICC ISO IEC 42001 Lead Implementer Competence Triangle 1024x841 (1)

THE EXAM

Four domains, weighted for the real job

Each domain carries a defined weight and item count across the 60-item examination.

  1. I · ISMS Governance, Context and Leadership

  2. II · ISMS Implementation and Operational Control

  3. III · Performance Evaluation, Audit Readiness and Improvement

  4. IV · Security Culture, Third-Party Risk and AI-Era ISMS

Exam structure at a glance

  • 60 scored items — 45 single-answer MCQ plus 15 multi-answer
  • 90 minutes, closed book, online AI-proctored or test-centre
  • 70% pass mark
  • Valid three years, renewable with CPD credits
  • Standard — ISO/IEC 27001:2022, with 27002 / 27003 / 27005 guidance
  • Credential — GAICC Certified ISO/IEC 27001 Lead Implementer
  • Issuer — Global AI Certification Council (GAICC)

HOW IT FITS

How it fits with standards you may already run

ISO 9001What it governsQuality managementRelationship to ISO/IEC 27001Shares the same high-level structure. Where 9001 governs process quality, 27001 governs how information risk is treated.
ISO/IEC 42001What it governsArtificial intelligence managementRelationship to ISO/IEC 27001The same management-system shape. Domain IV of this exam covers the AI-era ISMS and the 27001 to 42001 bridge.
ISO/IEC 27701What it governsPrivacy information managementRelationship to ISO/IEC 27001Overlaps where the ISMS processes personal data. Privacy controls and information-security controls are complementary rather than duplicative.

INSTRUCTOR

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

faiz

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

LinkedIn — Dr Faiz Rasool (opens in a new tab)

ENROL

Enrol on ISO/IEC 27001 Lead Implementer

Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.

  • Self-paced course package

    US$698

    • Video lessons included
    • Learning resources
    • Exam simulator access
    • Two exam attempts included
    • Certificate of completion
  • Membership and exam package

    US$248

    • Video lessons included (not included)
    • Learning resources
    • Exam simulator access
    • Examination voucher

    Membership included

FAQ

FAQ

What is the GAICC ISO/IEC 27001 Lead Implementer certification?

It is GAICC’s implementer-level credential for ISO/IEC 27001:2022. A Lead Implementer plans, builds and operates an Information Security Management System — context and scope, leadership, risk assessment and treatment, the Statement of Applicability, Annex A controls, and readiness for the certification audit.

Who is this training for in Malaysia?

ISMS managers and leads, security and risk officers, compliance and GRC teams, IT and cloud leads, consultants taking a client to audit, and ISO/IEC 42001 practitioners connecting an AI management system to the ISMS.

How is the exam set?

Sixty scored items: 45 single-answer multiple-choice questions and 15 multi-answer items, sat in 90 minutes, closed book. Delivery is online AI-proctored or at a test centre. The published pass mark is 70%.

Which version of the standard is examined?

ISO/IEC 27001:2022, with supporting guidance from ISO/IEC 27002, 27003 and 27005. The course lists clause and control references and titles only; the normative text of the standard is not reproduced.

How long is the certification valid, and how do I renew it?

The credential is valid for three years and may be renewed with CPD credits.

How many CPD hours will I earn?

You receive 32 CPD/PDU hours on completion of the Lead Implementer course.

How many exam attempts are included?

The self-paced course package includes two exam attempts.

What happens if I do not pass the exam?

The self-paced course package includes two attempts. A further sitting after those attempts requires the applicable exam fee.

What is the difference between the two packages?

The self-paced course package includes the full video course, two exam attempts and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 Lead Implementer training and only need the examination, membership and supporting resources.

Can I buy the exam package if I have not done the training?

No. If you have not completed the training, choose the self-paced course package.

How is this different from ISO/IEC 27001 Foundation?

Foundation is the two-day credential for people who need to read the standard. Lead Implementer is the four-day credential for the person who builds and operates the ISMS and takes it to certification audit.

How does this relate to ISO/IEC 42001?

Domain IV covers the AI-era ISMS and the 27001 to 42001 bridge, including AI-related information-security risks and integrating the ISMS with an ISO/IEC 42001 AI management system.

Is the GAICC certification programme CPD accredited?

The GAICC certification programme is CPD accredited.

Can I enrol a team?

Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.

Certifying more than one person?

We handle group enrolment, consolidated billing and HRD Corp documentation.

Request a corporate quote