GLOBAL AI CERTIFICATION COUNCIL
ISO/IEC 27001 Lead Implementer Certification Training in Malaysia
- Earn 32 CPD/PDU hours on completion of the course
- Certification valid for three years, renewable with CPD credits
- Self-paced learning, so you can start immediately and study on your own schedule
- Two packages available, either the full course or membership and exam only
- 32 CPD/PDU hours
- 4-day programme
- HRD Corp claimable

Issued by GAICC
Global AI Certification Council


ProCert is an Affiliate Partner of the Global AI Certification Council (GAICC)


OVERVIEW
What a Lead Implementer does
ISO/IEC 27001:2022 is the standard for an Information Security Management System. Lead Implementer is the credential for the person who takes that standard off the page and into a working programme — scope, leadership, risk assessment and treatment, a defensible Statement of Applicability across 93 Annex A controls, and readiness for the certification audit.
The four-day course follows the examination blueprint: four weighted domains and a nine-module path from governance through implementation to audit and improvement, including security culture, third-party and cloud risk, and the bridge to ISO/IEC 42001.
Foundation is how the standard is read. This page is how the system is built. Completing the self-paced course package includes the video course and two attempts at the 60-item examination.
WHO IT IS FOR
Who should take this certification
Built for people who will plan and operate an ISMS, not only describe the clauses.
ISMS managers and leads standing up or running the management system
Security and risk officers responsible for treatment, controls and evidence
Compliance and GRC teams mapping ISO/IEC 27001:2022 into day-to-day work
IT and cloud leads who own operational control and supplier risk
Consultants and advisers taking a client through implementation to audit
ISO/IEC 42001 practitioners connecting an AI management system to the ISMS
OUTCOMES
What you will be able to do
By the end of the course you should be able to lead an ISMS implementation through to audit readiness.
- Define ISMS context, scope and leadership commitments aligned with ISO/IEC 27001:2022
- Conduct information security risk assessments and develop risk treatment plans
- Select and justify Annex A controls and produce a Statement of Applicability
- Plan and lead end-to-end ISMS implementation and operational control
- Embed an information security culture and manage third-party and AI-era ISMS risks
- Carry out performance evaluation, internal audit readiness and continual improvement
WHY PROCERT
Why enrol through us
Claimable by your employer
HRD Corp registered provider. Where a programme is approved, your employer can claim against their levy.
Malaysian support
A local team handling enrolment, exam booking and any questions along the way.
Team enrolment
Group registration handled end to end, with a single invoice for the whole team.
| PackageSelf-paced course package | Through ProCertUS$698 | Typical listed priceUS$798 |
|---|---|---|
| HRD Corp levy, where the programme is approved | Included | Not included |
| Malaysian enrolment and exam-booking support | Included | Not included |
THE CREDENTIAL
GAICC Certified ISO/IEC 27001 Lead Implementer
The GAICC certification programme is CPD accredited.

INCLUDED
This course includes
- 9 modules across four days
- 32 CPD/PDU hours on completion
- Certification exam included Two exam attempts included
- 60-question exam 45 single-answer MCQ plus 15 multi-answer, 90 minutes, 70% pass mark
- GAICC Certificate of Achievement and digital badge
- Exam simulator access
- Exam voucher
Included resources to support your learning
- Structural Reference and Control Map (GAICC-REF-27001-001)
- Annex A control implementation workbook
- Risk assessment and Statement of Applicability templates
- 27001 to 42001 bridge guide
COURSE MODULES
Curriculum
The nine-module learning path, structured across the four-day programme to mirror the examination blueprint.
Governance
4 modules
Context and scope of the ISMS
internal and external issues, interested parties, boundaries, interfaces and the scope statement (Clause 4)
Leadership and policy
top-management commitment, the information security policy, roles, responsibilities and authorities (Clause 5)
Planning the programme
measurable objectives, planning of changes, resourcing and the implementation plan (Clauses 6.2, 6.3)
Governance and documented information
competence, awareness, communication and the control of documents and records (Clause 7)
Implementation
3 modules
Information security risk assessment
risk criteria, asset, threat and vulnerability or scenario approaches, risk owners and ISO/IEC 27005 alignment
Risk treatment and control selection
treatment options, control selection from Annex A, residual risk acceptance and the risk treatment plan
Statement of Applicability and Annex A
inclusion and exclusion justification, mapping to 93 controls and evidence patterns across the four themes
Audit and improvement
2 modules
Performance evaluation and audit
metrics and KPIs, the internal audit programme and management review (Clauses 9.1 to 9.3)
Improvement and AI-era ISMS
nonconformity and corrective action, certification readiness, third-party risk and the 27001 to 42001 bridge (Clause 10)


THE EXAM
Four domains, weighted for the real job
Each domain carries a defined weight and item count across the 60-item examination.
I · ISMS Governance, Context and Leadership
25% · 15 items
II · ISMS Implementation and Operational Control
40% · 24 items
III · Performance Evaluation, Audit Readiness and Improvement
20% · 12 items
IV · Security Culture, Third-Party Risk and AI-Era ISMS
15% · 9 items
Exam structure at a glance
- 60 scored items — 45 single-answer MCQ plus 15 multi-answer
- 90 minutes, closed book, online AI-proctored or test-centre
- 70% pass mark
- Valid three years, renewable with CPD credits
- Standard — ISO/IEC 27001:2022, with 27002 / 27003 / 27005 guidance
- Credential — GAICC Certified ISO/IEC 27001 Lead Implementer
- Issuer — Global AI Certification Council (GAICC)
HOW IT FITS
How it fits with standards you may already run
| Standard | What it governs | Relationship to ISO/IEC 27001 |
|---|---|---|
| ISO 9001 | What it governsQuality management | Relationship to ISO/IEC 27001Shares the same high-level structure. Where 9001 governs process quality, 27001 governs how information risk is treated. |
| ISO/IEC 42001 | What it governsArtificial intelligence management | Relationship to ISO/IEC 27001The same management-system shape. Domain IV of this exam covers the AI-era ISMS and the 27001 to 42001 bridge. |
| ISO/IEC 27701 | What it governsPrivacy information management | Relationship to ISO/IEC 27001Overlaps where the ISMS processes personal data. Privacy controls and information-security controls are complementary rather than duplicative. |
INSTRUCTOR
Dr Faiz Rasool
Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.
LinkedIn — Dr Faiz Rasool (opens in a new tab)ENROL
Enrol on ISO/IEC 27001 Lead Implementer
Choose a package and enter your name and email. If you choose the membership and exam package, you must confirm you have completed the required training.
Most popular
Self-paced course package
US$698
- Video lessons included
- Learning resources
- Exam simulator access
- Two exam attempts included
- Certificate of completion
Membership and exam package
US$248
- Video lessons included (not included)
- Learning resources
- Exam simulator access
- Examination voucher
Membership included
FAQ
FAQ
What is the GAICC ISO/IEC 27001 Lead Implementer certification?
It is GAICC’s implementer-level credential for ISO/IEC 27001:2022. A Lead Implementer plans, builds and operates an Information Security Management System — context and scope, leadership, risk assessment and treatment, the Statement of Applicability, Annex A controls, and readiness for the certification audit.
Who is this training for in Malaysia?
ISMS managers and leads, security and risk officers, compliance and GRC teams, IT and cloud leads, consultants taking a client to audit, and ISO/IEC 42001 practitioners connecting an AI management system to the ISMS.
How is the exam set?
Sixty scored items: 45 single-answer multiple-choice questions and 15 multi-answer items, sat in 90 minutes, closed book. Delivery is online AI-proctored or at a test centre. The published pass mark is 70%.
Which version of the standard is examined?
ISO/IEC 27001:2022, with supporting guidance from ISO/IEC 27002, 27003 and 27005. The course lists clause and control references and titles only; the normative text of the standard is not reproduced.
How long is the certification valid, and how do I renew it?
The credential is valid for three years and may be renewed with CPD credits.
How many CPD hours will I earn?
You receive 32 CPD/PDU hours on completion of the Lead Implementer course.
How many exam attempts are included?
The self-paced course package includes two exam attempts.
What happens if I do not pass the exam?
The self-paced course package includes two attempts. A further sitting after those attempts requires the applicable exam fee.
What is the difference between the two packages?
The self-paced course package includes the full video course, two exam attempts and everything needed to prepare from scratch. The membership and exam package is for candidates who have already completed their ISO/IEC 27001 Lead Implementer training and only need the examination, membership and supporting resources.
Can I buy the exam package if I have not done the training?
No. If you have not completed the training, choose the self-paced course package.
How is this different from ISO/IEC 27001 Foundation?
Foundation is the two-day credential for people who need to read the standard. Lead Implementer is the four-day credential for the person who builds and operates the ISMS and takes it to certification audit.
How does this relate to ISO/IEC 42001?
Domain IV covers the AI-era ISMS and the 27001 to 42001 bridge, including AI-related information-security risks and integrating the ISMS with an ISO/IEC 42001 AI management system.
Is the GAICC certification programme CPD accredited?
The GAICC certification programme is CPD accredited.
Can I enrol a team?
Yes. Group rates apply for five or more. Contact us for a corporate quote and consolidated invoicing.
Certifying more than one person?
We handle group enrolment, consolidated billing and HRD Corp documentation.
