G-CERTI TRAINING · ACADEMIC PROGRAM
ISO/IEC 27001
Diploma in Information Security · ISO/IEC 27001
REVIEW OF CONTROLS IN A SERVER ROOM
To train professionals able to assess information security risks, select and justify Annex A controls in a statement of applicability, sustain the system before clients and auditors, and audit it as a lead auditor.
Current.



THE PROGRAM ON ONE PAGE
Ten modules, three stages, threecertificates.
To train professionals able to assess information security risks, select and justify Annex A controls in a statement of applicability, sustain the system before clients and auditors, and audit it as a lead auditor.
Módulos 1
Módulos 2, 3, 4
Stage I assessment · CERTIFICATE I · Management Systems Design
Módulos 5, 6, 7
Stage II assessment · CERTIFICATE II · Internal Audit
Módulos 8, 9
Stage III assessment · CERTIFICATE III · Lead Auditor
Módulos 10
Informational document. Enrolment terms are confirmed in writing upon registration.
STARTING POINTS
Five ways to reach thisprogram.
El módulo 1 nivela. Se entra desde distintos puntos y se termina en el mismo lugar: diseñando, implementando y auditando un sistema de information security.
TODAY ·Sostiene el sistema de information security and IT y responde auditorías sin haberlo diseñado.
UPON COMPLETION ·Diseña el sistema completo y lo audita con criterio propio.
TODAY ·Implementa sistemas por encargo y necesita respaldo internacional que lo acredite.
UPON COMPLETION ·Presenta tres certificados de competencias verificables por código y QR.
TODAY ·Conoce la norma pero nunca condujo una auditoría de tercera parte.
UPON COMPLETION ·Dirige una auditoría completa: apertura, evidencia, hallazgos, cierre e informe.
TODAY ·Trabaja en development, infrastructure or risk y entra al campo de information security desde cero.
UPON COMPLETION ·Nivela en el módulo 1 y termina auditando con la misma vara que el resto.
TODAY ·Responde por la certificación de a software company, a service provider or an IT department ante clientes y auditores.
UPON COMPLETION ·Prepara la organización, audita por dentro y sostiene los hallazgos.
No prerequisites: module 1 levels the field. Basic familiarity with the case organization's IT infrastructure or services is recommended.
WHY NOW
La demanda no viene de la moda: viene del cycle.
The certification cycle lasts three years.
Nearly all the standards were revised together: certified systems have to transition.
Auditing requires demonstrated competence (ISO/IEC 17021-1), not just having completed a course.
Every system needs someone inside to sustain it between audits.
Certification is demanded throughout the supply chain: clients, tenders and suppliers require it.
THREE CERTIFICATES PER DIPLOMA PROGRAM
Three stages, three certificates.
Anyone who completes a diploma program receives three competency certificates under a single professional credential. All with a code and QR, verifiable in the same console as organization certificates.
I · Management Systems Design
Design the standard's complete management system: context and scope, policy, risks, documentation, operation, indicators and improvement.
RESPALDO IAC · EVALUACIÓN DE ETAPA
II · Internal Audit
Plan and conduct the internal audit —a first-party audit— based on the ISO 19011 cycle: program, plan, checklist, findings, report and follow-up.
RESPALDO IAC · EVALUACIÓN DE ETAPA
III · Lead Auditor
Conduct second- and third-party audits: lead the audit team, manage the opening and closing meetings, defend findings before the auditee and sign the report.
RESPALDO IAC + VALIDACIÓN GCT · MESA ADICIONAL
G-CERTI Training academic certificates. They document training and evaluated evidence; they do not certify individuals or grant professional authorization.
TECHNICAL SHEET
Diploma in Information Security · ISO/IEC 27001
CLAUSE MAP
Which clause each one works onmodule.
CL. 4 · Context
CL. 5 · Leadership
CL. 6 · Planning
CL. 7 · Support
CL. 8 · Operation
CL. 9 · Performance evaluation
CL. 10 · Improvement
A · Annex A · 93 controls
19011 · ISO 19011
17021 · ISO/IEC 17021-1
Stage I assessment · CERTIFICATE I · Management Systems Design
Stage II assessment · CERTIFICATE II · Internal Audit
Stage III assessment · CERTIFICATE III · Lead Auditor
CURRICULUM · MODULES 1 TO 5
Level up, get to know the standard and start toimplement it.
Introduction to management systems
- What a management system is and what it solves in an organization
- Harmonized structure (Annex SL): the ten common clauses
- PDCA cycle, process approach and risk-based thinking
- Confidentiality, integrity and availability; the ISO/IEC 27000 family
Context, scope and leadership
- Internal and external issues; interested parties and legal, regulatory and contractual requirements
- Scope of the ISMS: boundaries, interfaces and dependencies
- Leadership, information security policy and roles
- Security governance: committee, asset owners and risk owners
Requirements of ISO/IEC 27001:2022 and Annex A
- Complete reading of clauses 4 to 10 with expected evidence
- Annex A: 93 controls across four themes (organizational, people, physical, technological)
- Control attributes and their use in ISO/IEC 27002
- Changes from the 2013 edition
Risk assessment and treatment
- Methodology: acceptance criteria, identification, analysis and evaluation
- Risk owners; assets, threats and vulnerabilities
- Treatment options; selection of controls and statement of applicability
- Risk treatment plan and security objectives
Support, operation and controls
- Resources, competence, awareness and communication
- Operational planning and control; execution of the treatment plan
- Organizational and people controls: policies, roles, suppliers, incidents, continuity
- Physical and technological controls: access, cryptography, logging, configuration, secure development
CURRICULUM · MODULES 6 TO 10
Measure, audit, lead the audit and follow up for a yearmore.
Performance evaluation
- Monitoring, measurement, analysis and evaluation of control effectiveness
- Security metrics and incident management as a source
- ISMS internal audit program
- Management review
Improvement and system project
- Nonconformity and corrective action; lessons from incidents
- Continual improvement and risk update
- Closing of the complete ISMS on the case study
- Instructor feedback on the reasoning
ISMS internal audit under ISO 19011
- Audit program and plan; competence of the audit team
- Checklist by clause with expected evidence
- Interview, record sampling and process observation
- Drafting findings with evidence; report and follow-up of actions
Lead auditor · ISO/IEC 27001 Auditor Lab
- Simulated third-party audit on the case study, with real roles
- Opening meeting; leading and coordinating the audit team
- Control audit: sampling of access, logs, configurations and technical evidence against the statement of applicability
- Classification of nonconformities, closing meeting and signed report
Professional community · 12 months
- Weekly Auditor Lab: a simulated audit on a different case each week
- Business Lab: what the standard requires from management and how decisions are made with the system
- Academic interviews with practicing auditors
- Updates: ISO/IEC 27002, 27005, 27701 (privacy), ISO 19011
THREE CERTIFICATES PER DIPLOMA PROGRAM
One document, threecompetencies.
GLOBAL CERTIFICATION
PROFESSIONAL TRAINING · SAMPLE
COMPETENCY CERTIFICATE
GLOBAL CERTIFICATION certifies that
Holder's name
has completed and passed the educational program and its evaluation.
CERTIFICATE III · Lead Auditor
Conduct second- and third-party audits: lead the audit team, manage the opening and closing meetings, defend findings before the auditee and sign the report.



SAMPLE · NOT AN ISSUED DOCUMENT
Global Certification · G-CERTI Co., Ltd. · IAC
They are issued upon passing the stage assessment.

IAC + GCT validation
In addition to the Audit stage assessment, an additional validation panel is taken before GCT, the technical network of auditors. The certificate is issued with both endorsements.


I · Management Systems Design MANAGEMENT SYSTEMS SPECIALIST
II · Internal Audit INTERNAL AUDITOR
III · Lead Auditor LEAD AUDITOR
ASSESSMENT SYSTEM
The work is evaluated, not theattendance.
Each stage closes with an assessment that looks at the work submitted on the case, not attendance. Completing activities does not guarantee passing. Once the stage is passed, the corresponding certificate is issued; all three are earned in order.
FACULTY
Cesar Siambasi
COHORTS WITH LIVE CLASSES
Gestión de Seguridad de la Información
Cesar Siambasi · 19:00 to 21:00 · Argentina (UTC−3) · 16 clases
Live sessions in Spanish. The diploma program is completed on campus with access from enrollment; these dates are the cohorts with live classes.
THE PROFESSIONAL COMMUNITY
The auditor community of G-CERTI.
If you take a diploma program, you join the community the same day and stay for twelve months: real cases, weekly labs, standards updates and tools.
INCLUDED WITH EVERY DIPLOMA PROGRAM · 12 MONTHS · NO ADDITIONAL COST
A field situation, no names
The case is published: context, available evidence and the question an auditor would need to answer. It is discussed among peers until Thursday.
Simulated audit with four roles
Auditor, auditee, evidence and observer. Interview, sampling, drafting the finding. A professional gives feedback on the reasoning.
Managing with the system
For decision-makers: reading an audit report, using indicators to govern risk, presenting the system to a client or a board.
What changed and how an audit changes
Short session for those already familiar with the standard: standard transitions, ISO 19011, amendments, AI for auditors, interviews with practicing auditors.
AUDITOR LAB · ROLES
AUDITOR · Conducts the interview, requests evidence and upholds a finding.
AUDITEE · Responds from within the process, like a real organization.
EVIDENCE · Records, procedures and indicators prepared for the case.
OBSERVER · Records what happened and gives feedback on the reasoning.
OPEN TOOLS
Auditor assistant · Educational guidance on audit method and standards, with stated limits.
Standard selector · One or more needs are selected and the corresponding ISO references appear.
Standard comparison · Ten published pairs, side by side: what each standard covers and how they relate.
ISO glossary · The terms that appear in an audit, defined in plain language.
G-CERTI AUDITORS DIVISION
Auditors Division of G-CERTI.
The auditors G-CERTI works with, organized by standard and sector. Entry is by application and review of track record.
Those who completed a diploma program have priority for admission, and enrollment is free of charge when the requirements are met: neither the interview nor operating costs are charged.
Training prepares; admission is decided by the Division.
THE PATH
The technical foundation of the standard and the management system. G-CERTI diploma program per standard, or equivalent training with documented support.
The focus on the scheme or sector in which you will work. Declared standards and practice sector, with specific cases.
Effective participation in audits. Internal, second-party or certification audits, with role and responsibility described.
The capabilities observed in actual performance. It is assessed in the admission interview and in the criteria boards.
The stage that reviews the profile against the applicable requirements. Human review of the profile and interview; the result is communicated in writing.
ADMISSION
- Application · A three-step form: who you are, level of training and reason. You receive a reference number upon submission.
- Profile review · The team reviews track record, declared standards and practice. The review is done by people; additional documentation may be requested.
- Admission interview · A conversation about cases and criteria. Free of charge for G-CERTI graduates who meet the requirements; for everyone else, the interview and operating costs are payable by the applicant.
- Admission to the Division · If the application is accepted, admission, conditions and scope of participation by standard and sector are confirmed in writing.
- Practice and continuity · Criteria boards, technical meetings and an update schedule. Continuity sustains membership.
WHAT MEMBERSHIP PROVIDES
- A professional profile within G-CERTI's body of auditors.
- Criteria panels with peers to contrast difficult decisions.
- Standards update agenda and a monthly technical meeting.
- Consideration for projects and calls with partners.
- Field tools and a personal practice logbook.
WHAT IT IS NOT
- It is not a professional licence nor a register of certified persons.
- It does not guarantee work assignments, audits or income.
- Submitting the application does not confirm admission.
WHAT GRADUATES SAY
I completed the Diploma in Quality Management. Very good course and learning experience.
FERNANDO SANTAMARINA
Excellent institution with outstanding educational and human quality.
NICOLÁS CERNADAS
The account executives' attention is very courteous.
YAMIL MAIDANA
GOOGLE · 4,9 / 5 · 638 RESEÑAS
INVESTMENT
USD 999 por diploma program.
The discount applies when enrolling in several diploma programs in the same purchase. Reference amounts; confirmed in writing before enrollment.
Enrollment is done from the diploma program page or with your account executive. No payment is required in this document.



ACADEMIC PROGRAMME · 2026-27 EDITION · IN EFFECT FROM SEPTEMBER 2026 · ACADEMIC DIRECTION · G-CERTI TRAINING