Security Compliance: GDPR, ISO 27001, and Risk Documentation

Compliance work is often misunderstood as purely administrative. In practice, it requires translating technical realities into documented controls, justifying decisions to auditors, and keeping records that hold up under scrutiny. This course covers that translation work.
Frameworks covered
The course focuses on ISO/IEC 27001 and GDPR, with references to NIST CSF where relevant. You will not become a certified auditor by the end — that requires formal examination — but you will understand what auditors look for and how to prepare documentation that reflects actual practice.
ISO 27001 in practice
You will work through the structure of an Information Security Management System — scope definition, risk assessment, statement of applicability, and control implementation. Real examples of documentation are used throughout, including gap analysis templates.
GDPR obligations for security teams
The course covers data mapping, lawful basis for processing, breach notification timelines, and the technical measures GDPR requires. This is not a legal course — it addresses the security team's role in compliance, not legal interpretation.
Each module includes a documentation exercise. By the end, you will have a set of draft documents — risk register, asset inventory, and a sample ISMS policy — that you can adapt for your organization.
An audit does not measure how secure you are. It measures how well you can demonstrate what you have done and why.This course is relevant for those preparing for ISO 27001 Lead Implementer or Lead Auditor exams as background study.
-
Compliance Frameworks Overview
ISO 27001, NIST CSF, and GDPR — structure, purpose, and differences.
-
Information Security Management Systems
ISMS scope, policies, and governance structure.
-
Asset Inventory and Classification
Identifying information assets and assigning ownership.
-
Risk Assessment and Treatment
Risk identification, likelihood/impact matrices, and treatment options.
-
ISO 27001 Controls (Annex A)
Reviewing the control set, selecting applicable controls, and writing the Statement of Applicability.
-
GDPR Technical Requirements
Data mapping, privacy by design, breach notification, and DPO responsibilities.
-
Internal Audit Preparation
Audit checklists, evidence collection, and nonconformity handling.
-
Documentation Workshop
Building a draft risk register, asset inventory, and ISMS policy set.
