ISO/IEC 27001 Foundation
The vocabulary, the clause structure and the Annex A control set, the grounding every other program on this page assumes you already have.
Advance your career through internationally aligned professional learning programs: taught by practitioners, worked through real case material, and examined properly. Six tracks below. Pick one, or tell us what your team needs.
Category 01
For people who have to build, run or audit an information security management system against ISO/IEC 27001:2022, from first principles to leading the audit team.
The vocabulary, the clause structure and the Annex A control set, the grounding every other program on this page assumes you already have.
Lead a full ISMS audit against ISO/IEC 27001:2022: planning, opening meeting, evidence sampling, nonconformity writing, reporting and follow-up.
The other side of the table: scoping, risk assessment and treatment, Statement of Applicability, and getting a management system certification-ready without drowning it in documentation.
Run the clause 9.2 internal audit programme in your own organisation: checklists that ask the right question, sampling that stands up, and findings your management review can act on.
The short, non-technical session that satisfies your awareness control and actually changes behaviour: phishing, handling, reporting, and why it matters.
Category 02
ISO/IEC 42001 arrived in December 2023 and boards started asking about it almost immediately. These programs are for the people who now have to answer.
What an AI management system is, what the standard requires, and how the Annex A controls map onto the way your organisation actually builds and buys AI.
Audit an AI management system end to end: AI policy, roles, impact assessment, data governance, lifecycle controls and the Annex A control set.
Stand an AIMS up: scope, AI risk and impact assessment, supplier and model inventory, and the evidence trail that makes the whole thing auditable.
For risk, legal, product and engineering leads: governance structures, accountability, and where ISO/IEC 42001, the EU AI Act and the NIST AI RMF converge and diverge.
Fairness, transparency, human oversight and harm assessment: turned from principles into checks a team can run before a model ships, and an auditor can test afterwards.
Category 03
The management layer above the controls: who decides, on what evidence, against which obligation, and how you show that to a regulator, a customer or a board.
Running the security function itself: policy architecture, budget and headcount cases, metrics that mean something, and reporting into management review.
One control set, many obligations. Build an integrated governance, risk and compliance model instead of auditing the same evidence five times a year.
Risk identification, analysis, evaluation and treatment done to ISO 31000 discipline , including how to stop a risk register becoming a spreadsheet nobody reads.
Build and maintain a compliance obligations register, assign ownership, and evidence conformity across overlapping regulatory and contractual requirements.
The Cybersecurity Framework, SP 800-53 and the AI RMF: what each is for, how they fit together, and how they map onto an ISO management system you already run.
Governance and management objectives for enterprise IT: design factors, capability levels, and how COBIT complements rather than duplicates ISO/IEC 27001.
Category 04
India's DPDP Act, the GDPR and the standards that operationalise both: for the people who now have to answer “where is that personal data, and on what basis?”
The Digital Personal Data Protection Act in plain terms: who is a Data Fiduciary, what consent has to look like, breach notification, and what it means for your team.
Lawful bases, data subject rights, DPIAs, international transfers and the accountability principle, for teams serving EU customers from India.
The full practitioner track: privacy programme design, records of processing, vendor due diligence, breach response and running privacy across multiple jurisdictions.
Data mapping, retention, minimisation and privacy by design, the operating practices that make a privacy policy true rather than aspirational.
Extend an ISMS into a PIMS: controller and processor duties, records of processing, and mapping the control set to both GDPR and the DPDP Act.
Category 05
The disciplines every other standard borrows from: process thinking, risk-based planning, and continual improvement that survives contact with an auditor.
Lead a quality management system audit to ISO 19011 practice: audit programme, process approach, evidence, nonconformity grading and the closing meeting.
Design a QMS people actually use: context and interested parties, process mapping, documented information kept proportionate, and internal audit that finds real problems.
Audit a business continuity management system: BIA quality, recovery objectives, continuity strategy, and whether the exercise programme proves anything.
Business impact analysis, recovery objectives, continuity strategy and exercise design , built so the plan works on the day you actually need it.
On ISO 9001:2026. The revised edition is scheduled for publication in September 2026. Our material covers the current edition and flags every change ahead, and a short transition program will be published once the standard is released. Ask us if you are mid-cycle.
Category 06
Structured preparation for the four credentials hiring managers actually ask for. Domain-by-domain coverage, practice questions, and exam technique from people who have sat them.
All five domains of the Certified Information Systems Auditor exam: audit process, IT governance, acquisition, operations and asset protection.
Information security governance, risk management, programme development and incident management: the four domains, taught as a manager is expected to think.
The eight CBK domains at the depth the exam expects, with the risk-management mindset that decides most of the questions you will find ambiguous.
Cloud security architecture, data lifecycle, platform and infrastructure security, and the legal and compliance domain that catches most candidates out.
To be clear: CISA and CISM are awarded by ISACA; CISSP and CCSP by ISC2. ZULTIV prepares you for those examinations and does not award those credentials. You register and sit the exam with the awarding body directly, and their experience requirements apply.
Category 07
Same standards, rebuilt around your scope statement, your control set and the systems your people actually log into every morning.
Schedule
All sessions run in India Standard Time. If the date you need is not listed, ask, we open additional batches when there is demand.
| Program | Dates | Mode | Status | Action |
|---|---|---|---|---|
| ISO/IEC 27001 Lead Auditor | To be announced | Live online | Registering | Enquire |
| ISO/IEC 42001 Lead Auditor | To be announced | Live online | Registering | Enquire |
| ISO/IEC 27001 Lead Implementer | To be announced | Live online | Registering | Enquire |
| ISO 9001 Lead Auditor | To be announced | Live online | Waitlist | Enquire |
| ISO 22301 Lead Auditor | To be announced | Live online | Waitlist | Enquire |
| Data Privacy Professional | To be announced | Live online | Waitlist | Enquire |
| CISA Preparation | To be announced | Live online | Waitlist | Enquire |
Before you enrol