Course Content
MODULE 1 — Core ISO 27001 Training
0/17
MODULE 2 — Greenfield University Case Study | Education Sector Applied Learning
0/2
Interactive hands-on ISO27001
GRC Training Programme — Series Overview | Unlimited SkiesTech LLC
The Complete GRC Training Programme · ISO 27001:2022

The Most Interactive
GRC Programme
Ever Built

15 series. Real scenarios. Real policies. Real evidence. You do not just learn about ISO 27001 — you build the ISMS, conduct the audit, respond to the incident, chair the management review, and defend every control to the certification auditor. Built for the GRC professional who wants to do the job, not just know about it.

15
Series
93
Controls Mapped
18
Policies Written
100+
Think-First Challenges
20
Mock Auditor Questions
Scenario throughout: Nexora Health Technologies Ltd — UK SaaS startup processing NHS patient data. 85 staff. Series B funded. Pursuing ISO 27001 certification in 6 months. Every series uses real Nexora decisions, real Nexora risks, and real Nexora evidence — so you always know what you are building and why.
Filter:
🏥 The Nexora Scenario
One Company. One ISMS. The Complete Journey.
Every series follows Nexora Health Technologies Ltd — a real company with real problems. You are the GRC Analyst. You join at Series 0 when the CISO says "we need ISO 27001 in 6 months" and you leave at Series 14 having managed supplier risk, survived a ransomware attack, chaired a management review, and defended your controls to a real auditor. The scenario is continuous — every decision you make in one series has consequences in the next.
112
Staff at Nexora
10
Risks in Register
18
ISMS Policies
2
Real Incidents
🏗️
Foundation — Before You Build Anything
2 series
Series 0
💥
The CISO Says We Are Getting Certified
Monday morning. The CISO walks in. "We need ISO 27001 in 6 months." You are the GRC Analyst. Where do you even begin? Live dialogue, 6-month project plan, Day 1 gap analysis, the team you need, Stage 1 vs Stage 2 explained, and the 7 things that kill certification projects.
ISO 27001 IntroProject PlanningGap Analysis7 Scenes
7 scenes · Interactive dialogue · 5-question quiz
Start →
Series 1
⚖️
GDPR Foundation
Why data protection law exists and how it drives every ISO 27001 decision. 7 principles, 8 rights, 6 legal bases, 72-hour breach response, GDPR vs ISO 27001 mapping, sector scenarios. The foundation everything else is built on.
UK GDPRDPA 2018Breach Response8 Sections
8 tabbed sections · Sector scenarios · Quiz
Start →
🔧
Build the ISMS — Policies, Risk, Controls
8 series
Series 2
🛡️
ISO 27001 Overview + All Clauses
What ISO 27001 actually is — and how it works. The ISMS concept, the Plan-Do-Check-Act cycle, and a clause-by-clause walkthrough of Clauses 4–10. Every requirement explained in plain English with Nexora context.
Clauses 4–10PDCA Cycle12 Tabs
12 tabbed sections · All mandatory clauses
Start →
Series 3
🏷️
Data Classification
Restricted. Confidential. Internal. Public. How to classify every piece of information at Nexora — and what handling rules apply to each level. Interactive decision tree, sector scenarios, and the GRC Analyst's role in maintaining classification.
Classification LevelsDecision TreeAnnex A.5.12
8 sections · Interactive decision tree
Start →
Series 4
🧑‍💻
The GRC Analyst Role
Day in the life at Nexora. The skills triangle (governance, risk, compliance). Career path from junior analyst to CISO. Salary bands. Interview prep. Reporting lines and stakeholder map. What the job actually looks like — not what the job description says.
Career PathDay in the LifeSkillsInterview Prep
8 sections · Timeline · Salary data
Start →
Series 5
🗺️
ISMS Scoping
Define exactly what is in — and out — of the ISMS. Too broad and you cannot evidence it. Too narrow and the auditor finds a breach in an out-of-scope system. Write the Nexora scope statement, handle exclusions, and defend it in the audit room.
Clause 4.3Scope StatementExclusions
6 phases · Scope document · Audit room simulation
Start →
Series 6
⚠️
Risk Assessment
Build Nexora's complete Risk Register from scratch. Identify, score (likelihood × impact), and treat all 10 key risks — from ransomware to wrong-email recipients. Treatment decisions: modify, transfer, accept, avoid. Then defend every decision in the audit room.
Risk RegisterScoringTreatmentClause 6.1
6 phases · Live risk register · 10 Nexora risks
Start →
Series 7
📋
The Complete Policy Foundation
The 5-link policy chain: Law → Risk → Policy → Control → Evidence. All 32 ISO 27001 policies explained. Nexora's priority order. 6 core policies written in full. Evidence and audit room defence for every policy. What good looks like vs what creates findings.
32 PoliciesPolicy ChainAnnex A.5.17 Tabs
7 tabbed sections · 6 full policy documents
Start →
Series 7B
☁️
Technical Controls & Cloud Policies
6 technical policies written using the 3-layer method: Framework (WHY) → Challenge (write it yourself with Nexora context) → Model Policy + audit defence. Remote Working, Cryptography, Backup (RTO 4hr/RPO 1hr), Vulnerability Management, Physical Security, Information Transfer.
3-Layer FormatAWS ControlsPOL-007 to 012
6 policies · Think-first write-it-yourself format
Start →
Series 7C
👥
People & Infrastructure Policies
6 more policies in the same 3-layer format. HR Security, Change Management (CI/CD enforcement), Network Security (4-tier AWS VPC), Logging & Monitoring (CloudTrail + GuardDuty SLAs), Media Disposal, Data Retention & Deletion.
3-Layer FormatPeople ControlsPOL-013 to 018
6 policies · Think-first write-it-yourself format
Start →
🔍
Audit & Certification — Both Sides of the Table
3 series
Series 8
🔍
Internal Audit at Nexora
You are the auditor. Plan the audit, build the checklists, conduct 4 live interviews, classify every finding, write the complete audit report, and build the corrective action plan. Result: 0 Major NCs · 4 Minor NCs · 3 Observations · 3 Positive Findings.
Clause 9.26 PhasesAuditor SideFinding Writing
6 phases · Live interviews · Audit report document
Start →
Series 9
📋
Statement of Applicability — All 93 Controls
Every ISO 27001:2022 Annex A control — all 93. Plain English meaning, what it requires, why it applies to Nexora, the implementing policy, the audit question, and the evidence required. Plus the Quick Reference Table (filterable) and the formal SoA document Nexora hands to the certification body.
All 93 Controls7 TabsSoA DocumentSearchable Table
7 tabs · 93 expandable controls · Formal SoA document
Start →
Series 10
🪑
The Auditee Experience
Flip the table. You are 3 weeks in. The external auditor arrives Monday. Brief the CEO, engineering, and HR. Handle 4 evidence challenges under pressure. Manage a Major NC you did not see coming — live, in the room. The closing meeting. What happens in the 30 days after.
Auditee Side6 PhasesEvidence Under PressureMajor NC
6 phases · Weekend checklist · Live dialogue
Start →
⚙️
ISMS Operations — Running It After Certification
4 series
Series 11
🚨
Incident Response in Action
11:47pm. PagerDuty fires. Ransomware. 5 live decisions from detection to ICO notification. Then the wrong-recipient GDPR breach — is it reportable? When you have written deletion confirmation, what must you still do? Post-incident review with root cause analysis and 3 specific ISMS improvements.
RansomwareGDPR Breach3 ScenariosICO 72hrs
3 scenarios · 8 live decisions · Post-incident review
Start →
Series 12
🏛️
Management Review
Clause 9.3 — you chair the meeting. The 7 mandatory inputs. Build a pack the CEO will actually read. Live meeting simulation with 4 decision points. The CEO asks "could we have prevented the ransomware?" — how do you answer? Write the minutes that pass the certification audit.
Clause 9.35 PhasesCEO InterviewMinutes Document
5 phases · Live meeting simulation · Full minutes document
Start →
Series 13
🏅
Certification Readiness
The 8-week countdown. What cannot be done the final week. 35-item interactive evidence pack checklist. 20 real auditor questions with model answers and evidence required. Stage 1 vs Stage 2 explained. Year 1 and 2 surveillance audits. The certificate anatomy.
8-Week Plan35 Evidence Items20 Auditor Questions5 Phases
5 phases · Interactive checklist · Mock questions
Start →
Series 14
🤝
Supplier & Third Party Risk
Your risk does not stop at your door. The 3-tier supplier model. Nexora's full supplier register — AWS, Microsoft, Salesforce (overdue!), BambooHR, Stripe. Conduct a real Salesforce assessment question by question. DPA gaps identified. AWS and Salesforce exit plans documented.
Annex A.5.19–225 PhasesDPAsExit Planning
5 phases · Supplier register · Assessment simulation · Exit plan
Start →
🚀 Coming — Phase 2
Multi-Sector Scenarios + Interactive GRC Tool Suite
Phase 1 is the complete ISO 27001 programme using Nexora Health Technologies as the scenario. Phase 2 brings multi-sector scenarios — Financial Services, Education, Legal, Manufacturing, Retail — and a suite of interactive GRC tools: Risk Register Builder, Policy Generator, SoA Builder, Gap Analysis Tool, Audit Checklist Generator, and Evidence Mapper. Students build real artefacts they can show employers.
🏦 Financial Services
🎓 Education
⚖️ Legal
🏭 Manufacturing
🛒 Retail / eCommerce
🔧 Risk Register Builder
📋 Policy Generator
✅ SoA Builder
📊 Gap Analysis Tool
🎯 Evidence Mapper
0% Complete