Brit Certifications and Assessments UK (BCAA) is a specialized certification body based in the United Kingdom. It acts as a "quality seal" for businesses and professionals, particularly those working in the high-stakes worlds of IT, cybersecurity, and data privacy.
Think of BCAA like a driving school and a licensing authority combined: they don’t just teach you how to drive (Training); they also test you to make sure you’re safe on the road (Assessment) and give you a license that proves it to others (Certification).
 
 
BCAA uses a specific four-step model to help people master new skills. This ensures that a certification isn't just a piece of paper, but a true reflection of ability.
1.
Read: You start by learning the theory and understanding the rules.
2.
Act: You apply that knowledge through practical exercises and real-world scenarios.
3.
Certify: You take an exam to prove you have mastered the subject.
4.
Engage: After passing, you stay involved through webinars and group discussions to keep your skills sharp.
 
 
Executive implementation, assurance and performance leadership
The program develops the integrated competence required to establish, implement, audit, measure and continually
improve an Information Security Management System. It moves beyond clause awareness to programme leadership,
risk-informed decisions, objective evidence and board-level communication.
 
16-Executive modules
80-Structured curriculum sections
3-Integrated disciplines: implementation, audit and project leadership
1-Executive capstone and practitioner development plan
Core standards: ISO/IEC 27001:2022, ISO/IEC 27002, ISO 19011 and ISO 21502, supported by practical risk, control,
measurement and certification-readiness techniques.
 
 
 
Module 1: Foundations of Information Security and ISO/IEC 27001
1. Information security principles, business value and the CIA triad
2. Evolution, purpose and structure of ISO/IEC 27001:2022
3. Information Security Management System concepts and terminology
4. Relationship between governance, risk, compliance and resilience
5. Roles and competencies of an ISO/IEC 27001 Lead Practitioner
 
Module 2: ISO/IEC 27001 Requirements and Harmonized Structure
1. Harmonized Structure and integration with other management systems
2. Interpretation of Clauses 4-10 of ISO/IEC 27001:2022
3. Mandatory requirements, documented information and objective evidence
4. Process-based thinking, PDCA and continual improvement
5. Compliance obligations and certification expectations
 
Module 3: Organizational Context, Interested Parties and ISMS Scope
1. Analysis of internal and external organizational issues
2. Identification of interested parties and their requirements
3. Legal, regulatory, contractual and stakeholder obligations
4. Determination and documentation of the ISMS scope
5. Establishing ISMS processes, interfaces, boundaries and dependencies
 
Module 4: Leadership, Governance and Information Security Policy
1. Leadership commitment and executive accountability
2. Information security governance structure and decision rights
3. Development and approval of the information security policy
4. Assignment of roles, responsibilities and authorities
5. Security culture, management oversight and governance reporting
 
 
Module 5: Information Security Risk Management
1. Risk management principles, context and risk criteria
2. Asset, threat, vulnerability and control identification
3. Qualitative and quantitative risk assessment techniques
4. Risk treatment planning and residual risk acceptance
5. Risk registers, risk ownership and ongoing risk monitoring
 
Module 6: Statement of Applicability and Annex A Controls
1. Purpose, structure and governance of the Statement of Applicability
2. Interpretation of ISO/IEC 27001:2022 Annex A controls
3. Organizational, people, physical and technological control themes
4. Control selection, exclusion, justification and implementation status
5. Mapping the Statement of Applicability to risks and requirements
 
Module 7: ISO/IEC 27002 Control Implementation Guidance
1. ISO/IEC 27002 control attributes and implementation guidance
2. Organizational and information security governance controls
3. Human resource, awareness and personnel security controls
4. Physical, environmental and asset protection controls
5. Technological, operational and cyber-resilience controls
 
Module 8: ISO/IEC 27001 Implementation Techniques
1. ISMS readiness assessment and gap analysis
2. Implementation roadmap and work breakdown structure
3. Policy, procedure, process and record development techniques
4. Control implementation, integration and operationalization
5. Implementation validation and certification readiness
 
 
Module 9: ISO 21502-Based ISMS Project Management
1. ISO 21502 principles applied to ISMS implementation
2. Project initiation, business case, charter and governance
3. Stakeholder, scope, schedule, cost and resource management
4. Risk, quality, change, communication and procurement management
5. Project closure, benefits realization and operational transition
 
Module 10: Support, Competence, Awareness and Documented Information
1. Determining ISMS resources and organizational capabilities
2. Competence frameworks, role profiles and training needs analysis
3. Security awareness, communication and behavioural change
4. Creation, approval and control of documented information
5. Records retention, evidence integrity and document lifecycle
 
Module 11: ISMS Operations and Control Effectiveness
1. Operational planning and control of information security processes
2. Integration of security controls into business operations
3. Supplier, cloud, outsourced service and third-party security
4. Incident management, business continuity and operational resilience
5. Monitoring implementation and evaluating control effectiveness
 
Module 12: ISO 19011 Management System Auditing Principles
1. Purpose, principles and terminology of ISO 19011
2. Establishing and managing an ISMS audit programme
3. Auditor competence, independence, ethics and judgement
4. Risk-based audit planning, objectives, scope and criteria
5. Conducting, reporting, following up and improving audits
 
 
Module 13: ISO/IEC 27001 Auditing Techniques
1. Audit preparation, sampling strategies and evidence collection
2. Interviewing, observation, document review and technical verification
3. Process auditing, control testing and traceability techniques
4. Identifying and grading conformity and nonconformity
5. Audit findings, reports and executive presentations
 
Module 14: Performance Evaluation, KPIs and KRIs
1. Establishing an ISMS measurement and evaluation framework
2. Designing Key Performance Indicators for processes and controls
3. Designing Key Risk Indicators and risk thresholds
4. Dashboards, trend analysis, benchmarking and executive reporting
5. Audit results, management review and evidence-based decisions
 
Module 15: Corrective Action, Continual Improvement and Certification
1. Management of incidents, issues and nonconformities
2. Root-cause analysis and corrective-action techniques
3. Continual improvement planning and maturity assessment
4. Stage 1, Stage 2 and surveillance audit preparation
5. Maintaining certification and managing ISMS changes
 
Module 16: Lead Practitioner Integration and Executive Capstone
1. Integrating implementation, auditing and project competencies
2. Developing an industry-specific implementation strategy
3. Conducting a simulated ISMS audit and management review
4. Presenting ISMS performance, risks and recommendations
5. Capstone project and professional development plan
 
 
The learning architecture is designed for experienced professionals who must translate standards into
organizational outcomes.
Executive briefings:
Clause interpretation, governance implications and management decision points.
Applied workshops:
Context, scope, risk assessment, Statement of Applicability, controls, KPIs and KRIs.
Audit simulations:
Planning, interviewing, sampling, evidence evaluation, findings and reporting.
Project practice:
ISO 21502-aligned charter, roadmap, stakeholder plan, schedule, controls and closure.
Capstone integration:
Industry-specific implementation and assurance strategy presented to an executive panel.
Indicative learning evidence:
Gap assessment • ISMS scope • risk register • risk treatment plan • Statement of Applicability • audit plan • audit report •
KPI/KRI dashboard • management review pack • implementation roadmap
 
 
Designed for leaders and practitioners accountable for ISMS implementation, audit, risk, assurance
and performance.
• CISOs, information security managers and governance leaders
• ISMS managers, implementers and management representatives
• Internal auditors, lead auditors and compliance professionals
• Risk, privacy, resilience and business continuity professionals
• Project and programme managers leading ISO/IEC 27001 initiatives
• Consultants and advisers supporting certification readiness
 
 
• Lead an ISO/IEC 27001 implementation from business case to operational transition
• Apply ISO 19011 and advanced ISO/IEC 27001 auditing techniques
• Manage the ISMS as an ISO 21502-aligned project and change initiative
• Design meaningful KPIs, KRIs, dashboards and executive reports
• Guide certification readiness, corrective action and continual improvement
 
 
Separate exam for ISO27001 Lead Auditor and Lead Implementer
Demonstration Workshop on ISO27001 Implementation
Participation in mock audit
 
 
BRIT CERTIFICATIONS AND ASSESSMENTS (UK),
128 City Road, London, EC1V 2NX,
United Kingdom enquiry@bcaa.uk