The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From ISO 27001 Coordinator (L1)
1-2 yearsSkills to master
- Taking ownership of specific control areas, proactive stakeholder engagement, basic risk assessment application, independent problem-solving for routine issues.
You're ready to move on when
- Consistently delivers assigned evidence requests on time and accurately.
- Proactively identifies minor gaps or inconsistencies in documentation.
- Can clearly explain the purpose of several Annex A controls.
- Successfully manages simple CAPAs to closure with minimal supervision.
- 2
From IT Support / Junior Security Analyst
2-3 years (with relevant security focus)Skills to master
- Understanding of ISO 27001 framework, documentation standards, evidence collection methodologies, stakeholder communication for compliance.
You're ready to move on when
- Demonstrates a keen interest in information security governance and compliance.
- Has a good grasp of IT infrastructure and security concepts.
- Shows strong attention to detail in their current role.
- Has taken initiative to learn about ISO 27001 in their own time (e.g., online courses).
- 3
From Quality or Health & Safety Administrator
2-4 years (with information security training)Skills to master
- Translating quality/H&S compliance experience to information security, learning specific ISO 27001 requirements, understanding IT environments.
You're ready to move on when
- Proven track record in managing other ISO standards (e.g., ISO 9001, ISO 45001).
- Strong process management and documentation skills.
- Has undertaken formal training or certification in information security basics.
- Can articulate the differences and similarities between various compliance frameworks.