The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From ISO 27001 Administrator (L2)
2-3 yearsSkills to master
- You would have mastered evidence collection, CAPA tracking, and basic risk register maintenance. To step up, you'd need to develop strong internal auditing skills, stakeholder influence, and a deeper understanding of the 'why' behind the controls.
You're ready to move on when
- Successfully managed evidence collection for multiple control families independently.
- Proactively identified and proposed solutions for minor compliance gaps.
- Received positive feedback on your ability to work with other teams.
- Completed an ISO 27001 Lead Auditor course.
- 2
From General IT Security Analyst / Engineer
3-5 yearsSkills to master
- You'd bring strong technical security knowledge, but you'd need to quickly get up to speed on the ISO 27001 framework, auditing methodologies, and the specific nuances of compliance documentation and stakeholder management.
You're ready to move on when
- Demonstrated a strong understanding of security controls and their implementation.
- Expressed a clear interest in the governance and compliance aspects of security.
- Completed an ISO 27001 Lead Implementer or Lead Auditor certification.
- Successfully managed security projects that required cross-functional collaboration.
- 3
From Quality or Regulatory Compliance Role (non-IT)
3-5 yearsSkills to master
- You'd have excellent auditing and process management skills, but you'd need to rapidly acquire a solid foundation in information security principles, common threats, and the specific technical controls within ISO 27001.
You're ready to move on when
- Proven track record in managing other ISO standards (e.g., ISO 9001, ISO 14001) or similar regulatory frameworks.
- Taken relevant information security courses or certifications (e.g., Security+).
- Demonstrated ability to learn complex technical domains quickly.
- Expressed a clear desire to transition into information security compliance.