Training, exams and certification
Four questions. Eighty marks. Two and a half hours. Restricted open book, forty marks to pass. If that sounds unlike every other exam on this site, it is — and the shape tells you exactly what is being tested.
The APMG ISO/IEC 27001 Practitioner certificate — Information Security Officer — tests whether you can apply the standard to manage information security, not whether you can describe it.
| Questions | 4 objective-testing questions, worth 80 marks in total |
|---|---|
| Duration | 150 minutes |
| Pass mark | 50% — 40 marks out of 80 |
| Materials | Restricted open book |
| Prerequisites | None stated |
| Accredited training | Not mandatory. Self-study and direct exam booking are supported |
| Typical course | Two days, where a course is taken |
The arithmetic of this paper is unlike anything else in the families we cover.
| Questions | 4 |
|---|---|
| Marks per question | 20 |
| Time per question | About 37 minutes 30 seconds |
| Marks to pass | 40 — the equivalent of two questions answered perfectly |
| Marks you can drop | 40 |
Each question is a substantial piece of work built around a scenario, with parts that are marked individually. There is no recall element to speak of and no time pressure in the ordinary sense: thirty-seven minutes is a long time to sit with one problem.
The risk is the opposite of the usual one. On a fast paper you run out of clock; here you run out of discipline, and write around the question instead of answering it.
APMG frames this level as applying ISO/IEC 27001 to enable the management of information security — the officer’s job rather than the auditor’s.
Practically, that moves the questions from “does this comply” to “what would you do”: scoping an ISMS, deciding what belongs in a Statement of Applicability, treating a risk, planning what management review should look at. The standard supplies the frame; the decision is yours, and the marks are for the decision and the reasoning behind it.
It is the same distinction that separates the Auditor certificate from this one. An auditor judges a system that exists. An officer builds and runs one.
You may consult the permitted materials, and with thirty-seven minutes a question you actually can — this is the one exam here where looking something up properly is affordable.
Use that. On a four-question paper, one misremembered requirement can cost a large share of twenty marks, and you have the time to check rather than guess. Confirm what the standard requires before you build an answer on top of it.
Practise writing full answers, not recognising right ones. This is not a multiple-choice paper in any meaningful sense.
Budget by question. Thirty-seven minutes each, and hold the line — overrunning on question one is how people lose question four.
Answer the question asked. Forty of the eighty marks are yours to lose, and they are most often lost to answers that are about the right topic but not about the question.
Four, worth eighty marks in total.
Forty marks out of eighty — 50%.
Two and a half hours, which is about thirty-seven minutes per question.
Restricted open book — the permitted materials only.
APMG does not state it as a prerequisite, though most providers sequence the levels that way.
The Auditor level judges a system against the standard. The Practitioner level designs and manages one — the information security officer’s role.
Sources. Every figure on this page comes from APMG International’s own published certification pages, checked in September 2026.
GoToCertify will offer preparation for the ISO/IEC 27001 certifications, with the exam voucher alongside it.
Not on sale on GoToCertify yet — we are setting it up. In the meantime the exam facts above are free to use.