Frequently Asked Questions (FAQ) for ISO courses


Frequently Asked Questions for ISO courses offered by DPEXNetwork in partnership with PECB

1. Is the time frame for accessing the course materials on a limited time frame or accessible for life?

2. What are the benefits of ISO professional certification?

3. What is ISO 27701? What is the difference between ISO 27001 and ISO 27701?

4. Which is better to get ISO 27701 or IAPP cert? What are their main differences?

5. I would like my organisation to be ISO 27701 certified? How do I achieve this certification?

6. I have attained my CISA and i would like to learn how to conduct an audit process to prepare for GDPR compliance - can i go for ISO 27701 Lead Auditor?

7. Other than those listed in the DPEXnetwork.org web site, do I have the option to take other ISO courses and be certified like the iSO 27001?

8. Although the ISO courses are self-study courses, the course pages actually list the number of days for the self-study. What is the reason?

9. For self-study courses, do the participants have to finish each day’s materials on the day itself for XX days consecutively or can they take their time and choose to take the exam within a stipulated time frame?

10. Exam voucher in the self sponsored PECB course - covers one exam and one retake. How much does it cost for a second retake?

11. Does Straits Interactive intend to offer the option for class-room or online training?

12. Since my course fee includes my first year exam and certification fee, what is the subsequent annual PECB certification maintenance fee?

13. Is there a badge to display upon attaining the certification?

14. What is the difference between self-paced learning courses and e-learning courses?



1. Is the time frame for accessing the course materials on a limited time frame or accessible for life?

There is no expiration date on the materials. It can be accessed for life. 


2. What are the benefits of ISO professional certification?

ISO standards are internationally agreed by experts. Think of them as a formula that describes the best way of doing something.

With ISO certification, or as in any other professional certification, you can enjoy the following benefits:

  • Competitive Advantage. Having training differentiates you from the  competition 
  • Increase Efficiency
  • Increase Earning Potential
  • Expand Knowledge and Skills
  • Build Professional Credibility


The value of the certificate is the skill the person can bring to the organization when he/she have these skills. The certificate just helps the organization identify those people who can deliver greater value, but you also have to show evidence of that value.


3. What is ISO 27701? What is the difference between ISO 27001 and ISO 27701?

Many information security professionals are familiar with ISO 27001. In fact, the Information Security Management System (ISMS) defined in ISO IEC 27001 was designed to permit the addition of sector specific requirements, without the need to develop a new Management System to ensure information security. It is also designed as an international framework to be able to be implemented either separately or as a combined Management System.


4. Which is better to get ISO 27701 or IAPP cert? What are their main differences?

While they are different, they complement each other. Both focus on data protection and privacy. IAPP certifications courses are jurisdiction specific.

For example, CIPP/E and CIPM are based on GDPR (General Data Protection Regulation) while the ISO 27701 is based on international framework and standards which are applicable to any kind of data protection requirements.

The CIPP/E is targeted mainly at “legal professionals”. Anyone with a CIPP/E will be positioned as someone with expert knowledge on the GDPR.

The IAPP CIPM (Certified Information Privacy Manager) is targeted at anyone “managing” a privacy / data protection programme. Anyone with a CIPM will have international credentials as a credible data protection officer / manager or an expert in privacy programme administration.

As for the ISO 27701, there is both a "Lead Auditor" and "Lead Implementer"

The ISO 27701 Lead Auditor, as its name implies, is useful to anyone wanting to have the international credentials to "audit" a privacy management system. Hence, it is applicable for auditors, information security and data protection consultants.

The ISO 27701 Lead Implementer gives international credentials to anyone wanting to "implement" a privacy information management system (PIMS) that is not jurisdiction-specific and complements an information security management system (ISMS). Therefore, it will be applicable to information security professionals, data protection consultants and even those with a CIPM qualification.

As can be seen, both are internationally recognised - even by regulators. But their focus is different. Having BOTH IAPP and ISO 27701 certifications will definitely differentiate an individual especially a DPO or data protection consultant.


5. I would like my organisation to be ISO 27701 certified? How do I achieve this certification?

The course provided by DPEXNetwork/PECB is a professional certification for the individual and not the organisation. However, having someone who is ISO 27701 certified will give you the expertise to prepare your organisation to be certified.

Since ISO 27701 is an extension standard, it requires an underlying ISO 27001 implementation. Organisations looking to get certified to ISO 27701 will either need to have an existing ISO 27001 certification or can implement ISO 27001 and ISO 27701 together as a single implementation audit.  ISO 27701 is a natural expansion to ISO 27001 as the formatting of ISO 27701 requirements and controls maps directly to the ISO 27001 standard.


6. I have attained my CISA and i would like to learn how to conduct an audit process to prepare for GDPR compliance - can i go for ISO 27701 Lead Auditor?

The ISO/IEC 27701 Privacy Information Management System (PIMS) (formerly known as ISO/IEC 27552 during drafting period), helps organizations reconcile privacy regulatory requirements. The standard outlines a comprehensive set of operational controls that can be mapped to various regulations, including the GDPR. Once mapped, the PIMS operational controls are implemented by privacy professionals and audited by internal or third-party auditors resulting in a certification and comprehensive evidence of conformity.


7. Other than those listed in the DPEXnetwork.org web site, do I have the option to take other ISO courses and be certified like the iSO 27001?

Yes, you can write to us and let us know. And we will coordinate with PECB to make the course available to you.


8. Although the ISO courses are self-study courses, the course pages actually list the number of days for the self-study. What is the reason?

The number of days listed serves a guide to anyone wishing to take the course (which is equivalent to the number of full days of training if a participant were to attend class-room training). The self study option gives participants the flexibility to study based on their own convenience.


9. For self-study courses, do the participants have to finish each day’s materials on the day itself for XX days consecutively or can they take their time and choose to take the exam within a stipulated time frame?

Under self-learning, they can take their time to finish the material and choose the exam within the stipulated time frame.


10. Exam voucher in the self sponsored PECB course - covers one exam and one retake. How much does it cost for a second retake?

For candidates that fail the exam in the 2nd retake, it is recommended that the candidate attend the training course agan in order to be better prepared for the exam. Candidates need to purchase the course.


11. Does Straits Interactive intend to offer the option for class-room or online training?

Yes, eventually this option will be available in 2021 at a higher price point.


12. Since my course fee includes my first year exam and certification fee, what is the subsequent annual PECB certification maintenance fee?

A PECB certification requires the payment of the maintenance fee. The annual reporting begins with the initial certification date; however, the maintenance fee for the first year is included in the certification application payment.  

 The following fee applies:

  • Annual Maintenances Fee: $100 
  • Upgrade Fee: $100


In case one certified professional has more than 5 certificates issued by PECB, he/she will only have to pay $500 annually. For example, if one individual has 8 certificates, instead of paying $800, he/she will only have to pay $500 per year.


13. Is there a badge to display upon attaining the certification?

After successfully passing the exam, you can apply for the respective credential shown when you have complied. with all the requirements related to the selected credential. (Please see  https://pecb.com/en/certification-rules-and-policies and details under the respective course brochure pages)

PECB grants permission to use the PECB Certification Marks to PECB certified professionals that have satisfied all applicable PECB credentialing and certification requirements. Each PECB certified professional is authorized to use only the Certification Mark which represents the appropriate certification and credential.   Each PECB certified professional may use the appropriate PECB Certification Mark in professional and business materials such as business cards and email signatures.


14. What is the difference between self-paced learning courses and e-learning courses?

In a self-paced learning programme, participants have access to notes and slides.

Whereas in an e-learning programme, the notes and slides are complemented by video lectures to augment participants learning.