Compliance courses: ISO 27001, PCI DSS and more

Training by standard, with versions for everyone, executives and implementers. ISO 27001, PCI DSS, OWASP, LGPD and TISAX.

How it works

How the right version is chosen

Three versions where the standard asks

ISO 27001 and PCI DSS have everyone, executives and implementers. It is not the same quiz. It is not the same depth. Assigning the implementer version to a branch does not cover the control and burns adoption.

OWASP is 2025

The technical course uses Top Ten:2025. We do not publish another year’s Top Ten as if it were current. If the year changes again, the piece enters the catalog’s annual review.

LGPD and TISAX are not dressed up as ISO

LGPD covers data in Brazil. TISAX covers the automotive chain. They are not sold as an “every standard in the world” pack. If your operation does not declare them, do not assign them to inflate coverage.

Evidence, not a loose diploma

The course leaves progress, a score and a certificate. The compliance program — coverage, period, export — lives on the compliance page. It is not the Trust Center and not a control mapping.

Standards

Standards

ISO 27001

The standard asks for awareness tied to the role and evidence that the control exists over time, not an annual talk with an attendance list.

What an ISMS is, what is expected of each person, and what is not “security will handle it”. Three versions: everyone, executives, implementers.

Everyone, executives and implementers. It is not a single video with the ISO logo.

PCI DSS

PCI DSS 12.6 asks for awareness specific to phishing and social engineering for whoever touches payments, with evidence by period.

Why clicks and handing over data matter in a card environment, what is reported, and why a generic e-learning is not enough. Three versions: everyone, executives, implementers.

Whoever operates payments, whoever directs them, and whoever implements the control. Whalemate is not a QSA.

OWASP Top Ten:2025

A team that builds software needs the current Top Ten, not a 2017 poster.

The 2025 categories applied to design and code decisions a non-technical person does not have to memorise.

Technical profile. It is not assigned to a branch or a board as if it were digital hygiene.

Secure development

The training control for whoever writes and reviews code is not covered by the everyone-phishing course.

Design and review practices the program can assign and audit. It is not a bootcamp and not a vendor certification.

Technical profile and, when the customer defines it, implementers.

LGPD

Brazil asks for demonstrable handling of personal data, including the people who see it every day.

What personal data is in the operation, what can be asked over an informal channel, and what evidence remains when someone is trained.

Everyone in Brazil-facing operations, plus the compliance profile that has to show coverage.

TISAX

The automotive chain asks for an information level a generic awareness course does not document.

What is expected of whoever touches that chain’s information and how training is recorded.

Compliance and implementers in accounts that declare TISAX. It is not sold as a Whalemate badge.

Incident management

Knowing what to do in the first hour is not the same course as not clicking.

Roles, escalation, and what is not improvised over chat. It complements the report button; it does not replace it.

Operations and profiles the customer marks as part of response.

ISO, PCI and sister standards, with the profile the auditor asks for

An ISO 27001 course is not the standard read aloud

It is the piece the program assigns so a concrete role knows what is expected and leaves a record. The same for PCI DSS training: 12.6 is not met with a digital-hygiene video. It is met with phishing and social-engineering training aimed at whoever touches the payments environment, with evidence by period.

We do not list the whole catalog

It lists the standards that have their own query. Each anchor — ISO 27001, PCI DSS, OWASP Top Ten:2025, secure development, LGPD, TISAX, incident management — says what the training requires, what the course covers and which profile it is for. The catalog total is not published until commercial and catalog figures match.

We do not repeat the adaptive training pillar paragraph

The pillar orchestrates. Here we answer the search for the standard. If the auditor asks “do you have ISO 27001 for executives or only the everyone version?”, the answer is in this catalog cut, not on the module card.

What it is for

What it is for when the auditor names the standard

It is for when compliance brings a named control and People does not

ISO for the board is not ISO for whoever implements the ISMS. PCI for the register is not PCI for the CISO. OWASP does not belong in branch onboarding. That cut ends the argument: standard, profile, scope.

AML/CFT and privacy-by-country have their own pages

Here are the cross-cutting standards. The link to compliance is the program-evidence page, not a second catalog.

In the cycle

How it connects to adaptive training

The adaptive security awareness training engine can assign these pieces after a signal or as part of the annual plan. It does not invent them. It takes the course for the standard and the profile. If the roster falls for a payments lure, the reinforcement is not “everyone ISO” by default: the matching piece is chosen. The evidence the auditor exports is born in the program, not in a listing. Here is which course exists for each query. Compliance says how it is demonstrated. The pillar says how it is orchestrated.

Questions

Questions about compliance courses

Are ISO 27001 and PCI DSS the same course?
No. They share the three-version logic — everyone, executives, implementers — and nothing else. The control, the audience and the quiz are different.
Does Whalemate certify ISO or PCI?
No. It trains and leaves training evidence. Whalemate’s ISO/IEC 27001:2022 badge is of our operation, not of your ISMS. PCI does not make us a QSA.
Is OWASP Top Ten:2025 for the whole roster?
No. It is a technical profile. Assigning it to people who do not build software does not cover a control and wears the program out.
Where are AML/CFT and each country’s data law?
On their own pages, one URL per query, with per-country anchors. They are not duplicated here.
How many compliance courses are there in total?
The ones you see anchored plus the rest of the published catalog. The catalog total is not published until the figure is closed.

Calibrate the standard to the profile, not the poster

In the demo we see which version goes to the board, the register and whoever implements. No invented control mapping.