top of page
ChatGPT Image Sep 15, 2026, 04_44_31 PM.png

ISO 27001
Case Study

Find out how AKRUP helped Udacity implement and maintain an ISO 27001 Information Security Management System, supporting the organisation through certification audits and providing ongoing annual internal audits.

Project Overview

Udacity engaged AKRUP to support the implementation of a comprehensive Information Security Management System (ISMS) aligned with ISO 27001.

AKRUP worked closely with Udacity to establish the policies, processes, risk management framework and security controls required to build an effective ISMS and prepare the organisation for ISO 27001 certification.

Following implementation, AKRUP supported Udacity throughout the external certification audit process and continued to provide ongoing ISO 27001 support, including annual internal audits to assess compliance, identify opportunities for improvement and help maintain the effectiveness of the ISMS.

The relationship has continued from 2020 through to 2026, supporting Udacity with the ongoing maintenance and continual improvement of its information security management framework.

image.png

Project Duration: 2020-2026
Industry: Technology/Online Education
Framework: ISO 27001
Outcome: Successful ISO 27001 implementation, audit support and ongoing ISMS assurance.

The Challenge

Implementing ISO 27001 requires more than producing a set of information security policies. Organisations need to establish a structured management system that identifies and manages information security risks, assigns clear responsibilities, implements appropriate controls and provides evidence that those controls are operating effectively.

For a technology-focused organisation such as Udacity, it was important that the ISMS could support the organisation's operations while providing a structured and sustainable approach to information security.

Udacity required support establishing its ISO 27001 framework, preparing for external certification audits and ensuring that the ISMS continued to operate effectively after its initial implementation.

AKRUP worked alongside key stakeholders to establish the required processes, documentation and governance arrangements while helping the organisation prepare the evidence needed to demonstrate conformity during external audits.

Our Approach

We worked alongside Udacity throughout the ISO 27001 implementation rather than simply providing standard templates or documentation.

Our approach was to build an ISMS around the organisation's existing operations, helping relevant stakeholders understand their responsibilities and ensuring that ISO 27001 requirements were incorporated into day-to-day business processes.

This included developing the ISMS framework and supporting documentation, establishing a structured approach to information security risk management, reviewing the implementation of security controls and preparing the organisation for external certification audits.

Following the initial implementation and audit process, our role developed into an ongoing assurance relationship. AKRUP has continued to perform annual internal audits, reviewing the effectiveness of the ISMS and identifying areas where controls and processes can be strengthened.

This long-term approach has helped Udacity maintain a structured information security programme and continually improve its ISMS as the organisation and its security requirements have evolved.

What we delivered

ISMS Implementation

Worked closely with the Udacity team to build and implement a complete ISMS that met ISO 27001 requirements while fitting around the way the business actually operated.

Policies & Documentation

Created and updated the policies, procedures and supporting documentation needed for ISO 27001, making sure they reflected Udacity’s actual processes rather than relying on generic templates.

Risk Assessment

Worked with key stakeholders to identify and assess information security risks across the business and put appropriate actions in place to manage them.

Risk Treatment

Developed and maintained the Risk Treatment Plan, helping Udacity decide how identified risks should be addressed and which security controls were needed.

Security Controls

Worked with different teams across the business to review and implement the security controls required for ISO 27001 and make sure they were working effectively in practice.

Roles & Responsibilities

Helped define information security responsibilities across the organisation so that everyone involved in the ISMS understood their role and what was expected of them.

Security Awareness

Helped embed information security into the organisation by making sure employees understood their security responsibilities and the requirements relevant to their roles.

Annual Internal Audits

Carried out annual ISO 27001 internal audits to check that the ISMS continued to meet the requirements of the standard and to identify any areas that could be improved before the external audit.

Audit Preparation

Worked with Udacity ahead of each external audit to review documentation, check evidence, address any gaps and make sure the relevant teams were prepared for the auditor.

Corrective Actions

Where findings or areas for improvement were identified, we worked with the relevant teams to understand the issue, agree the appropriate action and make sure it was properly addressed.

External Audit Support

Supported the Udacity team throughout their ISO 27001 audits, helping with auditor questions, evidence requests and any issues that came up during the assessment.

Continual Improvement

Continued to review and improve the ISMS as Udacity changed and new risks, technologies and business requirements emerged.

Ongoing ISO 27001 Support

Our work with Udacity has continued from 2020 to 2026, providing ongoing ISO 27001 support rather than ending the engagement once the initial implementation and certification audit were complete.

Project Outcome

Working with AKRUP, Udacity successfully implemented a full Information Security Management System and put the processes in place needed to meet the requirements of ISO 27001.

We supported the Udacity team throughout the external audit process, helping them prepare the required evidence, answer auditor questions and address any issues that came up. Since the initial implementation, we have continued to work with Udacity and carry out their annual ISO 27001 internal audits.

As a result of the project, Udacity now has:

  • A fully implemented and established ISMS

  • A clear process for identifying and managing information security risks

  • Policies and procedures that reflect how the business actually operates

  • Regular internal audits to check that the ISMS continues to work effectively

  • Better visibility of security risks, controls and areas that need improvement

  • A structured approach to preparing for external ISO 27001 audits

  • Regular reviews of the ISMS as the organisation and its risks change

  • Ongoing ISO 27001 support from an experienced information security team

Our relationship with Udacity has continued from 2020 to 2026. Rather than simply helping with the initial ISO 27001 implementation and then stepping away, we have continued to support the team as their ISMS has developed and matured over the years.

This long-term approach has helped Udacity keep ISO 27001 embedded within the business and remain prepared for ongoing external audits.

Why AKRUP?

AKRUP has built a proven track record of helping organisations achieve successful compliance outcomes across recognised security and assurance standards. With experience supporting clients worldwide, we understand what it takes to move from uncertainty to audit-ready confidence.

Our 100% project success rate reflects the quality of our delivery, the strength of our expertise and our commitment to getting results right the first time. Businesses choose AKRUP because we provide clear direction, practical guidance and reliable support that helps turn compliance into a competitive advantage.

What our clients say

Trusted by organisations across automotive, manufacturing and technology sectors.

ChatGPT Image Jun 10, 2026, 01_15_31 PM.png
"Very happy with the service recieved and the ongoing support"

Denzil Allen, Head of HSEQT

Rudolph and Hellmann

ChatGPT Image Jun 10, 2026, 01_39_52 PM_edited.png

Speak With Our Experts

Discuss your ISO 27001 requirements with one of our specialists. Complete the form below and we'll help you plan your route to successful ISO 27001 implementation.

Looking to achieve ISO 27001? Complete the form and one of our consultants will contact you to discuss your requirements and next steps.

bottom of page