ISO/IEC 27001 Internal Auditor Training

Wishlist Share
Share Course
Page Link
Share On Social Media

About Course

Course Duration: 3 Days – 8 Hours/day

This three-day course provides participants with the necessary knowledge to audit all requirements of the ISO/IEC 27001:2022 standard and its organizational and technical controls from Annex A.

  • The course includes definitions from ISO/IEC 27000:2018 (Information Security Management Systems – Overview and Vocabulary), and auditing requirements from both ISO 19011:2018 (Guidelines for Auditing Management Systems) and ISO/IEC 27007:2017 (Guidelines for Information Security Management Systems Auditing).
  • Group exercises and case studies will be used to develop the required skills. Other topics covered include the auditing process and methodologies, e. g. planning and conducting an audit, writing nonconformity statements, preparing an audit summary and report, and verifying corrective actions following the requirements of ISO 19011 and ISO 27001. Case studies to develop skills for identifying nonconformities will be used.

Course Outline

Day One
  • Fundamentals of Information Security Management Systems (ISMS)
  • ISO/IEC 27001:2022 Requirements Descriptions
  • ISO/IEC 27001:2022 Clauses
  • Annex A Organizational and Technical Controls
  • Risk-based Thinking
  • ISMS Risks
  • ISMS Risk Assessment
  • ISMS Risk Treatment
  • Group Exercise 1: Risk Identification Discussion
  • ISO/IEC 27001 Clause 4 – Context of the Organization
  • ISO/IEC 27001 Clause 5 – Leadership
  • Group Exercise 2: Audit Scenarios
  • ISO/IEC 27001 Clause 6 – Planning
Day Two
  • ISO/IEC 27001 Clause 7 – Support
  • ISO/IEC 27001 Clause 8 – Operation
  • A look at and understanding of Annex A Controls
  • Group Exercise 3: Audit Scenarios
  • ISO/IEC 27001 Clause 9 – Performance Evaluation
  • ISO/IEC 27001 Clause 10 – Improvement
  • Group Exercise 4: Audit Scenarios
  • Understanding the ISMS Final Exam
  • Process Approach to Auditing, Turtle Diagrams and Audit Trails
  • Breakout Exercise 1: Create a Turtle Diagram
  • Audit Guidance, Definitions and Principles
  • The Need for an Audit Program
  • Audit Planning and Preparation – Using the Guidelines for Information Security Management Systems Auditing
  • Breakout Exercise 2: Documentation Review
  • Breakout Exercise 3: Create an Audit Plan
Day Three
  • Conducting the Audit
  • Conducting the Closing Meeting
  • Breakout Exercise 4: Conduct an Audit Interview
  • Writing Nonconformity Statements
  • Breakout Exercise 5: Write Nonconformity Statements
  • Conducting the Closing Meeting
  • Completing the Audit Report
  • Corrective Action and Close-Out
  • Management Systems Auditing Final Exam
Show More

What Will You Learn?

  • Understand the application of Information Security Management principles in the context of ISO/IEC 27001:2022.
  • Relate the Information Security Management system to the organizational processes, services, activities.
  • Understand the application of the principles, procedures and techniques and attributes needed for effective auditing.
  • Understand the conduct of an effective audit in the context of the auditee’s organizational situation.
  • Understand the application of the regulations, and other considerations that are relevant to the management system, and the conduct of the audit.

The Security You Need.
The Compliance to Succeed.

Company

Business Hours

About Us

About Us

Copyright Notice

Information

Work Hours

Terms and Conditions

Business Hours

Contact Info