This course is presented as
Live Virtual Training.
Click for more details.
- Practical orientation - not just theory. Features extensive use of real-world examples from trainer personal experience
- The ONLY independently accredited ISO 27001 Lead Auditor training in Asia-Pacific.
- Certificate exam 3rd-party set and marked
- Based on most recent version ISO 27001:2013
ISO 27001 is the recognised international standard for best practice in information security management systems (ISMS) within any organisation. This course will prepare you to plan and execute audits of information security management systems in line with the international standard ISO/IEC 27001.
Using the most recent version ISO 27001:2013, this training is based on management system audit guidelines (ISO 19011:2002) as well as international audit best practices: the International Federation of Accountants (IFAC), the American Institute of Certified Public Accountants (AICPA), the Information Systems Audit and Control Association (ISACA) and the Institute of Internal Auditor (IIA). An audit kit developed by experienced auditors will be distributed to participants.
Learning outcomes
- Acquiring the expertise to perform an ISO 27001 internal audit as specified by ISO 19011
- Acquiring the expertise to perform an ISO 27001 certification audit as specified by ISO 19011, ISO 17021 and ISO 27006
- Acquiring the expertise necessary to manage an ISMS audit team
- Understanding the application of the information security management system in the context of ISO 27001
- Understand the relationship between an Information Security Management System, including risk management, controls and compliance with the requirements of different stakeholders of the organisation
- Improve the ability to analyse the internal and external environment of an organisation, risk assessment and audit decision-making in the context of an ISMS
Who should attend
- Internal auditors
- Auditors wanting to perform and lead Information Security Management System (ISMS) certification audits
- Project managers or consultants wanting to master the Information Security Management System audit process
- Persons responsible for the Information security or conformity in an organisation
- Members of an information security team
- Expert advisors in information technology
- Technical experts wanting to prepare for an Information security audit function
Course contents
Day 1: Introduction to the management of an Information Security Management System based on ISO 27001
- Normative and regulatory and legal framework related to information security
- Fundamental principles in Information Security
- ISO 27001 certification process
- Information Security Management System (ISMS)
- Detailed presentation of the clauses 4 to 8 of the ISO 27001 standard
Day 2: Launching an ISO 27001 audit
- Fundamental audit concepts and principles
- Audit approach based on evidence and on risk
- Preparation of an ISO 27001 certification audit
- Documenting of an ISMS audit
- Conducting an opening meeting
Day 3: Conducting an ISO 27001 audit
- Communication during the audit
- Audit procedures:
- observation,
- document review
- interview
- sampling techniques
- technical verification
- Corroboration and evaluation
- Drafting test plans
- Formulation of audit findings
- Drafting of nonconformity reports
Day 4: Closing an ISO 27001 audit
- Audit documentation
- Quality review
- Review of audit notes
- Conducting a closing meeting and conclusion of an ISO 27001 audit
- Evaluation of corrective action plans
- Surveillance audit
- Audit management program
- Completion of training
Day 5
- Course review
- Exam preparation
- Certificate exam
Course fees
$2,960 + gst
Fees are per person and include:
- Course presentation
- Course workbook
- Supplementary materials
- Certificate exam
Prerequisites
ISO 27001 Foundation certification or basic knowledge of ISO27001 and ISO 27002 is recommended.
Examination
The ISO 27001 Lead Auditor exam is accessed online after the course.
- The exam consists of essay-type questions
- 3 hours duration
- Open book
- Minimum passing score: 70%
- A certificate will be issued to participants who successfully complete the exam
- After the training, the participant can apply for the title of ISO 27001 provisional auditor, ISO 27001 auditor, ISO 27001 principal auditor or ISO 27001 lead auditor depending on their experience.
Visit https://pecb.com/iso-27001-auditor-certification for more information.
- The certificate for the successful completion of the ISO 27001 Lead Auditor exam is recognised by IRCA (International Register of Certificated Auditors) and meets the IRCA/2016 certification criteria.
- A participant can register as IRCA or RABQSA auditor
- Successful participants can register as an accredited IRCA auditor
Certification Levels
There are three levels of accreditation that you can apply for after passing the exam, depending on professional experience:
- ISO/IEC 27001 Provisional Auditor - exam passed, no direct professional experience, no MS audit/assessment experience
- ISO/IEC 27001 Auditor - exam passed, two years professional experience with at least one year in information security, audit experience of at least 200 hours
- ISO/IEC 27001 Lead Auditor - exam passed, five years professional experience with at least two years in information security, audit experience of at least 300 hours
Candidates can apply for the appropriate level of accreditation once exam results have been received.