Course Outline
I. Information Security Management System compliant with ISO 27001 requirements
1. Key components of the Information Security Management System as defined by ISO 27001
2. Exercises focused on interpreting and analyzing ISO 27001 requirements
II. Audits – General Overview
1. The complete audit process
2. Types of audits
III. Audit planning and preparation
1. Audit criteria and scope definition
2. Selecting the audit team
3. Applying a process approach to internal audits
4. Critical considerations when developing control questionnaires
5. Practical exercises
IV. Conducting the audit – Guidelines for on-site execution
1. Effective auditing techniques
2. Establishing objective evidence
3. Identifying and demonstrating non-conformities
4. Practical exercises
V. Documenting audit findings
1. Artful formulation of observations
2. Documenting non-conformities
3. Identifying and documenting insights and improvement opportunities
4. Summary of audit outcomes – Audit Report
5. Practical exercises
VI. Effective post-audit activities
1. Responsibilities for initiating corrective actions
2. The importance of precisely determining the root causes of non-conformities
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities regarding insights and improvement potentials
6. Practical exercises
VII. Discussion and summary
Requirements
Audience
- Individuals preparing to assume the role of ISO 27001:2023 Internal Auditor.
- Anyone with a strong interest in the subject matter.
Testimonials (1)
Speed of response and communication