Course Outline
I. Introduction to Information Security
1. Systematic approach to information security management.
2. Organizational benefits and added value.
II. Overview of ISO 27001 Requirements
1. Key requirements of the standard.
2. Critical areas of focus.
3. Identifying documentation obligations.
4. Summary of Annex A controls.
III. Information Security Management System (ISMS) Compliant with ISO 27001
1. Core elements of the ISMS per ISO 27001.
2. Practical exercises on interpreting and analyzing ISO 27001 requirements.
IV. Audits – General Overview
1. Introduction to the audit process.
2. Conducting a full audit.
3. Establishing audit criteria.
4. Classification of audit types.
V. Audit Planning and Preparation
1. Defining audit criteria and scope.
2. Assembling the audit team.
3. Applying a process approach to internal audits.
4. Key considerations for developing a control questionnaire.
5. Executing audits in line with ISO 19011:2018.
6. Practical exercises.
VI. Conducting the Audit – On-Site Guidelines
1. Effective auditing techniques.
2. Establishing objective evidence.
3. Identifying and validating non-conformities.
4. Essential competencies for the Lead Auditor.
5. Practical exercises.
VII. Documenting Audit Results
1. Precisely formulating observations.
2. Documenting non-conformities.
3. Identifying and recording insights and improvement opportunities.
4. Summarizing findings – The Audit Report.
5. Practical exercises.
VIII. Effective Post-Audit Activities
1. Roles and responsibilities for initiating corrective actions.
2. The importance of accurate root cause analysis for non-conformities.
3. Defining corrective actions.
4. Evaluating the effectiveness of implemented actions.
5. Addressing insights and improvement potentials during post-audit phases.
6. Practical exercises.
IX. Discussion and Summary
Requirements
Target Audience
- Professionals aiming for the role of ISO 27001:2023 Lead Auditor.
- Anyone with a strong interest in information security auditing.
Testimonials (1)
Speed of response and communication