Course Outline
I. Introduction to Information Security
1. Systemic information security management
2. Benefits and added value for the organisation
II. Overview of ISO 27001 requirements
1. What are the standard's requirements?
2. Key areas of focus
3. Identification of documentation requirements
4. Overview of Annex A
III. Information Security Management System compliant with ISO 27001
1. Elements of the Information Security Management System per ISO
27001
2. Exercises in interpreting and analysing ISO 27001 requirements
IV. Audits – general information
1. Introduction to auditing
2. Full audit overview
3. Audit criteria
4. Types of audits
V. Audit planning and preparation
1. Audit criteria and scope
2. Selection of an auditor team
3. Process approach to internal audits
4. Key aspects when creating a control question list
5. Conducting an audit per ISO 19011:2018
6. Practical exercises
VI. Conducting an audit – rules for on-site audits
1. Auditing techniques
2. Objective evidence
3. Identification of non-conformities and how to demonstrate them
4. Competencies of an auditor
5. Practical exercises
VII. Documenting audit results
1. Articulating findings clearly
2. Documenting non-conformities
3. Identifying and documenting insights and improvement opportunities
4. Summary of Audit Results – Audit Report
5. Practical exercises
VIII. Effective post-audit activities
1. Responsibilities regarding the initiation of corrective actions
2. The Importance of Precisely Determining the Causes of Non-Conformity
3. Defining corrective actions
4. Evaluating the effectiveness of actions
5. Post-audit activities related to insights and improvement potentials
6. Practical exercises
IX. Discussion and summary
Requirements
Audience
- Individuals preparing for the role of Lead Auditor for ISO 27001:2023
- Anyone with an interest in the subject
Testimonials (1)
Speed of response and communication