ISO 27001 Lead Auditor

ISO 27001 Lead Auditor

Course Overview:

ISO/IEC 27001:2022 international standard specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. Information being a valuable asset and building block is important to the growth, success and maintaining credibility of any organization. Information needs to be suitably protected like any other important business asset. If this asset is compromised, then the organization may be exposed to various threats including cybersecurity threats, identity theft and risks which may lead to brand image erosion, business disruption, financial and productivity loss etc.

The course will be conducted by our experienced lead auditors, who have audited numerous organizations. This intensive course is a pre-requisite in becoming a registered auditor / lead auditor. The course is structured to provide the knowledge and skills required to assess the Information Security Management System of an organization in accordance with the requirements of the ISO/IEC 27001:2022 international standard.

This comprehensive five-day course is structured to provide an understanding of ISO/IEC 27001:2022 requirements blended with presentations, case studies, exercises, workshops and role-plays to ensure that the participant thoroughly understands the role of an auditor / lead auditor and acquires the expertise needed to perform effective audits.

Objective:

ISO 27001 Lead Auditor training enables you to develop the necessary expertise to perform an Information Security Management System (ISMS) audit by applying widely recognized audit principles, procedures and techniques.

By the end of this training course, the participants will be able to:

To equip participants with the auditing knowledge and skills to conduct effective audits
To help participants understand the purpose of an Information Security Management System and the processes involved in establishing, implementing, maintaining and continually improving an ISMS.
To help participants understand auditing concepts, principles and the role and skills required by an auditor / lead auditor.
To develop skills to plan conduct, report and follow up audits in accordance with ISO 19011.

Target Practice:

Information Security Practitioners, Head - IT
Chief Information Security Officer
Information Security Management System Consultants
Information Security Management System Management Representative
Information Security Managers and core group members responsible for establishing, implementing, maintaining, and improving Information Security Management Systems
Professionals who have a role to play in the auditing of Information Security Management System

Prerequisite:

Prior knowledge about concepts of information security and information security management system (ISO/IEC 27001) is mandatory. This course is not for filling gaps in the knowledge about the standard, but for enhancing the knowledge about the same with regards to the audit context. *Relevant proofs to be submitted.

Duration:

Full 5 Days (40 Hours)

Course Content:

Module 1:

ISMS concepts and ISO/IEC 27001 standard:

ISMS concepts and benefits.
Risk assessment and management.
ISO/IEC 27001 standard requirements.
ISMS documentation.

Module 2:

Auditing principles:

Auditing objectives.
Types of audits.
Process approach.

Module 3:

Roles, responsibility and competency of auditors:

The auditors’ responsibilities.
The lead auditors’ responsibilities.
Competency of auditors.
Auditors qualification and certifications.

Module 4:

Planning an audit:

Pre-audit planning.
Reviewing documentation.
Developing an audit plan.
Preparing checklists or working documents.
Communication factors.

Module 5:

Conducting an audit:

Opening meeting.
Collecting objective/audit evidence.
Effective interviewing techniques.
Identifying and recording nonconformities.
Preparing for the closing meeting.
Do’s and Don’ts of auditing.

Module 6:

Reporting audit results:

Conducting the closing meeting.
Preparing the audit report.
Distributing the audit report.

Module 7:

Corrective actions:

Corrective action responsibilities.
Follow up scheduling.
Monitoring corrective action.

Module 8:

CQI IRCA registration:

The registration process.

Module 9:

Exercises / Workshops / Roleplays

Module 10:

Written examination

Certification Prerequisites:

After successfully completing the exam, you can apply for the credentials shown on the table below. You will receive a certificate once you comply with all the requirements related to the selected credential.

CredentialExamProfessional ExperienceISMS audit Experience
Certified ISO/IEC 27001 Lead AuditorCertified ISO/IEC 27001 Lead Auditor ExamFive years: Two years of work experience in Information Security Management

Audit activities:

Total of 300 hours

Evaluation:

Continuous Assessment:

Participants will be assessed throughout the course for punctuality, presentation skills, interactive approach, involvement, role-play, daily tests etc. Passing criteria: 70%

Final Examination:

There will be a written examination at the end of the course. The examination is a ‘closed book’ and only reference material permitted in the examination is an unmarked copy of the ISO/IEC 27001:2022 international standard.

Passing Criteria:

70% overall and 50% in each section.

About Us

For the focus on powerful enablers such as “Adaptability” and “Transformability” we have hand picked our team, full of subject matter experts from various walks of life; however their objective is not really to share what they know but to understand fully what is actually needed, and then, devise methods to genuinely fulfil it

With our collective mindset that is Progressive, Customer centric and with an unstinting zeal to Outperform it is certain that we can create ‘true value’ for our Partners, Customers and Benefactors.

Create your account