Course Outline
I. Introduction to Information Security
1. Systemic management of information security
2. Benefits and added value for the organization
II. Overview of ISO 27001 Requirements
1. Key requirements of the standard
2. Critical areas of focus
3. Identification of documentation needs
4. Overview of Annex A
III. Information Security Management System Aligned with ISO 27001
1. Components of the Information Security Management System per ISO 27001
2. Exercises in interpreting and analyzing ISO 27001 requirements
IV. Audits – General Information
1. Introduction to auditing
2. Types of audits
3. Audit criteria
4. Classification of audit types
V. Audit Planning and Preparation
1. Defining audit criteria and scope
2. Selecting the audit team
3. Process-based approach to internal audits
4. Key considerations for developing a control questionnaire
5. Conducting audits according to ISO 19011:2018
6. Practical exercises
VI. Conducting an Audit – Guidelines for On-Site Audits
1. Auditing techniques
2. Objective evidence
3. Identifying and demonstrating non-conformities
4. Competencies of an auditor
5. Practical exercises
VII. Documenting Audit Findings
1. Effective formulation of findings
2. Documenting non-conformities
3. Identifying and documenting insights and improvement opportunities
4. Summary of Audit Results – Audit Report
5. Practical exercises
VIII. Effective Post-Audit Activities
1. Responsibilities regarding the initiation of corrective actions
2. The importance of accurately determining the root causes of non-conformities
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities related to insights and improvement potentials
6. Practical exercises
IX. Discussion and Summary
Requirements
Target Audience
- Professionals preparing to take on the role of Lead Auditor for ISO 27001:2023.
- Any individual interested in this subject matter.
Testimonials (1)
Speed of response and communication