Course Outline
I. Information Security Management System compliant with the requirements of ISO 27001
1. Key elements of the Information Security Management System as per ISO 27001
2. Exercises in interpreting and analysing the requirements of ISO 27001
II. Audits – General Information
1. Overview of the full audit process
2. Types of audits
III. Audit Planning and Preparation
1. Audit criteria and scope
2. Selection of the audit team
3. Process-based approach to internal audits
4. Key considerations when developing a control question list
5. Practical exercises
IV. Conducting an Audit – Guidelines for On-Site Audits
1. Audit techniques
2. Objective evidence
3. Identifying non-conformities and demonstrating them effectively
4. Practical exercises
V. Documenting Audit Results
1. Skillful formulation of inconsistencies
2. Documenting non-conformities
3. Identifying and recording insights and areas for improvement
4. Summary of Audit Results – The Audit Report
5. Practical exercises
VI. Effective Post-Audit Activities
1. Responsibilities related to initiating corrective and preventive actions
2. The importance of accurately determining the root causes of non-conformities
3. Defining appropriate corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities concerning insights and improvement opportunities
6. Practical exercises
VII. Discussion and Summary
Requirements
Target Audience
- Individuals preparing for the role of Internal Auditor for ISO 27001:2023
- Anyone with an interest in the subject