Key details...

Cost: In-House

Duration: 5 Days

PD Points: 40

Qualifications: AU TL IS

About the course...

This training session outlines the key processes and approaches a business needs to manage information security risk in a practical way. Our training will teach you how to implement and audit an information security management system adhering to the specific requirements of ISO/IEC 27001, in order to protect information assets such as customer details, sensitive corporate information and financial data. 

Our training is different because:

  • We never cancel a course – enrol with confidence
  • No homework or take-home assessment
  • Certificates are issued promptly upon the completion of the course
  • Trainers are practising audit professionals
  • All learning materials and refreshments provided

Plus, a free licensed copy of:

  • ISO/IEC 27001:2013 Information technology – Security techniques – Information security management systems – requirements.

Our training is different because...

No Homework or take-home assessment.

Internationally recognised courses.

Trainers are practising audit professionals.

All Learning materials and refreshments provided.

Certificates are issued promptly upon the completion of the course.

We never cancel a course - enrol with confidence.

Secure your place now

Book now

Course overview...

Participants will gain the knowledge to conduct internal or external audits of an Information Security Management System, either as a sole auditor, a member of an audit team, or as the team leader. Specifically, you will:

  • Learn how to plan and carry out an ISO 27001:2013 audit
  • Learn report writing and how to document an Information Security system
  • Recognise the role of the auditor
  • Understand, and be able to implement processes within the Information Security management system
  • Be able to improve your organisations conformance with ISO/IEC 27001:2013
  • Learn how to identify gaps in an Information Security management system
  • Satisfy training needs for Exemplar Global certification

This course includes a complimentary copy of ISO/IEC 27001:2013, along with all learning materials and refreshments.

Participants learn how to perform an audit in accordance with ISO 19011:2011 Guidelines for Auditing Management Systems. The course provides a comprehensive and practical understanding of how to conduct a successful internal or external audit, either as part of an audit team or as the team leader. We focus in particular on the principles and procedures of auditing, the importance of planning, the roles and responsibilities of an auditor, how to gather effective audit evidence and report on the audit findings, and the required follow up activities as an auditor.

Participants also learn the auditing requirements of ISO 27001, and how to best apply and integrate the standard for the benefit of an organisation.


This course is divided into two modules, enables participants to attend both modules in the one week, or spread across different sessions. The first 2 day module is equivalent to our ‘Becoming a Skilled Lead Internal/External Auditor’ course, where participants learn to conduct management systems audits. The remaining 3 day module covers the requirements of the Information security management systems standard, ISO 27001 and information Security controls.

Day 1

Introduction to Management Systems Auditing

  • Introduction to auditing
  • Roles and responsibilities of an auditor
  • Principles and procedures of auditing
  • Communication skills and interview techniques
  • Setting appropriate audit objectives, goals, and criteria
  • Planning a Management systems audit

Day 2

Management Systems Auditing

  • How to ensure that audits add value to an organisation
  • Auditing as a Team Leader
  • Effective audit evidence
  • Management Systems auditing scenarios
  • Writing audit findings and the audit report
  • Developing the audit report and writing audit findings
  • Reviewing corrective action

Day 3

Information Security Management Systems

  • Introduction to Information Security
  • Context of Information Security
  • Information Security management systems requirements
  • Risk-based approach to information security

Day 4

Information Security controls

  • ISO 27001 – Code of practice for Information Security management
  • Information classification
  • Documentation requirements of Information security management systems

Day 5

Information Security application

  • Statement of applicability
  • Information security audit scenarios
  • Course review

Upon successful completion of the course, each participant will receive a Certificate of Attainment which identifies the 3 Exemplar Global competencies below:

  1. Exemplar Global IS – Information Security management systems
  2. Exemplar Global AU – Management systems auditing
  3. Exemplar Global TL – Leading management systems audit teams

Additional Exemplar Global competencies for Quality management systems (Exemplar Global QM) Environmental management systems (Exemplar Global EM) and/or OHS management systems (Exemplar Global OH), and Food Safety management systems (Exemplar Global FS) may be attended separately.

There are no prerequisites for this course.

During the course, participants will complete a series of workshops, which form part of the assessment. Upon the completion of each module there is a short multiple choice exam. Participants receive continual assistance and feedback from the facilitator.

Designed to cater to a variety of people currently involved in the audit and Information Security Management System process, you should attend if you:

  • want to become an internal ISMS auditor
  • want to become a 3rd party IS auditor
  • need to write and implement a ISMS
  • are involved in the Information Security management process
  • are a manager responsible for an ISMS and ISMS auditing
  • wish to consolidate your existing knowledge into a formal qualification.

Prior experience in auditing and management systems is not essential.

If you wish to become a registered third-party, or external Information Security Management Systems auditor with Exemplar Global, completing this course is the first step.

Once you have obtained the Exemplar Global competencies from this course, you can follow either a qualification-based certification path, or competency-based. A full explanation of the requirements to become certified with Exemplar Global can be found here or contact us for more information.

This course is offered In-house.
Request a quote for upskill your workforce.

Request an In-house quote


In house

In house training can provide a cost-effective training solution for organisations with a number of staff who require training. We can also customise a course to suit your own individual needs, and include your own audit documentation. Contact Brock or Carrie on 1300 95 96 92 for a quote and to discuss your individual training needs.


PwC's Auditor Training & Certification

Secure your place now and pay later

Book now
Worker on construction site

“This was one of the best training courses I have been on. Tom was engaging and kept the information relevant.”

“Many thanks Tom, I really enjoyed the course and will get a lot of use from it at my workplace.”

Course Dates

Only 2 for 1 courses
Only 2 for 1 courses

Can't find course dates in your city?

Register and we'll be in touch when courses are available

Register Now

“This was one of the best training courses I have been on. Tom was engaging and kept the information relevant.”

“Many thanks Tom, I really enjoyed the course and will get a lot of use from it at my workplace.”

“Overall very valuable course. Balance of theory with practical workshops was excellent. Trainers stuck to timetable very well.”

“The course was thorough and many relevant examples provided by both Tom and Jackie to help me apply it to the workplace.”

“Great presentation of the course, engaging facilitators and good use of group work. I found the course to be a great refresher for an audit course I did 10 years ago and now feel more motivated to go audits in a non-bow tie way!”