Key details...

Cost: $2,995 (inc. GST)

Duration: 5 Days

PD Points: 40

Qualifications: AU TL IS

About the course...

This training session outlines the key processes and approaches a business needs to manage Information Security risk in a practical way. Learn how to implement and audit an Information Security Management System adhering to the specific requirements of ISO/IEC 27001, in order to protect information assets such as customer details, sensitive corporate information and financial data. 

Plus, you receive a free licensed copy of:

  • ISO/IEC 27001:2013 Information technology – Security techniques – Information security management systems – requirements.

Our training is different because...

No Homework or take-home assessment.

Internationally recognised courses.

Trainers are practising audit professionals.

All Learning materials and refreshments provided.

Certificates are issued promptly upon the completion of the course.

We never cancel a course - enrol with confidence.

Secure your place now

Book now

Course overview...

Learning Outcomes

Participants will gain the knowledge to conduct internal or external audits of an Information Security Management System, either as a sole auditor, a member of an audit team, or as the team leader. Specifically, you will:

  • Learn how to plan and carry out an ISO 27001:2013 audit
  • Learn report writing and how to document an Information Security system
  • Recognise the role of the auditor
  • Understand, and be able to implement processes within the Information Security management system
  • Be able to improve your organisation’s conformance with ISO/IEC 27001:2013
  • Learn how to identify gaps in an Information Security management system
  • Satisfy training needs for Exemplar Global certification

This course includes a complimentary copy of ISO/IEC 27001:2013.

Course Content

Participants learn how to perform an audit in accordance with ISO 19011:2011 Guidelines for Auditing Management Systems. The course provides a comprehensive and practical understanding of how to conduct a successful internal or external audit, either as part of an audit team or as the team leader. We focus in particular on the principles and procedures of auditing, the importance of planning, the roles and responsibilities of an auditor, how to gather effective audit evidence and report on the audit findings, and the required follow up activities as an auditor.

Participants also learn the auditing requirements of ISO 27001, and how to best apply and integrate the standard for the benefit of an organisation.

This course is divided into two modules, enabling participants to attend both modules in the one week, or spread across different sessions. The first 2 day module is equivalent to our ‘Becoming a Skilled Lead Internal/External Auditor’ course, where participants learn to conduct management systems audits. The remaining 3 day module covers the requirements of the Information security management systems standard, ISO 27001 and Information Security controls.

Day 1

Introduction to Management Systems Auditing

  • Introduction to auditing
  • Roles and responsibilities of an auditor
  • Principles and procedures of auditing
  • Communication skills and interview techniques
  • Setting appropriate audit objectives, goals, and criteria
  • Planning a Management systems audit

Day 2

Management Systems Auditing

  • How to ensure that audits add value to an organisation
  • Auditing as a Team Leader
  • Effective audit evidence
  • Management Systems auditing scenarios
  • Writing audit findings and the audit report
  • Developing the audit report and writing audit findings
  • Reviewing corrective action

Day 3

Information Security Management Systems

  • Introduction to Information Security
  • Context of Information Security
  • Information Security management systems requirements
  • Risk-based approach to information security

Day 4

Information Security controls

  • ISO 27001 – Code of practice for Information Security management
  • Information classification
  • Documentation requirements of Information security management systems

Day 5

Information Security application

  • Statement of applicability
  • Information security audit scenarios
  • Course review


Upon successful completion of the course, each participant will receive a Certificate of Attainment which identifies the 3 Exemplar Global competencies below:

  1. Exemplar Global IS – Information Security management systems
  2. Exemplar Global AU – Management systems auditing
  3. Exemplar Global TL – Leading management systems audit teams

Additional Exemplar Global competencies for Quality Management Systems (Exemplar Global QM) Environmental Management Systems (Exemplar Global EM) and/or OH&S Management Systems (Exemplar Global OH), and Food Safety Management Systems (Exemplar Global FS) may be attended separately.


There are no prerequisites for this course.


During the course, participants will complete a series of workshops, which form part of the assessment. Upon the completion of each module there is a short multiple choice exam. Participants receive continual assistance and feedback from the facilitator.

Who should attend 

Designed to cater to a variety of people currently involved in the audit and Information Security Management System process, you should attend if you:

  • want to become an internal ISMS auditor
  • want to become a 3rd party IS auditor
  • need to write and implement a ISMS
  • are involved in the Information Security management process
  • are a manager responsible for an ISMS and ISMS auditing
  • wish to consolidate your existing knowledge into a formal qualification.

Prior experience in auditing and management systems is not essential.

Study Pathway – Where to from here?

If you wish to become a registered third-party, or external Information Security Management Systems auditor with Exemplar Global, completing this course is the first step.

Once you have obtained the Exemplar Global competencies from this course, you can follow the qualification-based certification path. A full explanation of the requirements to become certified with Exemplar Global can be found here or contact us for more information.

How to enrol

PwC offers an easy, streamlined enrolment process – you can either enrol directly into your course online, or call us on 1300 95 96 92 to enrol over the phone.

Discounts for multiple attendees are available – Please call us to find out what discounts can be applied.

How to pay

We offer a variety of payment methods:

  • Direct debit
  • Credit card
  • Cheque
  • Payment plans

Payment plans

We are able to arrange flexible payment plans on an individual basis. Please be aware that your certificate will be held until full payment has been received.


Public – Face to face

Our regular public courses are conducted in capital cities and key regional centres in Australia and New Zealand. You will enjoy an excellent learning experience in a premium training venue, and;

  • We never cancel courses – book with confidence
  • Class sizes are kept to manageable numbers – so everybody learns
  • No homework or take-home assessment! All work is completed in course time – we know you’re busy
  • No major exam – we assess you as you go

Public – Virtual/Online

In response to COVID-19 and social distancing, we’ve developed an online digital classroom to deliver our courses virtually and keep the interaction and engagement between trainer and participants. Our virtual training platform incorporates:

  • Group exercises – facilitated by mini break out workshops amongst the team
  • Ability to ask questions in real time
  • Built in note taking and tracking of course materials
  • You can interact with participants throughout the session through a chat functionality
  • Online assessments providing a streamlined marking process

Our aim is to recreate the classroom experience in a safe, virtual environment, maintaining the fun and engaging experience our clients find useful and valuable.

In house – Face to face or virtual

In house training can provide a cost-effective training solution for organisations with a number of staff who require training. We can also customise a course to suit your own individual needs, and include your own audit documentation. Call us on 1300 95 96 92 for a quote and to discuss your individual training needs.

PwC Training Academy

Secure your place now and pay later

Book now

“The virtual classroom coupled with an enthusiastic trainer made the course easy to run through and as good as any face to face courses I have ever attended.”

“Overall very valuable course. Balance of theory with practical workshops was excellent. Trainers stuck to the timetable very well.”

Course Dates

Only 2 for 1 courses
Only 2 for 1 courses
Sort Location Start Finish Duration
Virtual - AEDT Mon 28 Nov 2022 Fri 02 Dec 2022 5 Days Book now

There are no search results in your chosen search.
Register and we'll be in touch when courses are available

Register Now

Can't find course dates in your city?

Register and we'll be in touch when courses are available

Register Now

“The virtual classroom coupled with an enthusiastic trainer made the course easy to run through and as good as any face to face courses I have ever attended.”

“Overall very valuable course. Balance of theory with practical workshops was excellent. Trainers stuck to the timetable very well.”

“To be honest, I wasn’t really looking forward to the training and wasn’t too sure what to expect. It turned out to be quite enjoyable and a really great experience which I put down to the facilitators, Pat and Tom and the group. Both Pat and Tom shared their breadth of knowledge and experiences and were really engaging.”

“Great presentation of the course, engaging facilitators and good use of group work. I found the course to be a great refresher for an audit course I did 10 years ago and now feel more motivated to go audits in a non-bow tie way!”

“Trainers’ knowledge was excellent, their knowledge made the training and learning easy.”