Participants will learn the auditing requirements of ISO 27001, and how to best apply and integrate the standard for the benefit of an organisation.
Module
This course is delivered as a single, 3 day module covering the requirements of ISO/IEC 27001.
This module can be joined to an additional module; ‘Becoming a Skilled Lead Internal/External Auditor‘ where participants learn to conduct management systems audits in accordance with ISO 19011:2011 Guidelines for Auditing Management Systems. The course provides a comprehensive and practical understanding of how to conduct a successful internal or external audit, either as part of an audit team or as the team leader. We focus in particular on the principles and procedures of auditing, the importance of planning, the roles and responsibilities of an auditor, how to gather effective audit evidence and report on the audit findings, and the required follow up activities as an auditor. To complete these modules together, see the Information Management Systems Lead Auditor course.
Day 1
Information Security Management Systems
- Introduction to Information Security
- Context of Information Security
- Information Security management systems requirements
- Risk-based approach to information security
Day 2
Information Security controls
- ISO 27001 – Code of practice for Information Security management
- Information classification
- Documentation requirements of Information security management systems
Day 3
Information Security application
- Statement of applicability
- Information security audit scenarios
- Course review