Course Outline
I. Introduction to Information Security
1. Systemic information security management
2. Benefits and added value for the organization
II. Overview of ISO 27001 Requirements
1. Key requirements of the standard
2. Critical areas requiring special attention
3. Identification of documentation requirements
4. Overview of Annex A
III. Information Security Management System Compliant with ISO 27001 Requirements
1. Elements of the Information Security Management System according to ISO 27001
2. Exercises in interpreting and analyzing the requirements of ISO 27001
IV. Audits – General Information
1. Introduction to auditing
2. Complete audit process
3. Audit criteria
4. Types of audits
V. Audit Planning and Preparation
1. Audit criteria and scope
2. Selection of the audit team
3. Process approach to internal audits
4. Key aspects when creating a control question list
5. Conducting an audit according to ISO 19011:2018
6. Practical exercises
VI. Conducting an Audit – Rules for On-Site Audits
1. Auditing techniques
2. Objective evidence
3. Identification of non-conformities and methods for demonstrating them
4. Competencies of an auditor
5. Practical exercises
VII. Documenting Audit Results
1. Effective formulation of findings
2. Documenting non-conformities
3. Identifying and documenting insights and areas for improvement
4. Summary of Audit Results – Audit Report
5. Practical exercises
VIII. Effective Post-Audit Activities
1. Responsibilities related to initiating corrective actions
2. The importance of precisely determining the causes of non-conformity
3. Defining corrective actions
4. Evaluating the effectiveness of actions taken
5. Post-audit activities related to insights and areas for improvement
6. Practical exercises
IX. Discussion and Summary
Requirements
Target Audience
- Professionals preparing for the role of Lead Auditor for ISO 27001:2023
- Anyone with an interest in the subject matter
Testimonials (1)
Speed of response and communication