Course Outline
I. Information Security Management System compliant with the requirements of ISO 27001
1. Components of the Information Security Management System as per ISO 27001
2. Exercises in interpreting and analyzing ISO 27001 requirements
II. Audits – Overview
1. Comprehensive audit process
2. Types of audits
III. Audit planning and preparation
1. Audit criteria and scope
2. Selecting an auditor team
3. Applying a process approach to internal audits
4. Key considerations when developing a control question checklist
5. Practical exercises
IV. Conducting an audit – Guidelines for on-site assessments
1. Auditing techniques
2. Objective evidence
3. Identifying and demonstrating non-conformities
4. Practical exercises
V. Documenting audit findings
1. Crafting precise descriptions of discrepancies
2. Recording non-conformities
3. Identifying and documenting insights and areas for improvement
4. Summarizing audit results – Audit Report
5. Practical exercises
VI. Effective post-audit activities
1. Responsibilities for initiating corrective actions
2. The Importance of Accurately Determining the Root Causes of Non-Conformity
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities concerning insights and improvement opportunities
6. Practical exercises
VII. Discussion and summary
Requirements
Audience
- Individuals preparing for the role of Internal Auditor 27001:2023
- Anyone with an interest in the subject