Course Outline
I. Information Security Management System compliant with ISO 27001 requirements
1. Components of the Information Security Management System as defined by ISO 27001
2. Exercises involving the interpretation and analysis of ISO 27001 requirements
II. Audits – General Overview
1. The complete audit process
2. Different types of audits
III. Audit planning and preparation
1. Establishing audit criteria and scope
2. Selecting the audit team
3. Applying a process approach to internal audits
4. Key considerations when developing a checklist of control questions
5. Practical exercises
IV. Conducting the audit – Rules for on-site assessments
1. Auditing techniques
2. Collecting objective evidence
3. Identifying non-conformities and presenting them effectively
4. Practical exercises
V. Documenting audit outcomes
1. Skillfully articulating findings of non-compliance
2. Recording non-conformities
3. Identifying and documenting insights and opportunities for improvement
4. Summarising audit outcomes – Producing the Audit Report
5. Practical exercises
VI. Effective post-audit activities
1. Responsibilities regarding the initiation of corrective actions
2. The importance of accurately determining the root causes of non-conformity
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities related to insights and improvement potentials
6. Practical exercises
VII. Discussion and summary
Requirements
Target Audience
- Individuals preparing for the role of Internal Auditor under ISO 27001:2023
- Any person with an interest in the subject matter
Testimonials (1)
Speed of response and communication