Course Outline
I. Information Security Management Systems aligned with ISO 27001 Requirements
1. Core components of an ISM System per ISO 27001.
2. Practical application: Interpreting and analyzing ISO 27001 requirements.
II. Fundamentals of Auditing
1. Overview of the complete audit lifecycle.
2. Distinction between various types of audits.
III. Strategic Audit Planning and Preparation
1. Defining audit criteria and scope.
2. Criteria for selecting the audit team.
3. Applying the process approach to internal audits.
4. Key considerations when developing control question lists.
5. Applied practice exercises.
IV. Executing the Audit: Protocols for On-Site Engagement
1. Effective auditing techniques.
2. Collecting and utilizing objective evidence.
3. Identifying and clearly demonstrating non-conformities.
4. Applied practice exercises.
V. Reporting and Documentation of Audit Findings
1. Articulating inconsistencies with precision and clarity.
2. Proper documentation of non-conformities.
3. Highlighting insights and opportunities for improvement.
4. Compiling the final Audit Report and results summary.
5. Applied practice exercises.
VI. Post-Audit Actions and Continuous Improvement
1. Defining responsibilities for initiating corrective measures.
2. The critical role of accurate root cause analysis for non-conformities.
3. Formulating effective corrective actions.
4. Assessing the effectiveness of implemented actions.
5. Leveraging post-audit insights for further improvement.
6. Applied practice exercises.
VII. Closing Discussion and Course Summary
Requirements
Target Audience
- Professionals preparing to assume the role of an Internal Auditor for ISO 27001:2023.
- Individuals with a professional interest in information security management.