Course Outline
I. Introduction to Information Security
1. Systemic approaches to information security management
2. Organizational benefits and added value
II. Overview of ISO 27001 Requirements
1. Detailed breakdown of standard requirements
2. Key areas requiring special attention
3. Identifying documentation obligations
4. Introduction to Annex A
III. ISO 27001-Compliant Information Security Management System (ISMS)
1. Core components of the ISMS per ISO 27001
2. Practical exercises in interpreting and analyzing standard requirements
IV. Fundamentals of Auditing
1. Basic concepts of auditing
2. The complete audit lifecycle
3. Definition of audit criteria
4. Different categories of audits
V. Audit Planning and Preparation
1. Defining audit criteria and scope
2. Criteria for selecting auditor teams
3. Applying the process approach to internal audits
4. Key considerations when developing checklists
5. Conducting audits per ISO 19011:2018
6. Practical application exercises
VI. Executing the Audit – On-Site Protocols
1. Advanced auditing techniques
2. Gathering objective evidence
3. Identifying and substantiating non-conformities
4. Required auditor competencies (note: 'watering' in source likely refers to 'internal' or similar, kept as 'auditor' for accuracy)
5. Hands-on practice sessions
VII. Reporting Audit Outcomes
1. Effective phrasing of non-conformities
2. Proper documentation of findings
3. Highlighting insights and improvement opportunities
4. Summarizing results in the final Audit Report
5. Practical drafting exercises
VIII. Post-Audit Activities and Follow-Up
1. Roles in initiating corrective and preventive actions
2. Determining root causes of non-conformities
3. Defining effective corrective measures
4. Assessing the effectiveness of implemented actions
5. Leveraging insights for continuous improvement
6. Follow-up practical exercises
IX. Review and Conclusion
The following outlines the ISO/IEC 27001 Lead Auditor certification path, formatted for web presentation.
PECB ISO/IEC 27001 Auditor Certification Criteria
To attain any PECB ISO/IEC 27001 Auditor designation, candidates must successfully pass the PECB Certified ISO/IEC 27001 Lead Auditor exam (or an approved equivalent) and adhere to the PECB Code of Ethics.
Your professional background and history of active management system (MS) audits determine which of the four certification levels you may pursue:
1. Provisional Auditor
-
Credential: PECB Certified ISO/IEC 27001 Provisional Auditor
-
Experience: No prior professional experience required.
-
MS Audit Experience: No prior MS audit/assessment experience required.
-
Best For: Individuals who have passed the exam but do not yet meet the field experience thresholds for higher designations.
2. Auditor
-
Credential: PECB Certified ISO/IEC 27001 Auditor
-
Experience: Two years of total professional experience, including at least one year in Information Security Management.
-
MS Audit Experience: 200 documented hours of audit/assessment activities.
3. Lead Auditor
-
Credential: PECB Certified ISO/IEC 27001 Lead Auditor
-
Experience: Five years of total professional experience, including at least two years in Information Security Management.
-
MS Audit Experience: 300 documented hours of audit/assessment activities.
4. Senior Lead Auditor
-
Credential: PECB Certified ISO/IEC 27001 Senior Lead Auditor
-
Experience: Ten years of total professional experience, including at least seven years in Information Security Management.
-
MS Audit Experience: 1,000 documented hours of audit/assessment activities.
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-auditor
Requirements
Target Audience
- Professionals preparing to take on the role of Lead Auditor for ISO 27001:2023
- Individuals with a general interest in information security auditing