Course Outline
I. Information Security Management System (ISMS) aligned with ISO 27001 requirements
1. Key components of the ISMS as per ISO 27001
2. Exercises on interpreting and analysing ISO 27001 requirements
II. Audits – Overview
1. The complete audit process
2. Types of audits
III. Audit planning and preparation
1. Defining audit criteria and scope
2. Selecting the audit team
3. Process-oriented approach to internal audits
4. Key considerations when developing a checklist of audit questions
5. Practical exercises
IV. Conducting the audit – Guidelines for on-site assessments
1. Auditing techniques
2. Establishing objective evidence
3. Identifying non-conformities and substantiating them
4. Practical exercises
V. Documenting audit findings
1. Artful phrasing of findings
2. Documenting non-conformities
3. Identifying and recording insights and improvement opportunities
4. Audit report – summarising results
5. Practical exercises
VI. Effective post-audit activities
1. Responsibilities for initiating corrective actions
2. The importance of accurately determining the root causes of non-conformities
3. Defining corrective actions
4. Evaluating the effectiveness of actions taken
5. Post-audit activities related to insights and improvement potentials
6. Practical exercises
VII. Discussion and summary
Requirements
Target Audience
- Professionals preparing to take on the role of an ISO 27001:2023 Internal Auditor.
- Anyone with an interest in the subject matter.