Course Outline
I. Information Security Management System (ISMS) Requirements under ISO 27001
1. Key components of an ISMS aligned with ISO 27001
2. Exercises interpreting and analyzing ISO 27001 requirements
II. Overview of Auditing
1. The complete audit process
2. Types of audits
III. Audit Planning and Preparation
1. Defining audit criteria and scope
2. Assembling the auditor team
3. Applying a process approach to internal audits
4. Key considerations for developing control questionnaires
5. Practical exercises
IV. Executing the Audit – Guidelines for On-Site Activities
1. Auditing techniques
2. Gathering objective evidence
3. Identifying non-conformities and demonstrating them effectively
4. Practical exercises
V. Documenting Audit Findings
1. Clearly articulating observations and inconsistencies
2. Documenting non-conformities
3. Identifying and recording insights and improvement opportunities
4. Compiling the Audit Report
5. Practical exercises
VI. Post-Audit Activities for Continuous Improvement
1. Roles and responsibilities in initiating corrective actions
2. The importance of accurately determining root causes of non-conformities
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Addressing insights and improvement potentials in post-audit phases
6. Practical exercises
VII. Discussion and Summary
Requirements
Target Audience
- Professionals preparing to assume the role of ISO 27001:2023 Internal Auditor
- Individuals with a general interest in the subject matter