Course Outline
I. Information Security Management System aligned with ISO 27001 requirements
1. Components of the Information Security Management System per ISO 27001
2. Exercises in interpreting and analysing ISO 27001 requirements
II. Audits – general overview
1. The complete audit lifecycle
2. Different types of audits
III. Audit planning and preparation
1. Audit criteria and scope definition
2. Selection of the audit team
3. Process-oriented approach to internal audits
4. Key considerations when developing a checklist of control questions
5. Practical exercises
IV. Conducting the audit – guidelines for on-site activities
1. Audit techniques
2. Collecting objective evidence
3. Identifying non-conformities and demonstrating them
4. Practical exercises
V. Documenting audit findings
1. Skillful articulation of discrepancies
2. Documenting non-conformities
3. Identifying and recording insights and improvement opportunities
4. Summary of Audit Results – Audit Report
5. Practical exercises
VI. Effective post-audit activities
1. Responsibilities related to initiating corrective actions
2. The importance of accurately determining the root causes of non-conformities
3. Defining corrective actions
4. Evaluating the effectiveness of implemented actions
5. Post-audit activities concerning insights and improvement potentials
6. Practical exercises
VII. Discussion and summary
Requirements
Audience
- Individuals preparing for the role of Internal Auditor under ISO 27001:2023
- Anyone with an interest in the subject matter