Course description

This five-day intensive course enables participants to develop the necessary expertise to audit an Information Security Management System (ISMS) and to manage a team of auditors by applying widely recognised audit principles, procedures and techniques. The ISO /IEC 27001 proves that you have the expertise to support an organization to successfully implement an Information Security Management System (ISMS) and avoid threats, vulnerabilities and possible negative impacts. This enables you to establish a systematic analysis of an organization’s information security risks and ensure the protection of the sensitive data. One of the major benefits for individuals who seek to pursue this certification is that the standard is recognized internationally as the best practice, allowing you to offer a continual improvement to your organization and ensure its compliance with regulations and requirements.

Course content

Day 1 Introduction to Information Security Management Systems (ISMS) and ISO/IEC 27001
  • Course objectives and structure
  • Standards and regulatory frameworks
  • Certification process
  • Fundamental principles of Information Security
  • Management Systems
  • Information Security Management Systems (ISMS)
Day 2 Audit principles, preparation and launching of an audit
  • Fundamental audit concepts and principles
  • Evidence based audit approach
  • Initiating the audit
  • Stage 1 audit
  • Preparing the stage 2 audit (on-site audit)
  • Stage 2 audit (Part 1)
Day 3 On-site audit activities
  • Stage 2 audit (Part 2)
  • Communication during the audit
  • Audit procedures
  • Creating audit test plans
  • Drafting audit findings and non-conformity reports
Day 4 Closing the audit
  • Documentation of the audit and the audit quality review
  • Closing the audit
  • Evaluating action plans by the auditor
  • Benefits of the initial audit
  • Managing an internal audit program
  • Competence and evaluation of auditors
  • Closing the training
Day 5 Revise & Exams
  • Exam preparation and revision

Course Objectives

During this training, the participant will acquire the necessary knowledge and skills to proficiently plan and perform internal and external audits in compliance with ISO 19011 the certification process according to ISO 17021. Based on practical exercises, the participant will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary to efficiently conduct an audit.

Target audience

  • IT Auditor
  • Information Security Officer
  • Technical Project Management
  • Security Business Analyst
  • Persons responsible for auditing and monitoring management systems

Location / Delivery

  • Classroom

Start date

  • August 24, 2020


  • 5 days


  • £850.00 £1,200.00

Related Courses

Certification & Exams