About this course
This course builds the skills to audit an Information Security Management System against ISO 27001, covering risk assessment, Annex A controls, and the audit lifecycle from planning through reporting.
Everything you get
✓
Live instructor-led sessions
✓
Downloadable templates and working documents
✓
Full learning management system access
✓
Realistic simulated audit case study
✓
Exam registration handled for you
✓
Digital certificate on successful completion
Learning outcomes
OUTCOME 1
Explain the ISMS framework and ISO 27001 requirements
OUTCOME 2
Audit information security risk assessments and Annex A controls
OUTCOME 3
Plan, conduct, report and follow up an ISMS audit
OUTCOME 4
Evaluate the effectiveness of security controls
Practical, job-ready skills
Where this can take you
Step 1
Internal ISMS Auditor
Audit your organization's information security management system.
Step 2
ISMS Lead Auditor
Lead certification audits for third-party bodies.
Step 3
Information Security Manager
Oversee organization-wide security compliance.
Course modules
1
Module 1: ISMS Fundamentals & ISO 27001 Framework
2
Module 2: Audit Principles & Auditor Roles
3
Module 3: Risk Assessment & Statement of Applicability Review
4
Module 4: Conducting the Stage 2 Audit
5
Module 5: Auditing Annex A Controls
6
Module 6: Nonconformities & Reporting
7
Module 7: Closing Meetings & Corrective Action
8
Module 8: Auditor Ethics & Programme Management
Format & delivery
✓
Live virtual instructor-led sessions
✓
One continuous case study audited end-to-end
✓
Choice of intensive or part-time schedule
How you're assessed
Assessment is continuous through in-course activities, plus a final objective examination lasting approximately 1 hour 45 minutes, open book. Your first exam attempt is included in the course fee. A certificate is issued shortly after a passing result.
Who should attend
- Information security managers and officers
- IT governance and risk professionals
- Internal auditors moving to certification auditing
- Professionals pursuing ISMS lead auditor certification
Frequently asked questions
What does this course cover? +
ISO 27001 requirements, risk assessment, Annex A controls, and the ISMS audit lifecycle.
Do I need an IT background? +
Basic information security awareness is helpful but not mandatory.
Is this course recognized internationally? +
It follows internationally recognized ISO 19011 auditing principles applied to ISO 27001.
What is the exam duration? +
Approximately 1 hour 45 minutes, open book.
Do I need to bring my own materials? +
All materials are provided digitally through the learning management system.