What you'll learn
- Audit as per the requirements of the ISO/IEC 27001 standard
- Understand key elements of the ISO 19011 and ISO/IEC 17021 standards
- Plan and execute an Information Security Management System audit
- Create clear, concise and relevant audit reports and communicate findings to a client
- Understand accreditation issues and auditor competence
Course outline
Foundations of ISMS Auditing
- Background and overview of ISO 27001 and other Information Security Standards
- Introduction to auditing and implementing an audit system
- The auditor's role in the process
Planning and Managing the Audit
- Management's role in reviewing risk and ISMS effectiveness
- Resources and timing
- Use of checklists
- Selection of audit teams
Conducting the Audit
- Audit skills, techniques and auditor competence
- Evaluating the significance of audit findings
- Communicating and presenting audit reports
Closing Out the Audit
- Nonconformities and improved security from corrective actions
- Management of the third-party assessment and certification process
