Course

ISO/IEC 27001 Lead Auditor («HSI»)

This training enables you to develop the necessary expertise to perform an Information Security Management System (ISMS) audit by applying widely recognized audit principles, procedures and techniques.
Duration 5 days
Price 5'900.–
Course documents Official material and ISO standards
Information Included examination fee worth CHF 800.–

Course facts

  • Understanding how an information security management system based on ISO/IEC 27001 works 
  • Understanding the relationships between ISO/IEC 27001, ISO/IEC 27002 and other standards and regulations
  • Understanding the role of an auditor: planning, performing and following up an ISO 19011 management system audit
  • Leading an audit and an audit team
  • Interpreting the requirements of ISO/IEC 27001 in the context of an ISMS audit
  • Acquiring the skills of an auditor: planning, conducting, reporting and following up an ISO 19011 audit

Day 1: Introduction to Information Security Management Systems (ISMS) and ISO/IEC 27001

  • Course objectives and structure
  • Standards and regulatory frameworks
  • Certification process
  • Fundamental principles of Information Security
  • Management Systems
  • Information Security Management Systems (ISMS)

Day 2: Audit principles, preparation and launching of an audit

  • Fundamental audit concepts and principles
  • Evidence based audit approach
  • Initiating the audit
  • Stage 1 audit
  • Preparing the stage 2 audit (on-site audit)
  • Stage 2 audit (Part 1)

Day 3: On-site audit activities

  • Stage 2 audit (Part 2)
  • Communication during the audit
  • Audit procedures
  • Creating audit test plans
  • Drafting audit findings and non-conformity reports

Day 4: Closing the audit

  • Documentation of the audit and the audit quality review
  • Closing the audit
  • Evaluating action plans by the auditor
  • Benefits of the initial audit
  • Managing an internal audit program
  • Competence and evaluation of auditors
  • Closing the training

Day 5: Certification Exam

Consists of the following modules

  • ISO/IEC 27001 Lead Auditor
  • Exam ISO/IEC 27001 Lead Auditor

This training is based on both theory and best practices used in ISMS audits :

  • Lecture sessions are illustrated with examples based on case studies
  • Practical exercises are based on a case study which includes role playing and discussions
  • Practice tests are similar to the Certification Exam
  • Auditors seeking to perform and lead Information Security Management System (ISMS) certification audits
  • Managers or consultants seeking to master an Information Security Management System audit process
  • Individuals responsible for maintaining conformance with Information Security Management System requirements
  • Technical experts seeking to prepare for an Information Security Management System audit 
  • Expert advisors in Information Security Management

A fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles, equivalent to the training : 

Training material containing over 600 pages of information and practical examples will be distributed.

  • Copy of the ISO 19011 standard
  • Copy of the ISO 27001 standard

Download

Questions

Choose your date

Further courses