ISO 27001 Lead Auditor Course Objectives
- Introduction of ISO 27001:2013 Series LA Training Course
- Introduction of Information Security Management Systems and Standards Development.
- Requirements of ISO 27001:2013
- Audit Planning and Preparation
- Process Audit Techniques and Collecting Evidence
- Conclusion
ISO 27001 Lead Auditor Course Outline
Introduction of ISO 27001:2013 Series LA Training Course
- Introduction
- Auditor Certification
- World-Wide Recognition of Auditor Qualifications
- Reference Standards and Documents
- Learning Objectives
- Continues Assessment
- Examination
- IRCA Code of Conduct
Introduction of Information Security Management Systems and Standards Development
- Definition and importance of Information in ISMS
- CIA and DAD Triads
- Additional Goals
- ISMS Purpose and Objectives
- Legal and Regulatory compliance
Requirements of ISO 27001:2013
- Quick Content Comparison ISO 27001:2013vs ISO 27001:2013
- Contents of ISO 27001:2013
- Process approach and processes involved in establishing
- Implementing & operation
- ISMS scope, boundaries of ISMS and permissible exclusions
- ISMS Scope and exclusions
- ISMS Clauses
- Policy and Objectives
- Asset Register
- Risk Assessment and Risk Treatment
- Risk Assessment examination and Evaluation
- Annex A Controls and ISO 27002
- Introduction to SoA Examination and Evaluation
Audit Planning and Preparation
- Reasons for auditing
- Audit principles
- Process of audit program management
- Audit competence and evaluation methods
- Audit Responsibilities
Process Audit Techniques and Collecting Evidence
- Process auditing, Auditor qualities and selection
- Audit Script
- Audit stages
- Audit techniques
- Collecting evidence through questions
- Observation, checking, note taking, and collecting evidence
- Audit techniques and collecting evidence through questions, observation, checking, note taking and collecting evidence
- Introduction to audit role playing
- Reporting the Audit Findings
Intended Audience for this ISO 27001 Lead Auditor
- Quality professionals with experience in implementation and auditing of information Security Management Systems (ISMS)
- Those wishing to implement a formal Information Security Management System (ISMS) in accordance with ISO 27001:2013
- Existing security auditors who wish to expand their auditing skills
- Consultants who wish to provide advice on ISO 27001:2013 systems certification.
- Security and Quality Professionals