Course : ISO 27001: Lead Auditor, PECB Certification

ISO 27001: Lead Auditor, PECB Certification




This course presents the ISO standards (19011, 27001, etc) for Information System Security and explains what is needed to audit an information security risk management system (ISMS).


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class

Ref. ISD
  5d - 35h00
Price : Contact us




This course presents the ISO standards (19011, 27001, etc) for Information System Security and explains what is needed to audit an information security risk management system (ISMS).


Teaching objectives
At the end of the training, the participant will be able to:
Comprender el funcionamiento de un sistema de gestión de la seguridad de la información (SGSI) conforme a la ISO 27001
Explicar la correlación entre ISO/CEI 27001 y 27002, así como con otras normas y marcos normativos
Comprender el papel de un auditor: planificación, dirección y seguimiento de una auditoría del SGSI de conformidad con la norma ISO 19011
Dirigir una auditoría y un equipo de auditoría
Interpretar los requisitos de la norma ISO/CEI 27001 en el contexto de una auditoría del SGSI

Intended audience
Internal auditors, risk managers, CISOs, IT directors or managers, security engineers or contacts, project managers who work with security constraints.

Prerequisites
Basic knowledge of IT security.

Certification
The final exam certifies that you possess the knowledge and skills required to implement an ISMS according to the ISO/IEC 27001:2022 standard. The exam is held during the final half-day session and is conducted in partnership with the PECB certification body. The course materials include extracts from the relevant standard(s) necessary for the certification exam. The exam is administered remotely in an asynchronous format.
Remote certifications
See the certifier’s official documentation for the list of prerequisites for completing the online certification exam.

Course schedule

1
Information security management system (ISMS)

  • Standards and regulatory frameworks.
  • Fundamental principles of the information security management system.
  • How an information security management system (ISMS) compliant with the ISO 27001 standard works.
  • Leading an audit and an audit team.

2
Audit principles, preparation, and triggering

  • Principles and fundamental concepts of an audit.
  • Evidence-based approach to auditing.
  • Interpreting the requirements of ISO/IEC 27001 in the context of an ISMS audit
  • Step 1 of the audit.
  • Preparing for step 2 of the audit (on-site audit).
  • Preparing for an ISO/IEC 27001 and triggering the audit.
  • Conducting an ISO/IEC 27001 audit.
  • Role of an auditor: Planning, directing, and tracking a management system audit with the ISO 19011 standard.

3
On-site auditing activities

  • Step 2 of the audit.
  • Communication during the audit.
  • Auditing procedures.
  • Writing audit testing plans.
  • Writing audit findings and non-compliance reports.

4
Ending the audit

  • Documenting the audit and reviewing the audit’s quality.
  • Closing an ISO/IEC 27001 audit
  • Assessment of action plans by the auditor.
  • Advantages of the initial audit.
  • Managing an internal audit program.
  • Skills and assessment of auditors.

5
Certification

  • Review. Tips for the exam.
  • Contents of the exam, rules to follow. Standards or other documents provided to the candidates.
  • Conditions in place to preserve the confidentiality of the copies.
  • Minimum score needed to pass the written exam.
  • The exam includes a multiple-choice questionnaire about the ISO/IEC 27001 standards.
  • A participation certificate worth 31 CPD (Continuing Professional Development) credits is issued.
Exam
Mock exam and group correction. Taking the exam.


Customer reviews
4,4 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.


Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class