ISO/IEC 27001:2022 Information Security Management Systems Internal Auditor Course
- 2 DAY
ISO/IEC 27001:2022 Information Security Management Systems
- Internal Auditor Course
- 2 Day Course
Course Objectives
This two-day training course is designed for internal auditors or potential auditors who require an in-depth understanding of auditing an Information Security Management System (ISMS) against the requirements of ISO/IEC 27001:2022.
The course will help participants understand the key components of an effective ISMS and the role of the internal auditor in evaluating compliance, identifying opportunities for improvement and supporting the continual development of information security arrangements.
Course Content
This two-day Internal Auditor training course is delivered through a mixture of presentations, discussions and practical group exercises. The course will cover the following areas:
- Understanding the purpose and key requirements of ISO/IEC 27001:2022.
- Understanding the structure and core components of an Information Security Management System.
- Understanding information security risks, controls and the Statement of Applicability.
- Understanding the purpose of Annex A and its relationship to information security risk treatment.
- Understanding the principles of auditing and the role and responsibilities of an internal auditor.
- Planning and preparing for an internal ISMS audit.
- Gathering and evaluating objective audit evidence.
- Conducting effective audit interviews.
- Identifying and reporting nonconformities and opportunities for improvement.
- Preparing clear and effective internal audit reports.
- Understanding corrective action, audit follow-up and continual improvement.
- Applying internal auditing techniques through practical exercises.
Who Should Attend?
This course is suitable for individuals who are responsible for conducting or supporting internal audits of an Information Security Management System. It is particularly relevant for:
- Existing or prospective internal auditors.
- Information security and IT personnel.
- Quality, compliance and risk professionals.
- Data protection and information governance personnel.
- Managers, supervisors and employees involved in maintaining an ISMS.
- Individuals who want to develop their understanding of ISO/IEC 27001:2022 and internal auditing.
The course will build participants’ understanding of the purpose and requirements of ISO/IEC 27001:2022 and provide the practical knowledge needed to support an organisation’s internal audit programme.
No prerequisite qualifications or auditing experience are required. However, an interest in information security and management systems is essential to gain the full benefit from the course.
On satisfactory completion of the course, participants will receive a certificate.
Please contact us for the latest price for this 2-day course