• Practical orientation - not just theory.  Features extensive use of real-world examples from trainer personal experience
  • The ONLY independently accredited ISO 27001 Lead Auditor training in Asia-Pacific.
  • Certificate exam 3rd-party set and marked
  • Based on most recent version ISO 27001:2013

ISO 27001  is  the  recognised  international  standard  for  best practice  in  information  security  management  systems  (ISMS) within any organisation. This course will prepare you to plan and execute audits of information security management systems in line with the international standard ISO/IEC 27001.

Using the most recent version ISO 27001:2013, this training is based on management system audit guidelines (ISO 19011:2002) as well as international audit best practices: the International Federation of Accountants (IFAC), the American Institute of Certified Public Accountants (AICPA), the Information Systems Audit and Control Association (ISACA) and the Institute of Internal Auditor (IIA). An audit kit developed by experienced auditors will be distributed to participants.

Learning outcomes

  • Acquiring the expertise to perform an ISO 27001 internal audit as specified by ISO 19011
  • Acquiring  the  expertise  to  perform  an  ISO  27001  certification audit as specified by ISO 19011, ISO 17021 and ISO 27006
  • Acquiring  the  expertise  necessary  to  manage  an  ISMS  audit team
  • Understanding   the   application   of   the   information   security management system in the context of ISO 27001
  • Understand  the  relationship between  an  Information Security Management System, including risk management, controls and compliance with the requirements  of different stakeholders  of the organisation
  • Improve  the   ability  to   analyse  the   internal  and   external environment  of  an  organisation,   risk assessment   and  audit decision-making in the context of an ISMS

Who should attend

  • Internal auditors
  • Auditors wanting to perform and lead Information Security Management System (ISMS) certification audits
  • Project managers or consultants wanting to master the Information Security Management System audit process
  • Persons responsible for the Information security or conformity in an organisation
  • Members of an information security team
  • Expert advisors in information technology
  • Technical experts wanting to prepare for an Information security audit function

Course contents

Day 1: Introduction to the management of an Information Security Management System based on ISO 27001
  • Normative and regulatory and legal framework related to information security
  • Fundamental principles in Information Security
  • ISO 27001 certification process
  • Information Security Management System (ISMS)
  • Detailed presentation of the clauses 4 to 8 of the ISO 27001 standard
Day 2: Launching an ISO 27001 audit
  • Fundamental audit concepts and principles
  • Audit approach based on evidence and on risk
  • Preparation of an ISO 27001 certification audit
  • Documenting of an ISMS audit
  • Conducting an opening meeting
Day 3: Conducting an ISO 27001 audit
  • Communication during the audit
  • Audit procedures:
    • observation,
    • document review
    • interview
    • sampling techniques
    • technical verification
    • Corroboration and evaluation
    • Drafting test plans
    • Formulation of audit findings
    • Drafting of nonconformity reports
Day 4: Closing an ISO 27001 audit
  • Audit documentation
  • Quality review
  • Review of audit notes
  • Conducting a closing meeting and conclusion of an ISO 27001 audit
  • Evaluation of corrective action plans
  • Surveillance audit
  • Audit management program
  • Completion of training
Day 5
  • Course review
  • Exam preparation
  • Certificate exam

Course fees

S$3,450 + gst

Fees are per person and include:

  • Course presentation
  • Course workbook
  • Supplementary materials
  • Certificate exam (held on last day of course)
  • Full catering including sit-down lunch each day

Prerequisites

ISO 27001 Foundation certification or basic knowledge of ISO27001 and ISO 27002 is recommended.

Examination

The ISO 27001 Lead Auditor exam is held on the last day of the course.

  • The exam consists of essay-type questions
  • 3 hours duration
  • Minimum passing score: 70%
  • A certificate will be issued to participants who successfully complete the exam
  • After the training, the participant can apply for the title of ISO 27001 provisional auditor, ISO 27001 auditor, ISO 27001 principal auditor or ISO 27001 lead auditor depending on their experience.
    Visit https://pecb.com/iso-27001-auditor-certification for more information.
  • The certificate for the successful completion of the ISO 27001 Lead Auditor exam is recognised by IRCA (International Register of Certificated Auditors) and meets the IRCA/2016 certification criteria.
  • A participant can register as IRCA or RABQSA auditor
  • Successful participants can register as an accredited IRCA auditor

Certification Levels

There are three levels of accreditation that you can apply for after passing the exam, depending on professional experience:

  • ISO/IEC 27001 Provisional Auditor - exam passed, no direct professional experience, no MS audit/assessment experience
  • ISO/IEC 27001 Auditor - exam passed, two years professional experience with at least one year in information security, audit experience of at least 200 hours
  • ISO/IEC 27001 Lead Auditor - exam passed, five years professional experience with at least two years in information security, audit experience of at least 300 hours

Candidates can apply for the appropriate level of accreditation once exam results have been received.