Auditing is crucial to the success of any management system. As a result, it carries with it heavy responsibilities, tough challenges and complex problems. This five-day intensive course trains ISMS auditors to lead, plan, manage and implement an Audit Plan. It also empowers them to give practical help and information to those who are working towards certification and also provides the knowledge and skill required to carry out 2nd party auditing (suppliers and subcontractors).
How will I benefit?
Effective auditing helps to ensure that the measures you put in place to protect your organization and your customers are properly managed and achieve the desired result.
Who should attend?
- Those wishing to Lead audits of Information Security Management System (ISMS) in accordance with ISO 27001:2013 (either as a 2nd party, or 3rd party auditor)
- Those wishing to learn about effective audit practices
- Existing information security auditors who wish to expand their auditing skills
- Consultants who wish to provide advice on ISO 27001:2013 ISMS Auditing
- Security and quality professionals
Prerequisites
Delegates are expected to have the following prior knowledge:
- The requirements of ISO/IEC 27001 (with ISO/IEC 27002) and the commonly used information security management terms and definitions, as given in ISO/IEC 27000.
- The Plan-Do-Check-Act (PDCA) cycle.
- The assignment of responsibility for information security;
- Using the results of risk assessments to determine appropriate controls to reach acceptable levels of risk;
- Incorporating security as an essential element of information networks and systems;
- The active prevention and detection of information security incidents.