Course Outline
I. Introduction to Information Security
1. Systemic management of information security
2. Strategic benefits and value addition for public entities
II. Overview of ISO 27001 Requirements
1. Defining the core requirements of the standard
2. Critical areas requiring heightened attention
3. Identification of documentation obligations
4. Summary of Annex A controls
III. Information Security Management System (ISMS) Aligned with ISO 27001
1. Core components of the ISMS under ISO 27001
2. Practical exercises in interpreting and analyzing standard requirements
IV. Audits – General Overview
1. Fundamentals of the audit process
2. Scope of the entire audit cycle
3. Establishment of audit criteria
4. Classification of audit types
V. Audit Planning and Preparation
1. Defining audit criteria and scope
2. Selection of qualified auditor teams
3. Applying the process approach to internal audits
4. Key considerations when developing control question lists
5. Execution of audits in accordance with ISO 19011:2018
6. Practical application exercises
VI. Conducting Audits – Protocols for On-Site Evaluations
1. Methodologies for auditing
2. Collection of objective evidence
3. Identification and demonstration of non-conformities
4. Required competencies for the auditing officer
5. Practical application exercises
VII. Documentation of Audit Results
1. Precise formulation of identified inconsistencies
2. Formal recording of non-conformities
3. Identification and documentation of insights and improvement opportunities
4. Consolidation of audit findings into the final report
5. Practical application exercises
VIII. Post-Audit Activities and Corrective Actions
1. Responsibilities for initiating corrective and remedial measures
2. Critical importance of accurately determining root causes of non-conformities
3. Definition of specific corrective actions
4. Assessment of the effectiveness of implemented actions
5. Post-audit follow-up regarding insights and improvement potentials
6. Practical application exercises
IX. Discussion and Summary
The following is a structured summary of the ISO/IEC 27001 Lead Auditor certification pathway, formatted for public access.
PECB ISO/IEC 27001 Auditor Certification Requirements
To achieve any PECB ISO/IEC 27001 Auditor designation, all candidates must successfully pass the PECB Certified ISO/IEC 27001 Lead Auditor examination (or an approved equivalent) and execute the PECB Code of Ethics.
Your level of professional experience and history of active management system (MS) audits determine eligibility for one of the four certification tiers:
1. Provisional Auditor
-
Credential Designation: PECB Certified ISO/IEC 27001 Provisional Auditor
-
Professional Experience: No prior experience required.
-
MS Audit/Assessment Experience: No prior experience required.
-
Intended For: Professionals who have passed the examination but lack the requisite field experience to qualify for advanced levels.
2. Auditor
-
Credential Designation: PECB Certified ISO/IEC 27001 Auditor
-
Professional Experience: Two years of overall experience, including at least one year specifically focused on Information Security Management.
-
MS Audit/Assessment Experience: A cumulative total of 200 hours of documented audit activities.
3. Lead Auditor
-
Credential Designation: PECB Certified ISO/IEC 27001 Lead Auditor
-
Professional Experience: Five years of overall experience, including at least two years specifically focused on Information Security Management.
-
MS Audit/Assessment Experience: A cumulative total of 300 hours of documented audit activities.
4. Senior Lead Auditor
-
Credential Designation: PECB Certified ISO/IEC 27001 Senior Lead Auditor
-
Professional Experience: Ten years of overall experience, including at least seven years specifically focused on Information Security Management.
-
MS Audit/Assessment Experience: A cumulative total of 1,000 hours of documented audit activities.
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-auditor
Requirements
Target Audience
- Professionals preparing for the Lead Auditor role under ISO 27001:2023
- Any individual interested in information security governance and auditing
Testimonials (1)
Speed of response and communication