Course Outline
Day 1: Introduction to the Information Security Management System (ISMS) and ISO/IEC 27001 for government entities.
Day 2: Audit principles, preparation, and initiation of an audit for government agencies.
Day 3: On-site audit activities for government operations.
Day 4: Closing the audit for government organizations.
Day 5: Certification Exam
Examination:
The “PECB Certified ISO/IEC 27001 Lead Auditor” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). This exam covers the following competency domains for government professionals:
Domain 1: Fundamental principles and concepts of Information Security Management System (ISMS) for government.
Domain 2: Information Security Management System (ISMS) application in a government context.
Domain 3: Fundamental audit concepts and principles for government audits.
Domain 4: Preparation of an ISO/IEC 27001 audit for government agencies.
Domain 5: Conducting an ISO/IEC 27001 audit in a government setting.
Domain 6: Closing an ISO/IEC 27001 audit for government entities.
Domain 7: Managing an ISO/IEC 27001 audit program in a government environment.
Certification:
After successfully completing the exam, you can apply for the credentials shown in the table below. You will receive a certificate once all requirements related to the selected credential are met. For more information about ISO/IEC 27001 certifications and the PECB certification process, please refer to the Certification Rules and Policies.
The requirements for PECB Auditor Certifications are:
Credential
Exam
Professional experience
MS audit/assessment experience
Other requirements
PECB Certified ISO/IEC 27001 Provisional Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
None
None
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Two years: One year of work experience in Information Security Management for government.
Audit activities: a total of 200 hours
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Lead Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Five years: Two years of work experience in Information Security Management for government.
Audit activities: a total of 300 hours
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Senior Lead Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Ten years: Seven years of work experience in Information Security Management for government.
Audit activities: a total of 1,000 hours
Signing the PECB Code of Ethics
Note: PECB Certified Individuals who possess both Lead Implementer and Lead Auditor Credentials are qualified for the respective PECB Master Credential, provided they have completed four additional Foundation Exams related to this scheme. For more detailed information about the Foundation Exams and the overall Master Requirements, please visit: https://pecb.com/en/master-credentials.
To be considered valid, these audits should follow best audit practices and include the following activities:
- Audit planning
- Audit interview
- Managing an audit program
- Drafting audit reports
- Drafting non-conformity reports
- Drafting audit working documents
- Documentation review
- On-site Audit
- Follow-up on non-conformities
- Leading an audit team
Requirements
Testimonials (5)
The fact that there were practical examples with the content
Smita Hanuman - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
The knowledge and understanding of the trainer on the training material was exceptional. The trainer was well aware of the subject, provided practical examples in relevance. I would highly recommend him as a trainer for this training.
Tayyeb Mahmood - Ajman Municipality
Course - COBIT 2019 Foundation
The trainer was extremely clear and concise. Very easy to understand and absorb the information.
Paul Clancy - Rowan Dartington
Course - CGEIT – Certified in the Governance of Enterprise IT
The trainer was very motivated and knowledgeable. The trainer was not only capable of information transfer, she also brought it with humor to lighten the dry theoretical training subject.