Course Outline
Day 1: Introduction to the Information Security Management System (ISMS) and ISO/IEC 27001 for government
Day 2: Audit principles, preparation, and initiation of an audit for government entities
Day 3: On-site audit activities for government agencies
Day 4: Closing the audit for government organizations
Day 5: Certification Exam
Examination:
The “PECB Certified ISO/IEC 27001 Lead Auditor” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). The exam covers the following competency domains for government professionals:
Domain 1: Fundamental principles and concepts of Information Security Management System (ISMS)
Domain 2: Information Security Management System (ISMS) implementation
Domain 3: Fundamental audit concepts and principles for government audits
Domain 4: Preparation of an ISO/IEC 27001 audit for government entities
Domain 5: Conducting an ISO/IEC 27001 audit in a government setting
Domain 6: Closing an ISO/IEC 27001 audit for government organizations
Domain 7: Managing an ISO/IEC 27001 audit program for government entities
Certification:
After successfully completing the exam, you can apply for the credentials shown in the table below. You will receive a certificate once you comply with all the requirements related to the selected credential. For more information about ISO/IEC 27001 certifications and the PECB certification process for government professionals, please refer to the Certification Rules and Policies.
The requirements for PECB Auditor Certifications are:
Credential
Exam
Professional experience
MS audit/assessment experience
Other requirements
PECB Certified ISO/IEC 27001 Provisional Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
None
None
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Two years: One year of work experience in Information Security Management for government
Audit activities: a total of 200 hours
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Lead Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Five years: Two years of work experience in Information Security Management for government
Audit activities: a total of 300 hours
Signing the PECB Code of Ethics
PECB Certified ISO/IEC 27001 Senior Lead Auditor
PECB Certified ISO/IEC 27001 Lead Auditor exam or equivalent
Ten years: Seven years of work experience in Information Security Management for government
Audit activities: a total of 1,000 hours
Signing the PECB Code of Ethics
Note:PECB Certified Individuals who possess both the Lead Implementer and Lead Auditor Credentials are qualified for the respective PECB Master Credential, given they have taken 4 additional Foundation Exams which are related to this scheme. For more detailed information about the Foundation Exams and the overall Master Requirements, please go to the following link: https://pecb.com/en/master-credentials.
To be considered valid, these audits should follow best audit practices and include the following activities:
- Audit planning
- Audit interview
- Managing an audit program
- Drafting audit reports
- Drafting non-conformity reports
- Drafting audit working documents
- Documentation review
- On-site Audit
- Follow-up on non-conformities
- Leading an audit team
Requirements
A thorough understanding of ISO/IEC 27001 is essential, along with a comprehensive grasp of audit principles for government.
Testimonials (5)
The fact that there were practical examples with the content
Smita Hanuman - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
The knowledge and understanding of the trainer on the training material was exceptional. The trainer was well aware of the subject, provided practical examples in relevance. I would highly recommend him as a trainer for this training.
Tayyeb Mahmood - Ajman Municipality
Course - COBIT 2019 Foundation
The trainer was extremely clear and concise. Very easy to understand and absorb the information.
Paul Clancy - Rowan Dartington
Course - CGEIT – Certified in the Governance of Enterprise IT
The trainer was very motivated and knowledgeable. The trainer was not only capable of information transfer, she also brought it with humor to lighten the dry theoretical training subject.