Course Description
This course is designed to equip participants with the skills and knowledge needed to conduct effective internal audits of an Information Security Management System (ISMS) based on ISO/IEC 27001:2022. It integrates the auditing principles of ISO 19011 with the specific requirements of ISO 27001, enabling participants to assess conformity, effectiveness, and continual improvement of information security controls. Real-world audit exercises and reporting templates help bridge the gap between theory and practice.
What You’ll Learn
By the end of the course, you will be able to:
-
Understand ISO/IEC 27001:2022 clause structure and the purpose of an ISMS.
-
Explain the internal audit process in accordance with ISO 19011.
-
Plan internal audits based on risk, scope, and objectives.
-
Develop audit checklists and gather evidence through interviews, records, and observation.
-
Evaluate implementation of information security controls (Annex A).
-
Identify nonconformities, opportunities for improvement, and best practices.
-
Write clear, objective audit reports aligned with organizational requirements.
-
Support management review, corrective action, and continual improvement.
-
Assess audit effectiveness and follow up on previous audit results.
-
Prepare for certification and surveillance audits through internal audit readiness.
Who Should Attend
-
ISMS Coordinators and IT Managers
-
Internal Auditors and Risk Officers
-
Compliance Managers and Data Protection Officers
-
Cybersecurity and Governance Professionals
-
Consultants supporting ISO 27001 implementation or audits
-
Anyone involved in internal audit or information security roles
Recommended
-
Familiarity with ISO/IEC 27001:2022 or general information security principles is helpful
-
No prior auditing experience is required
-
Some technical understanding of IT and data management is beneficial