What you'll learn:
- Management system auditing principles and basics
- Requirements of ISO/IEC 27001 from the auditor's perspective
- Assessing the information security controls from ISO/IEC 27001
- Formulating findings and conculsions for the ISMS audit
This course will help you master Information Security Management System (ISMS) auditing and the requirements of ISO/IEC 27001:2022 — the world's leading international standard for information security — equipping you with the skills to work as an internal auditor, lead auditor or consultant in one of the fastest-growing fields in compliance.
ISO/IEC 27001 certification is now a critical requirement for organizations across industries including finance, IT, engineering, transportation, professional services and manufacturing. Professionals who can assess compliance and guide organizations in strengthening their information security are in high demand — and auditing skills are the most direct path into that demand.
What you will learn?
By enrolling in this course, you will gain a solid understanding of auditing fundamentals, the requirements of ISO/IEC 27001:2022, all 93 information security controls in Annex A, and how to evaluate compliance during an ISMS audit.
ISMS foundations. The first part of the course introduces information security management systems: what an ISMS is, the standards of the ISO/IEC 27000 series, and the purpose and structure of ISO/IEC 27001:2022.
Auditing fundamentals. You will learn the core principles auditors must adhere to, methods for collecting audit evidence, and the key audit documents — audit programme, audit plan and audit report. This section also covers remote auditing, analysing audit findings and conclusions, the difference between auditors and lead auditors, and internal versus external (certification) audits — aligned with the guidance of ISO 19011.
Auditing the ISO/IEC 27001 requirements. Key topics include auditing the information security risk assessment, the ISMS scope, the information security policy and objectives, management reviews, internal audits, the Statement of Applicability (SoA), the risk treatment plan, and the management of nonconformities. Each topic is analysed from an auditor's perspective, emphasizing what to evaluate during compliance assessments.
All 93 Annex A controls, across the four themes of ISO/IEC 27001:2022:
Organizational controls — policies, supplier relationships, incident management, privacy and protection of PII, access control, threat intelligence, information classification, and the inventory of information and assets
People controls — screening, disciplinary process, information security awareness and training, confidentiality and non-disclosure agreements
Physical controls — securing infrastructure, protection against natural and environmental threats, cabling security, assets off-premises, and storage media life cycle management
Technological controls — cryptography, malware protection, network security, secure development, capacity management, backups, information deletion, data masking, vulnerability management and system redundancy
The course also addresses modern audit challenges such as remote working and BYOD (bring your own device), with actionable guidance on how auditors evaluate compliance in these scenarios.
Closing the audit. The final section covers formulating audit findings and conclusions, conducting the closing meeting, and planning post-audit activities.
Throughout, the course draws on related standards — ISO/IEC 27002 (control implementation guidance), ISO/IEC 27005 (information security risk management) and ISO/IEC 27035 (incident management) — combining theory with practical examples of where auditors should focus to gather meaningful evidence.
Who this course is for?
Professionals preparing for ISMS internal auditor or lead auditor roles
Information security, IT and compliance professionals preparing their organization for ISO/IEC 27001 certification
Quality or management system auditors (ISO 9001, ISO 14001) extending their scope to information security
Anyone building a career in information security governance, risk and compliance (GRC)
Whether you are advancing your career as an ISMS auditor or preparing for an upcoming certification audit, this course offers a structured, comprehensive approach to mastering ISO/IEC 27001:2022 auditing.