Details
This five-day intensive course enables the participants to develop the expertise needed to audit an Information Security Management System (ISMS), and manage a team of auditors by applying widely recognized audit principles, procedures and techniques. During this training, the participants will acquire the knowledge and skills needed to proficiently plan and perform internal and external audits in compliance with certification process of the ISO/IEC 27001 standard. Based on practical exercises, the participants will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary to conduct an audit efficiently
Outline
Day 1: Introduction to information Security Management System (ISMS) concepts as required by ISO/IEC 27001
- Normative, regulatory and legal framework related to Information Security
- Fundamental principles of Information Security
- The ISO/IEC 27001 certification process
- Detailed presentation of the clauses of ISO/IEC 27001
Day 2: Planning and initiating an ISO/IEC 27001 audit
- Fundamental audit concepts and principles
- Audit the approach based on evidence and on risk
- Preparation of an ISO/IEC 27001 certification audit
- Documenting of an ISMS audit
Day 3: Conducting an ISO/IEC 27001 audit
- Communication during the audit
- Audit procedures: observation, document review, interview, sampling techniques, technical verification, corroboration and evaluation
- Drafting test plans
- Formulation of audit findings, drafting of nonconformity reports
Day 4: Concluding and ensuring the follow-up of an ISO/IEC 27001 audit
- Audit documentation
- Conducting a closing meeting and conclusion of an ISO/IEC 27001 audit
- Evaluation of corrective action plans
- ISO/IEC 27001 surveillance audit and audit management program
Day 5: Certification Exam
Rcert are the pioneer in total business practice and solution providers both for Process Automation, Product Deployment and System and Business Process Implementation, Stabilization and Standardization.
Rcert helps the community with professional Trainings, Consulting and International Registration, Media Publishing and Recognition Services.
With Rcert at the core, we assist users from setup and training, support, deliverables recognition. Rcert designs customized service solution to meet the people, process and technology needs that allow your organization to achieve its business goals. Most importantly, your needs are always at the center of our focus.Rcert and its associates currently deliver global solutions to clients in Asia Pacific and Europe.