ISO 27001:2022 - Audit: Information Security Management System
Business Organisation & TransformationDescription
Introduction
In one day, learn how to prepare and conduct an audit of an information security management system in accordance with ISO 27001:2022. This training provides a clear method for analysing requirements, collecting evidence, formulating findings, and presenting conclusions that support continual improvement.
Objectives
By the end of the training, participants will be able to:
Understand the principles, challenges, and governance of an information security management system according to ISO 27001:2022
Identify key requirements, information security risks, and interested-party expectations applicable to the organisation
Assess security measures, responsibilities, controls, and evidence associated with an ISMS
Prepare and conduct an audit of the information security management system using a structured, objective, and pragmatic approach
Formulate relevant audit findings and propose improvement actions to strengthen information security
Programme
Interactive roundtable: participants’ expectations, information security challenges, and the context of ISMS audits
Introduction to the information security management system: purpose, principles, governance, and continual improvement
Guided review of ISO 27001:2022: structure, key requirements, organisational context, and interested-party expectations
Practical workshop: identifying assets, threats, vulnerabilities, and risks related to information security
Case study: analysing security measures, responsibilities, applicable controls, and associated evidence
Simulation: preparing an ISMS audit – scope, objectives, criteria, audit plan, and sampling
Role play: conducting audit interviews with objectivity, confidentiality, and active listening
Group exercise: collecting audit evidence, formulating findings, qualifying nonconformities, and assessing the effectiveness of security controls
Collective debrief: presenting clear, objective audit conclusions focused on improving the ISMS
Final summary: building an action plan to strengthen information security and support continual improvement
Target audience
Internal auditors, quality auditors, and management system auditors wishing to work on an ISMS
Information security managers, CISOs, risk managers, governance, internal control, or data protection officers
Managers, business owners, project managers, and key contacts involved in implementing or improving an ISMS
Consultants, advisors, and professionals supporting the preparation, assessment, or audit of an information security management system
Anyone required to prepare, conduct, follow up on, or contribute to an ISO 27001:2022 audit within their organisation
Conditions
Support de cours
-
Des supports de cours seront disponibles après les modules respectifs
-
Die Kursunterlagen werden nach den jeweiligen Modulen zur Verfügung gestellt
-
Course materials will be made available after the respective modules
Certificate
At the end of the training, participants will receive a certificate of attendance issued by the House of Training.
Location
L-1615 Luxembourg
Luxembourg