|
Information Security Management System (ISMS) is now getting integrated with existing standards and guidelines followed by organizations. This ensures customers and stakeholders are assured that global best practices are followed to secure the information assets of the organization.
About this workshop
The course is aimed at providing an in-depth understanding of how to conduct audits of the ISO/IEC 27001:2005 standard. The course includes exercises, case studies and role plays to help participants gain a better understanding on how to conduct an ISMS audit.
This 5 day course provides participants with the necessary tools, techniques and checklists to conduct a full-fledged and comprehensive ISO/IEC 27001 Lead Audit.
Students will be evaluated through a series of continuous assessments through the course followed by a written exam. On successful completion of the course participants will be awarded the ISO/IEC 27001:2005 Lead Auditor certification.
Benefits
On completion of this course, participants will get a better understanding of
- The business drivers for information security
- ISMS Compliance using the PDCA (Plan-Do-Check-Act) cycle
- Auditing sample documentation
- Creating checklists
- Conducting opening and closing meeting
- Conducting Audit along with role play
- NCR writing exercises
- CA/PA evaluation during audit follow up
Who should attend
This course is meant for professionals responsible for an organization’s key functions such as
- Security Management
- Facilities Management
- Human Resource Department
- Administration Department
- Financial Department
- Emergency Unit
- Operations
- Supply Chain
- Risk and Crisis Management
Anyone aspiring to handle an ISO/IEC 27001 lead audit would benefit from this course. Prior Knowledge about the ISO 27001:2005 series of standards and ISMS auditing is desirable.
Course Outline
- ISMS Scope and Benefits
- ISO 27001: Process Framework Requirements
- ISO 27001: Control Objectives and Controls
- Asset Identification and Classification
- Risk Identification
- Risk Assessment
- Risk Management
- Statement of Applicability
- Information Security Incident Management
- Business Continuity
- Auditing Concepts
- Audit Planning & Execution
- Audit Reporting & Follow up
- Dos and Don’ts of Auditing
|