Thank You
Your registration has been completed successfully. If you have any questions or need further assistance, feel free to contact us at info@omnex.com
Course Duration: 5 Days - 8 Hours/day
Omnex is an Exemplar Global Certified TPECS provider for Exemplar Global IS, AU and TL Competency Units. This course has been developed to satisfy the Exemplar Global IS, AU and TL Examination Profiles and, as such, all attendees who successfully pass the exams during this course will achieve a Certificate of Attainment for the following competency units:
· Exemplar Global-IS
· Exemplar Global-AU
· Exemplar Global-TL
This course has been developed to cover all requirements of the ISO/IEC 27001:2022 standard. The course includes definitions from ISO/IEC 27000:2018 (Information Security Management Systems – Overview and Vocabulary), Guidance from ISO/IEC 27003:2017 (Information Security Management System Implementation and Guidance) and auditing requirements from both ISO 19011:2010 (Guidelines for Auditing Management Systems) and ISO/IEC 27007:2017 (Guidelines for Information Security Management Systems Auditing). Group exercises and case studies will be used to develop the required skills. Other topics covered include the auditing process and methodologies, e. g. planning and conducting an audit, writing nonconformity statements, preparing an audit summary and report, and verifying corrective actions following the requirements of ISO 19011 and ISO 27007. Auditing case studies to develop skills for identifying nonconformities will be used.
Day One
· Fundamentals of Information Security Management Systems (ISMS)
o What is an Information Security Management System (ISMS)?
o The purpose of ISO/IEC 27001 ISMS described.
· Process Approach to Information Security
· Risk-based Thinking
o ISMS Risks
o ISMS Risk Assessment
o ISMS Risk Treatment
o Group Exercise 1: Risk Identification Discussion
· ISO/IEC 27001 Clause 4 – Context of the Organization
· ISO/IEC 27001 Clause 5 – Leadership
o Group Exercise 2: Audit Scenarios
· ISO/IEC 27001 Clause 6 – Planning
Day Two
· ISO/IEC 27001 Clause 7 – Support
· ISO/IEC 27001 Clause 8 – Operation
· A look at and understanding of Annex A Controls
o Group Exercise 3: Audit Scenarios
· ISO/IEC 27001 Clause 9 – Performance Evaluation
· ISO/IEC 27001 Clause 10 – Improvement
o Group Exercise 4: Audit Scenarios
· Understanding ISMS Final Exam
· Process Approach to Auditing, Turtle Diagrams and Audit Trails
o Breakout Exercise 1: Completing a Turtle Diagram
· Audit Guidance, Definitions and Principles
· The Audit Program
· Audit Planning and Preparation including ISO 27007 Guidelines for Information Security Management Systems Auditing
o Breakout Exercise 2: Documentation Review
o Breakout Exercise 3: Creating an Audit Plan
Day Three
· Conducting the Audit
o Breakout Exercise 4: Conducting an Audit Interview
· Writing Nonconformity Statements
o Breakout Exercise 5: Writing Nonconformity Statements
· Closing Meeting
· Completing the Audit Report
· Corrective Action and Close-Out
· Management Systems Auditing Final Exam
Day Four & Five
· Leading Audit Teams
· Management System Certification Scheme and Auditor Qualifications
· Leading Management Systems Audit Teams Mock Audit Case Study
· Review of Audit Process and Audit Management Strategies
· Leading Management Systems Audit Teams Final Exam
· Practical Application of Audit Principles and Instructor Interviews
This training is primarily designed for lead auditor candidates, but can also be valuable for Information Security Assurance Managers, ISO/IEC 27001:2022 Implementation and/or Transition Team Members, Management Representatives, and all others who would like to develop competency in ISO/IEC 27001:2022 and the auditing process for third party auditing.
Each participant will receive a seminar manual and a breakout workbook that includes auditing case studies.
Note: Omnex does not provide copies of standard(s) during training courses, but clients are encouraged to have their own copy.
Note: Omnex does not provide copies of standard(s) during training courses, but clients are encouraged to have their own copy.
An understanding of the ISO/IEC 27001:2022 requirements and/or work experience in applying ISO/IEC 27001:2022 is recommended.
ISO/IEC 27001 Lead Auditor Training for ISMS Program is available in multiple locations globally, including the USA, Canada, Mexico, India, Europe, Thailand, Singapore, Middle East and China.
We are proud to announce that Omnex Inc. is now a member of Andersen Consulting.