Skip to content
W3 SolutionzACADEMY

ISO/IEC 27001:2022 Information Security Management Systems Internal Auditor

Wishlist Share

Share this course

Help a colleague take their next step.

About Course

Develop ISMS internal audit skills through 12 modules and 36 text lessons with exercises and model feedback. Evaluate risk assessment, treatment, the Statement of Applicability, all four Annex A control groups and security performance. Includes selected control examples, not specialist implementation training for all 93 controls. Practise audit planning, sampling, interviews, findings, reporting and corrective-action follow-up. Includes a 40-question exam and a marked practical assignment. Total workload: 14 hours excluding breaks.

What Will You Learn?

  • LO01: Explain information security, the ISMS and applicable audit criteria.
  • LO02: Audit ISMS boundaries, responsibilities, objectives and planned change.
  • LO03: Evaluate risk methods, treatment decisions and the Statement of Applicability.
  • LO04: Assess competence, controlled information and operational risk processes.
  • LO05: Audit supplier, cloud, incident, continuity and workforce control trails.
  • LO06: Evaluate physical protection, access and selected technical control evidence.
  • LO07: Test metrics, management review, audit arrangements and corrective action.
  • LO08: Apply objectivity, competence safeguards and risk-based audit programmes.
  • LO09: Prepare audit plans, process questions and justified evidence samples.
  • LO10: Use interviews, authorized observation and reliable digital evidence.
  • LO11: Write defensible findings and verify effective corrective action.
  • LO12: Complete an ISMS audit rehearsal and prepare for supervised workplace practice.

Course Content

ISMS foundations and audit criteria
Explain information security, the ISMS and applicable audit criteria.

  • Course route and the internal auditor role
  • Information security and the management system
  • ISO/IEC 27001, Annex A and related guidance

Context, leadership and planning
Audit ISMS boundaries, responsibilities, objectives and planned change.

Risk assessment, treatment and applicability
Evaluate risk methods, treatment decisions and the Statement of Applicability.

Support and ISMS operation
Assess competence, controlled information and operational risk processes.

Organizational and people controls
Audit supplier, cloud, incident, continuity and workforce control trails.

Physical and technological controls
Evaluate physical protection, access and selected technical control evidence.

Evaluation and improvement
Test metrics, management review, audit arrangements and corrective action.

Audit principles and programme management
Apply objectivity, competence safeguards and risk-based audit programmes.

Audit preparation, planning and sampling
Prepare audit plans, process questions and justified evidence samples.

Conducting the information-security audit
Use interviews, authorized observation and reliable digital evidence.

Findings, reporting and follow-up
Write defensible findings and verify effective corrective action.

Integrated practice and workplace application
Complete an ISMS audit rehearsal and prepare for supervised workplace practice.

Assessment