Skip to content
W3 SolutionzACADEMY

ISO 28000:2022 Security Management Systems Internal Auditor

Wishlist Share

Share this course

Help a colleague take their next step.

About Course

Develop security-management internal audit skills through 12 modules and 36 text lessons with exercises and model feedback. Cover ISO 28000:2022 clauses 4–10 and Amendment 1:2024. Follow context, leadership, risk and objectives into access permissions, shipment custody, supplier interfaces, information dependencies, incident arrangements, performance and improvement. Practise audit planning, sampling, evidence, findings and follow-up. Includes a 40-question exam and marked practical assignment. Total workload: 14 hours excluding breaks.

What Will You Learn?

  • LO01: Explain the security management system, its scope and the current edition basis.
  • LO02: Evaluate context, interested parties, boundaries, policy and leadership accountability.
  • LO03: Audit security risk decisions, objectives, treatment and planned changes.
  • LO04: Assess resources, competence, communication and controlled security information.
  • LO05: Trace physical access, personnel and shipment controls into operating evidence.
  • LO06: Assess outsourced interfaces, information dependencies and incident preparedness.
  • LO07: Evaluate security measures, management review and effective corrective action.
  • LO08: Apply ethical conduct, competence, independence and risk-based programme planning.
  • LO09: Develop objectives, scope, criteria, process trails and justified samples.
  • LO10: Collect reliable evidence through interviews, observation and record reconciliation.
  • LO11: Write traceable findings, communicate limits and verify corrective-action effectiveness.
  • LO12: Apply audit skills to an integrated security case and practical assessment.

Course Content

Security management and audit foundations
Explain the security management system, its scope and the current edition basis.

  • What a security management system does
  • Security assurance across organizational boundaries
  • Edition basis and climate amendment

Context and leadership
Evaluate context, interested parties, boundaries, policy and leadership accountability.

Planning and security risk
Audit security risk decisions, objectives, treatment and planned changes.

People and documented information
Assess resources, competence, communication and controlled security information.

Operational security controls
Trace physical access, personnel and shipment controls into operating evidence.

Partners and incident arrangements
Assess outsourced interfaces, information dependencies and incident preparedness.

Performance and improvement
Evaluate security measures, management review and effective corrective action.

Auditor principles and programme
Apply ethical conduct, competence, independence and risk-based programme planning.

Preparing the internal audit
Develop objectives, scope, criteria, process trails and justified samples.

Conducting the audit
Collect reliable evidence through interviews, observation and record reconciliation.

Findings and follow up
Write traceable findings, communicate limits and verify corrective-action effectiveness.

Integrated security audit practice
Apply audit skills to an integrated security case and practical assessment.

Assignment

Assessment

Earn a certificate

Add this certificate to your resume to demonstrate your skills & increase your chances of getting noticed.

selected template

Student Ratings & Reviews

No Review Yet
No Review Yet