Anyone with the need to audit an organization’s processes in relation to ISO/IEC 27001:2022, and has met the prerequisites for attending (see below).
You are expected to have the following prior knowledge:
a) Management systems
Understand the Plan, Do, Check, Act (PDCA) cycle
b) Information security management
Knowledge of the information security management principles:
- Awareness of the need for information security
- Assignment of responsibility for information security
- Incorporating management commitment and the interests of stakeholders
- Enhancing societal values
- Risk assessments determining appropriate controls to reach acceptable levels of risk
- Security incorporated as an essential element of information networks and systems
- Active prevention and detection of information security incidents
- Ensuring a comprehensive approach to information security management
- Continual reassessment of information security and making modifications as appropriate
c) ISO 27001
Knowledge of the requirements of ISO/IEC 27001:2022 (with ISO/IEC 27002) and the commonly used information security management terms and definitions, as given in ISO/IEC 27000. **The course examination can cover the requirements of ISO 27001, and these are not covered during this course.
d) Management system audit
Knowledge of management systems audit through satisfactory completion of a CQI and IRCA Certified (or the acceptable alternative) Lead Auditor Training course in another discipline. **Delegates will be asked to provide a copy of their Lead Auditor training course certificate as evidence of their qualification, prior to attending this course
If you have not successfully completed a CQI and IRCA Certified (or acceptable alternative) Lead Auditor Training Course in another discipline, you’re unlikely to complete this 24 hour course successfully and will find the 40 hours ISO/IEC 27001:2022 Lead Auditor (ISMS) Training Course more appropriate.