ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection - Information Security Management Systems (ISMS) Internal Auditor Training Course

The purpose of this course is to provide participants with the knowledge and skills required to perform an internal audit of an Information Security Management System (ISMS) based on ISO/IEC 27001 (or equivalent) and report on the effective implementation and maintenance of the management system in accordance with ISO 19011.

2 Days In-person / Virtual Class Next: 22 Oct 2026 English Identifier: 111473308
ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection - Information Security Management Systems (ISMS) Internal Auditor Training Course

Course Overview

What you'll learn

Upon completion of this course, participants will be able to:

  • Explain the process based information security management system model for ISO/IEC 27001, with reference to the Plan Do Check Act (PDCA) cycle, and the role of internal audit in the maintenance and improvement of information security management systems.
  • Explain the role and responsibilities of an Auditor to plan, conduct, report and follow up an information security management system internal audit, in accordance with ISO 19011.
  • Plan, conduct, report and follow up an internal audit of part of an information security management system based on ISO/IEC 27001 and in accordance with ISO 19011.

Participants will need to demonstrate acceptable performance in each of these areas in order to complete the course successfully.

Upon successful completion of the course requirements, a Certificate of Successful Completion will be issued.

Who This Course Is For

This course is aimed at anyone interested to understand and conduct internal audits against ISO/IEC 27001:2022.

NOTE: Learners are required to obtain a copy of the ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection – Information Security Management Systems. Learners should familiarise themselves with the standard prior to attending the training course.

If attending a Virtual Course:
To ensure your access to the virtual course and to gain the most out of this training we request all learners have:

  • Reliable internet access (High speed)
  • Computer with microphone and camera capabilities

 Assessment and group activities for this course requires your camera to be turned on. Background effects such as blurring can be used for preserving privacy.

About this course

The purpose of this course is to provide participants with the knowledge and skills required to perform an internal audit of an Information Security Management System (ISMS) based on ISO/IEC 27001 (or equivalent) and report on the effective implementation and maintenance of the management system in accordance with ISO 19011.

Course Content:

  • Introduction to Information Security Management Systems (ISMS) and ISO/IEC 27000 series of standards.
  • Process-based ISMS.
  • Audit definition and principles.
  • Planning and preparation for the internal audit.
  • Conducting the audit.
  • Audit reporting and follow-up.

Prior Knowledge:

Before starting the course, participants are expected to have the following knowledge:

  • An understanding of the Plan-Do-Check-Act (PDCA) cycle.
  • A basic knowledge of the concepts of information security management.
  • An understanding of the requirements of ISO/IEC 27001 (with ISO/IEC 27002) and the commonly used information security management terms and definitions which may be gained by completing an ISO/IEC 27001 Introduction training course or equivalent.

Not sure if this is right?

Let us help you find the perfect match.

Course Finder
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.