Information security management system internal auditor (ISO 27001, ISO 19011)
To enhance understanding, all course slides are voiced. Real-life cases will help participants better apply theory in practice. Structured information is divided into modules, making the learning process even more efficient.
Internal audits are crucial for ensuring company’s information security. Proper qualifications for an internal auditor are essential for effective identifying and assessing risks, as well as ensuring compliance with normative requirements and standards.
This course allows to get necessary qualifications, providing participants with practical skills and knowledge to conduct internal audits in accordance with ISO 27001 and ISO 19011.
This course is an essential step for those aspiring to become highly qualified auditors and make a significant contribution to enhancing their company’s information security management system.
Duration
42 hours
Language
English/Ukrainian
Format
100% online
Course objective
Internal auditors play a critical role in the information security management system. Their work contributes to identifying and minimizing risks, ensuring compliance with standards, and enhancing the overall security of the organization.
Target audience
- external auditors of management system certification bodies;
- lead auditors who are involved in certification, surveillance, and recertification audits;
- candidates for external auditors who are undergoing training or qualification to work within certification bodies;
- auditors involved in integrated and combined management system audits.
The course is aimed at professionals who have basic knowledge of management system standards and perform independent, impartial assessments of organizations.
Document on completion
ISMS internal auditor certificate, listed in the SIC international register
Thematic plan
Module 2 — Internal audit (ISO 19011)
Module 3 — ISO 19011:2026 – updates for internal auditors. SIC.MODULE.ISO19011:2026
The program is designed for 42 hours, including time for studying theoretical material and taking tests.
Objectives
Module 1 — Module "Information security management systems (ISO/IEC 27001)"
| # | Topic | Hours |
| 1 | Introduction | 1,5 |
| 2 | General provisions of the standard | 2,5 |
| 3 | Context of the organization | 2 |
| 4 | Leadership | 2 |
| 5 | Planning | 2,5 |
| 6 | Support (resources) | 2,5 |
| 7 | Operation | 1 |
| 8 | Performance evaluation | 3 |
| 9 | Improvement | 1 |
| 10 | Information security controls | 5 |
| Testing | 1 | |
| Hours total | 24 |
Module 2 — Internal audit (ISO 19011)
| # | Topic | Hours |
| 1 | Introduction | 1 |
| 2 | General provisions of the standard | 1 |
| 3 | Audit program management (AP) | 3 |
| 4 | Carrying out an audit | 3 |
| 5 | Competence of auditors | 3 |
| Testing | 1 | |
| Hours total | 12 |
Module 3 — ISO 19011:2026 – updates for internal auditors. SIC.MODULE.ISO19011:2026
| # | Topic | Hours |
| 1 | Key changes in ISO 19011:2026 for internal audit practice | 2 |
| 2 | Remote audit methods: selection of audit methods, evaluation of audit locations, and on-site auditing | 1 |
| 3 | Audit programme: a risk-based approach | 1 |
| 4 | Audit planning and organization using remote and hybrid audit methods | 2 |
| 5 | Methods for obtaining audit evidence | 1,5 |
| 6 | Evaluation of digital evidence and documented information | 1 |
| 7 | Competence of the internal auditor | 1 |
| 8 | Updating the internal auditor’s working tools | 1 |
| 9 | Case studies | 1 |
| 10 | Testing | 0,5 |
| Hours total | 12 |