About the course
The flagship of our ISO 27001 Implementation Learning Path, this Advanced-level course is focused on developing the in-depth knowledge and skills required to implement and deliver an ISMS in any organisation.
Who should attend this course?
Individuals who want a globally-recognised ISO 27001 lead auditor qualification to further their careers, and at managers who are responsible for the implementation and maintenance of an ISO 27001-compliant ISMS.
- IT/ Information Security Consultant
- IT/ Information Security Manager
- IT/ Information Security Officer
- IT/ Information Security Project Manager
- Cyber security consultant
- Head of IT
- CISO (Chief Information Security Officer)
- GDPR Consultant
- Information security analyst
- ISMS Manager
- Network manager
- Compliance Auditor
- Internal Auditor
Why choose IT Governance for your training needs?
- We’re internationally recognised as the authority on ISO 27001 – our team led the world’s first ISO 27001 certification project, and since then we have trained more than 8,000 professionals on information security management system (ISMS) implementations and audits.
- Trained by industry experts – our trainers are working consultants with years of practical, hands-on experience.
- Pass first time or train again for free – we have trained more than 17,000 people and we’re confident you’ll pass with us first time. If you don’t, we’ll train you again for free.*
- Choose the method that suits you – we offer classroom, Live Online, distance learning, e-learning and in-house training options.
- Access your training anywhere – all our course materials are provided as a digital copy, allowing you to access them anywhere and at any time. Documents will be made available 20 days before your course.
- Business solutions to suit you – whether you’re a multinational wanting us to manage all your training needs or a small business wishing to boost your workforce skills, we offer a range of training solutions.
What does the Certified ISO 27001 Lead Implementer and Lead Auditor Combination training course cover?
The course will cover:
- The key concepts, principles and main requirements of ISO/IEC 27001:2013.
- The terms and definitions used in the Standard, including risk and options for risk assessments.
- How to interpret the requirements of ISO/IEC 27001:2013 to determine the scope of your ISMS.
- How to secure senior management commitment by building a compelling business case.
- How to structure and manage your ISO 27001 project.
- How to review and map your existing controls to Annex A of ISO 27001.
- The importance of the Statement of Applicability (SoA), and justifications for inclusions and exclusions.
- How to carry out an information security risk assessment – the core competence of information security management.
- How to develop a management framework, write policies and produce other critical documentation.
- The key elements of management review.
- The importance of staff, an effective communication strategy and general awareness training.
- How to prepare for your ISO 27001 certification audit and ensure you that you pass first time.
- How to manage and drive continual improvement under ISO 27001.
- An overview of the audit process used by certification bodies.
- Best-practice audit methodology based on ISO 19011.
- How to establish, maintain and manage an audit programme.
- How to plan, conduct, report, summarise and follow-up on an audit.
- Effective interviewing techniques and observation skills.
- How to use audits to identify nonconformities and ensure appropriate corrective action is taken.
- How the audit process is used in first, second and third-party audits.
Course agenda (day 1-3):
- Project mandate
- Project initiation
- ISMS initiation
- Management framework
- Baseline security criteria
- Risk management
- Annex A controls
- Measure, monitor, review and improve
What’s included in this course?
- A professional training venue with lunch and refreshments;
- Full course materials (digital copy provided as a PDF file);
- The ISO 27001 Certified ISMS Lead Implementer exam;
- The ISO 27001 Certified ISMS Lead Auditor exam; and
- A certificate of attendance.
What equipment should I bring?
The exam is an online exam. You will need to bring a ‘pop-up enabled’ laptop/tablet to the venue. Full details on how to access the exam will be provided by email 1–2 days before sitting the exam.
This course is equivalent to 56 CPD/CPE points.
Certified ISO 27001 Lead Implementer and Lead Auditor Combination training course exams
Attendees sit the online ISO 27001 CIS LI examination at the end of day 3 – a 90-minute, multiple-choice, ISO 17024-certificated exam set by IBITGQ. They also sit the online ISO 27001 Certified ISMS Lead Auditor (CIS LA) examination– a 90-minute, multiple-choice, ISO 17024-certificated exam set by IBITGQ at the end of the course. There is no extra charge for taking these exams.
What qualifications will I receive?
ISO 27001 Certified ISMS Lead Implementer (CIS LI) and ISO 27001 Certified ISMS Lead Auditor (CIS LA)
How will I receive my exam results and certificates?
- Provisional exam results will be available immediately on completion of the exam. Confirmed exam results will be issued within ten working days from the date of the exam.
- Certificates for those who have achieved a passing grade will be issued within ten working days from the date of the exam.
- Results notifications and certificates are sent directly to candidates by the relevant exam board in electronic format; please note that hard copy exam certificates are not issued.
Can exams be retaken?
Yes, if you are unsuccessful on the first attempt you can retake the exam for an additional fee. You can email us to schedule the retest for the exam.
|Start date||Location / delivery|
|04 Nov 2020||Manchester|
|18 Nov 2020||London|
|09 Dec 2020||London|