ATAUDITOR TRAINING · ISO INTERNATIONAL SERVICES
plugin Programme · 2-Day Intensive
Course: ISO/IEC 27001 Information Security Lead Auditor
Audit ISMS programs across SaaS, defense, banking and tech supply chains.
01Programme Overview
Bridge traditional management-system auditing with cybersecurity governance. Master Annex A controls, risk treatment plans, Statement of Applicability, and ISMS scoping for cloud, SaaS, and regulated environments.
Delivery
Hybrid · Live + Simulation
02Learning Outcomes
On completion, candidates will be able to:
- Plan and lead a Stage 1 + Stage 2 ISO/IEC 27001 certification audit
- Evaluate a Statement of Applicability against current Annex A (2022) controls
- Interpret risk assessment, risk treatment and residual-risk acceptance evidence
- Audit cloud and shared-responsibility ISMS scopes
- Raise defensible NCRs against the four Annex A control themes
03Course Outline
A blended pathway combining lecture (4), lab (1), and simulation (1) modules across 2 days. Assessed components are marked.
Day 1
09:00 — 10:30 · lecture
ISMS Foundations & Annex SL Alignment
Position ISO/IEC 27001:2022 inside Annex SL and contrast it with NIST CSF, SOC 2 and the EU NIS2 directive.
10:45 — 12:30 · lecture
Annex A (2022) Controls: The Four Themes
Decode the 93 Annex A controls grouped under Organisational, People, Physical and Technological themes.
13:30 — 15:30 · lab
Risk Assessment, Risk Treatment & Statement of Applicability
Hands-on workshop: trace a single information asset from risk register → treatment plan → SoA → control evidence.
Day 2
09:00 — 11:00 · lecture
Auditing Cloud, SaaS & Shared-Responsibility ISMS
Evaluate ISMS scope where the cloud provider owns physical and platform controls and the customer owns identity, data, and configuration.
11:15 — 13:00 · lecture
Incident Response, Continuity Linkage & Reporting
Audit the bridge between ISMS clause 8.2 incident response, BCMS recovery objectives, and breach-notification obligations.
15:00 — 16:00 · exam
Final Knowledge Assessment
Multiple-choice assessment covering every clause area introduced in Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Pass mark 70%.
16:00 — 18:00 · simulation
Closeout: Live Audit & NCR Drafting
Live War Room simulation tied to Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Conduct an AI-driven interview, evidence-gather, then draft a defensible NCR.
04Assessment Outline
Candidates are assessed against IAF / ISO/IEC 17021-1 personnel competence criteria. Assessment is layered — written examination, practical NCR simulation, and witnessed audit closeout — modelled on certification body witness protocols.
Written Examination
13 Questions
Closed-book, clause-anchored multiple choice. 70% pass mark. Single re-sit included.
Practical Closeout Simulation
1 Scenario
Live NCR drafting, opening/closing meeting facilitation, evidence triangulation, rubric-scored by lead assessor.
Continuous Calibration
In-Module Labs
1 lab modules with formative feedback; instructor calibration on rubric drift.
Credential Issue
Digital Credential + Transcript
Verifiable digital credential issued within 5 working days of successful closeout. PDF transcript supplied for CPD logging with CQI/IRCA, Exemplar Global, JRCA.
Assessed Modules
- Day 2 · Final Knowledge Assessment (exam)
- Day 2 · Closeout: Live Audit & NCR Drafting (simulation)
05A Globally Recognised Credential
Audit anywhere. Certify everywhere.
The Auditor Training credential is engineered against the IAF Multilateral Recognition Arrangement (MLA), aligning competence with conformity assessment bodies in 100+ economies — so the assessor you train in Sydney is the assessor that's accepted in Frankfurt, Singapore, São Paulo or Toronto.
IAF MLA Aligned
International Accreditation Forum
Course architecture mapped to ISO/IEC 17021-1 §7 personnel competence criteria — the framework underpinning IAF signatories worldwide.
CQI / IRCA Pathway
Chartered Quality Institute
Module taxonomy and assessor rubric mirror CQI/IRCA certified course requirements, providing a direct pathway for IRCA QMS / EMS / OH&S auditor registration.
Exemplar Global Recognised
Americas & Asia-Pacific
Transcripts are formatted for Exemplar Global CPD logging — accepted across Exemplar Global TPECS units (AU, QM, EM, OH).
JRCA Compatible
Japan & East Asia
Clause-anchored evidence taxonomy is compatible with JRCA registration pathways for ISO 9001 / 14001 / 45001 auditors.
Total Investment
A$1,850
Per seat. Includes courseware, simulation access, examination, single re-sit, and digital credential. Group rates available for cohorts of 6+.
To accept this quote
Reply with Quote Ref above to
info@auditortraining.com
or visit auditortraining.com/programs
Authorised — Steven Asnicar, Master Assessor
Accepted — Client Signature & Date