plugin Module

Course: ISO/IEC 27001 Information Security Lead Auditor

Audit ISMS programs across SaaS, defense, banking and tech supply chains.

2 Days Accelerated
ISO Aligned
A$1,850

Program Overview

Bridge traditional management-system auditing with cybersecurity governance. Master Annex A controls, risk treatment plans, Statement of Applicability, and ISMS scoping for cloud, SaaS, and regulated environments.

Syllabus

D1

Day 1 Schedule

09:00 - 10:30
lecture

ISMS Foundations & Annex SL Alignment

Position ISO/IEC 27001:2022 inside Annex SL and contrast it with NIST CSF, SOC 2 and the EU NIS2 directive.

Clauses:
Annex SL 4 Context
Annex SL 5 Leadership
Annex SL 6 Planning
10:45 - 12:30
lecture

Annex A (2022) Controls: The Four Themes

Decode the 93 Annex A controls grouped under Organisational, People, Physical and Technological themes.

Clauses:
Annex SL 6.1.3 Information security risk treatment
13:30 - 15:30
lab

Risk Assessment, Risk Treatment & Statement of Applicability

Hands-on workshop: trace a single information asset from risk register → treatment plan → SoA → control evidence.

Clauses:
Annex SL 6.1.2
Annex SL 6.1.3
Annex SL 8.2
Annex SL 8.3
D2

Day 2 Schedule

09:00 - 11:00
lecture

Auditing Cloud, SaaS & Shared-Responsibility ISMS

Evaluate ISMS scope where the cloud provider owns physical and platform controls and the customer owns identity, data, and configuration.

11:15 - 13:00
lecture

Incident Response, Continuity Linkage & Reporting

Audit the bridge between ISMS clause 8.2 incident response, BCMS recovery objectives, and breach-notification obligations.

15:00 - 16:00
exam
Closeout — Enrolment Required

Final Knowledge Assessment

Multiple-choice assessment covering every clause area introduced in Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Pass mark 70%.

This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.

16:00 - 18:00
simulation
Closeout — Enrolment Required

Closeout: Live Audit & NCR Drafting

Live War Room simulation tied to Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Conduct an AI-driven interview, evidence-gather, then draft a defensible NCR.

This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.

Learning Outcomes

  • Plan and lead a Stage 1 + Stage 2 ISO/IEC 27001 certification audit
  • Evaluate a Statement of Applicability against current Annex A (2022) controls
  • Interpret risk assessment, risk treatment and residual-risk acceptance evidence
  • Audit cloud and shared-responsibility ISMS scopes
  • Raise defensible NCRs against the four Annex A control themes

Brochure

Download the full executive briefing for internal approval.

Modular Audit Engine

The precision training instrument for boardroom-grade assurance professionals. ISO compliance accelerated through AI simulation.

Pathways

  • Exemplar Global Aligned
  • CQI/IRCA Compatible
  • Positive Duty (AU) Ready
  • GDPR (EU) Aware

Stay informed

Weekly digest: global auditor news, firm moves and new Auditor Training courses.
English · Español · Deutsch · 中文 · العربية · 日本語

© 2026 Modular Audit Engine. All rights reserved.

Operated by Auditor Training — ISO International Services. Aligned to IAF MLA, CQI/IRCA, Exemplar Global recognition pathways.

Regulatory Disclaimer: This platform provides simulated training environments.PrivacyTerms