Program Overview
Bridge traditional management-system auditing with cybersecurity governance. Master Annex A controls, risk treatment plans, Statement of Applicability, and ISMS scoping for cloud, SaaS, and regulated environments.
Syllabus
Day 1 Schedule
ISMS Foundations & Annex SL Alignment
Position ISO/IEC 27001:2022 inside Annex SL and contrast it with NIST CSF, SOC 2 and the EU NIS2 directive.
Annex A (2022) Controls: The Four Themes
Decode the 93 Annex A controls grouped under Organisational, People, Physical and Technological themes.
Risk Assessment, Risk Treatment & Statement of Applicability
Hands-on workshop: trace a single information asset from risk register → treatment plan → SoA → control evidence.
Day 2 Schedule
Auditing Cloud, SaaS & Shared-Responsibility ISMS
Evaluate ISMS scope where the cloud provider owns physical and platform controls and the customer owns identity, data, and configuration.
Incident Response, Continuity Linkage & Reporting
Audit the bridge between ISMS clause 8.2 incident response, BCMS recovery objectives, and breach-notification obligations.
Final Knowledge Assessment
Multiple-choice assessment covering every clause area introduced in Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Pass mark 70%.
This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.
Closeout: Live Audit & NCR Drafting
Live War Room simulation tied to Plug-In: ISO/IEC 27001 Information Security Lead Auditor. Conduct an AI-driven interview, evidence-gather, then draft a defensible NCR.
This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.
Learning Outcomes
- Plan and lead a Stage 1 + Stage 2 ISO/IEC 27001 certification audit
- Evaluate a Statement of Applicability against current Annex A (2022) controls
- Interpret risk assessment, risk treatment and residual-risk acceptance evidence
- Audit cloud and shared-responsibility ISMS scopes
- Raise defensible NCRs against the four Annex A control themes
