ISO/IEC 27001:2022 Information Security Management System Internal Auditor Training
This course helps participants understand the requirements of ISO/IEC 27001:2022 and develop the skills to plan, conduct, report on and follow up internal audits of an information security management system (ISMS), using the guidance in ISO 19011:2026. It focuses on risk assessment, the Statement of Applicability (SoA) and the effectiveness of controls in preserving the confidentiality, integrity and availability of information.
Course objectives
- Understand the structure and requirements of ISO/IEC 27001:2022 and the links between risk assessment, risk treatment, the SoA and security controls.
- Understand auditing principles, audit programme management and the steps involved in auditing management systems, following the guidance in ISO 19011:2026.
- Practise audit planning, checklist development, evidence collection, documenting findings and preparing ISMS internal audit reports.
- Develop interviewing, evidence analysis and corrective action follow-up skills to conduct objective audits, maintain confidentiality and contribute to ISMS improvement.
Who should attend
- Managers
- Information security and ISMS personnel
- IT, operations and software development personnel
- Risk management and compliance personnel, and information owners
- Internal audit team members
- Personnel seeking to develop internal auditing competence
Key considerations when auditing an ISMS
Course content
Select a section to expand or collapse its content.
01Overview of ISMS and ISO/IEC 27001:2022
- Information security concepts; confidentiality, integrity, availability and the value of an ISMS.
- Structure of Clauses 4 to 10, Annex A and the role of ISO/IEC 27002:2022 as guidance.
- Key aspects of the 2022 edition and the climate change considerations introduced by ISO/IEC 27001:2022/Amd 1:2024.
- The role of internal audits in maintaining ISMS conformity and effectiveness, and supporting improvement.
02ISMS requirements, risks and controls
- ISMS context, scope and interested parties; leadership, policy, objectives and planning changes.
- Resources, competence, awareness, communication and control of documented information.
- Risk identification, analysis and evaluation; acceptance criteria and the responsibilities of risk owners.
- Risk treatment plans and the SoA; comparison with Annex A to ensure that no necessary controls are overlooked.
- Organisational, people, physical and technological controls; reviewing evidence of appropriate implementation.
- Monitoring, measurement and performance evaluation; management review, corrective actions and ISMS improvement.
03Auditing principles and process in accordance with ISO 19011:2026
- Auditing principles, objectivity and the confidentiality of information during audits.
- Managing an audit programme and the steps involved in conducting an audit.
- Defining audit objectives, scope, criteria and methods using a risk-based approach.
- Roles, responsibilities and competence requirements for audit team leaders and members.
04Planning and preparing for internal audits
- Reviewing the ISMS scope, risk records, treatment plans, the SoA and previous audit results.
- Developing the audit plan, assigning responsibilities and agreeing access to information and systems.
- Developing checklists based on the standard’s requirements, processes, risks and applicable controls.
- Preparing the sampling approach, interview questions and evidence collection methods to maintain confidentiality and minimise operational disruption.
05Conducting audits and documenting findings
- Conducting opening meetings, interviews, observations and reviews of documents and records.
- Collecting and verifying evidence relating to access rights, backups, change management or incident handling within the audit scope.
- Evaluating evidence against audit criteria, the SoA and risk treatment plans, and assessing ISMS conformity and effectiveness.
- Clearly documenting findings and nonconformities based on requirements and evidence, and addressing issues arising during the audit.
06Reporting, audit follow-up and auditor skills
- Consolidating audit results, presenting conclusions and conducting closing meetings.
- Preparing clear, consistent reports with traceable evidence, and protecting sensitive information in audit records.
- Following up on the implementation of corrective actions and verifying their effectiveness.
- Developing communication, questioning, listening, analytical and conflict management skills.
Training methods
The course combines theory with practical activities to help participants apply their knowledge to internal auditing.
Trainers
Our trainers are professionals with experience in information security management and management system auditing in businesses. Training focuses on ISMS auditing methods, evidence analysis and practical scenarios.
Contact GIC Vietnam for advice on course schedules, training formats and a programme tailored to the needs of your organisation.
12F, 14 Lang Ha Building, Ba Dinh, Hanoi
Tel: 024.6275 2268 · Email: tuandm@gicvn.vn
Ho Chi Minh City Office: Room 502, 160 Nam Ky Khoi Nghia · Tel: 028.3930 7936