INFORMATION SECURITY MANAGEMENT SYSTEM
The purpose of this course is to provide participants with the knowledge and skills required to perform and lead first, second and third-party audits of Information Security Management systems against ISO 27001:2013
PRINCIPLES OF ISMS :
Confidentiality, integrity, and availability are the three core principles (tenets) of information security. Every aspect of an information security program (and every security control implemented by an entity) should be designed to meet at least one of these principles.
Who Should Attend?
· Individuals interested in conducting first, second and third party audits
· Individuals leading their companies to ISO 27001 certification
· Professionals who are responsible for developing and implementing management systems based on ISO 27001: 2013
· IT and Security professionals
· Corporate or division ISMS auditors
· Corporate loss control/risk managers
Course Outline
· Introduction to auditing Information Security management system standards (ISO 27001)
· Overview of ISO 19011 - Guidelines for Auditing Management Systems
· Auditing the Organization and its Context
· Auditing Leadership
· Auditing Planning of the ISMS
· Auditing Management of Support Activities
· Auditing Operations
· Auditing ISMS Performance Evaluation
· Auditing ISMS Improvement
Comments
Post a Comment