Understand how to initiate, participate in, lead, and report on audits, aligned with the guidance provided in ISO 19011, including:
- Audit planning requirements, such as undertaking the document review and developing the audit plan and timetable
- Delivering a successful, risk-based audit program using appropriate auditing techniques, including evidence collection, sampling, and verification
- Conducting and leading audit meetings, including opening, closing, and team meetings
- Collating audit findings, understanding and identifying key risks and documenting nonconformances
- Creating, reviewing, and issuing the audit report, including audit findings and outcomes.
- Understand the structure and requirements of an ISMS in alignment with ISO/IEC 27001:2022 and its relationship with ISO/IEC 27002:2022
- Identify and evaluate the application of Information Security Management principles from ISO/IEC 27002:2022, aligned with an organisation’s threat and risk environment, including organisational, people, physical, and technological controls
Apply the ISO/IEC 27001 and 27002 standards to design and assess ISMS controls and processes within an organisational context, and to establish conformity with the standard.


Upon successful completion of the course, you will receive a Certificate of Attainment with 3 Exemplar Global competencies:
Upon successful completion of the course and all required assessment items, you will receive a Statement of Attainment for BSBSS00128 Lead Auditor Skill Set, consisting of: 