Learning objectives
- Define the scope, criteria and readiness plan
- Build relevant, traceable and consistent evidence
- Prepare teams for interviews and control testing
- Manage findings, corrective actions and indicators
Who should attend
Security, compliance, internal control, quality and IT managers, and control owners.
Prerequisites
General knowledge of security policies, processes and controls.
Course outline
- Audit types, independence, criteria and sampling
- Scope, stakeholders, schedule and responsibilities
- Control mapping and evidence matrix
- Evidence quality, traceability and retention
- Interviews, testing, gap management and disagreements
- Action plan, follow-up, reporting and simulation exercise
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: ISO/IEC 27001 and NIST CSF 2.0 ↗
Avnorys operational readiness programme. It does not replace an independent audit or certification exam.
Avnorys operational readiness programme. It does not replace an independent audit or certification exam.
