Loading Events

Training Calendar

หลักสูตรที่ได้รับการออกแบบเนื้อหาที่ครอบคลุม ทั้งทฤษฎี เทคนิค และสาระน่ารู้ที่ทันสมัยสอนโดยอาจารย์ผู้เชี่ยวชาญ และมีประสบการณ์ด้านความปลอดภัยของสารสนเทศโดยตรง

IRCA ISO 27001:2013 ISMS Lead Auditor

กำหนดการ
20/07/2026 - 24/07/2026
9:30 am - 4:30 pm

About this course

ISO/IEC 27001:2013 – Information security management system lead auditor teaches students the fundamentals of auditing information security management systems to ISO/IEC 27001. This five day intensive course trains students on how to conduct audits for certification bodies and facilitate the ISO/IEC 27001 registration process.

The auditing exercises and lectures are based on ISO 19011:2011, “Guidelines for Quality and/or Environmental Management Systems Auditing.” The course is designed specifically for those people who wish to conduct external assessments or internal audits to ISO/IEC 27001, although students will also gain the knowledge and understanding necessary to give practical help and information to other individuals and organizations working toward conformance to the standard.

Course Benefits

  • Review the requirements of ISO/IEC 27001
  • Understand the relationship between ISO/IEC 27001 and ISO/IEC 27002
  • Learn how to assess security threats and vulnerabilities
  • Understand security controls and countermeasures
  • Understand the roles and responsibilities of the auditor
  • Learn how to, plan, execute, report, and follow-up on an information security management system audit

Who should Attend?

01

Information security managers

02

IT and corporate security managers

03

Corporate governance managers

04

Risk and compliance managers

05

Internal legal teams

06

Private data and records administration teams

07

Any management representatives or personnel in charge of ISMS quality assurance

Course Contents

Day 1 :

  • Course Introduction
    • Housekeeping
    • Course and learner objectives
    • Course structure and methods
    • Delegate assessment
  • What is an Information Security Management System?
    • Information security
    • Management systems
    • Purpose and benefits of ISO 27001
    • Related standards
  • Process Approach
    • PDCA model
    • Process model
  • Overview of ISO 27001 contents
  • ISO 27001 Mandatory clauses 4 – 8

Day 2 :

  • Course Recap day 1. Questions and Answers
  • Controls
  • Overview of the audit process
  • Auditing the SOA
  • Audit and Auditors
    • Definitions
    • 1st, 2nd and 3rd party audits
    • Roles and responsibilities of auditors and lead auditors
    • Skills and characteristics of effective auditor
  • Audit Planning
    • Information needed to plan the audit, and things to consider
    • Preliminary visits
    • Preparation of an audit plan
  • Audit communications and meetings
    • Good practice for communication during the audit
    • Formal meetings
    • Opening meeting – what to cover and how
  • Checklists
    • Benefits and drawbacks
    • Content – what to include
    • Developing a checklist for a specific audit

Day 3 :

  • Process Audits
  • Case studies
  • Conducting the audit
    • interviewing
    • sampling
    • note taking
    • interacting with the auditee
    • who’s involved and general points
  • Nonconformities
    • definition of nonconformity
    • linking to requirements of ISO 27001
    • grading nonconformity reports
    • structure and content of nonconformity reports

Day 4 :

  • Case studies
    • including interviewing.
    • developing and following audit trails
    • identifying non conformities
  • Specimen Examination
    • Review of answers
    • Layout and marking scheme of the papers
  • Closing Meeting
    • Outcomes
    • Content
    • Identifying possible issues and how to prevent or deal with these
  • Corrective Actions
    • Corrective action process
    • Evaluating corrective actions
  • Reporting the audit
    • Purpose and content of the written audit report
  • Next steps
    • action planning
    • further development
    • auditor registration

Day 5 :

  • Course Evaluations
  • Examination Rules
  • Written Examination
  • End of the Course

Prerequisites

  • A prior knowledge of the requirements of ISO 27001 would be beneficial.

Training Info

Date : 

20/07/2026 - 24/07/2026

Time : 

9:30 am - 4:30 pm

Duration:  5 Days
Venue: Grande Centre Point Lumphini 16th Floor,1188 Rama IV Road,
Thungmahamek, Sathon, Bangkok 10120
Training price: 38,000 Baht (Ex.Vat)

02 670 8980-4 ext. 321, 322, 323

Bookings

Bookings are closed for this event.

ติดต่อเรา
เพื่อรับคำปรึกษาข้อมูลเพิ่มเติม
ACinfotec พร้อมเป็นพาร์ทเนอร์เคียงข้างคุณ ตั้งแต่ก้าวแรก… จนถึงการรับรอง