ISO/IEC 27001:2022 Lead Auditor – Information Security Management Systems (ISMS)
I completed ISO/IEC 27001:2022 lead auditor training in January 2024 and received the certificate in February. The training covered audits of an Information Security Management System (ISMS), including planning, evidence collection, reporting and follow-up.
The exercises focused on assessing an organisation’s security management system against the standard and documenting non-conformities.
Category
Information
Security
Issued By
CQI – IRCA
Issue Date
23 Feb 2024
Training Dates
08.01.24 – 16.01.24
Certificate ID
BTIS/C1786/01:0224
CQI-IRCA ID
533472

Curriculum
The training included simulated audit exercises covering:
- The structure of ISO/IEC 27001:2022 and an ISMS.
- Organisational context, leadership and risk planning.
- Information security risk assessment, treatment and control selection.
- Audit scope, objectives, schedules and preparation.
- Interviews, sampling and collection of audit evidence.
- Writing findings and reviewing corrective actions.
- Audit team roles, ethics and impartiality.
- Closing an audit and following up.
What I learned
I practised planning an ISMS audit, collecting evidence and writing findings. I also studied Annex A controls, their relationship to security risks, and how to assess corrective actions after an audit.
This training is relevant to my policy reviews and security assessments. It provides a reference for checking how an ISMS is documented, operated and reviewed.