Become an ISO 27001:2022 Certified ISMS Internal Auditor
Gain the skills and knowledge you need to become an effective ISO 27001:2022 Internal Auditor. Our four-day course provides a clear, practical understanding of the updated standard, its requirements, and proven audit practices across different organizations.
By completing this course, you will:
Understand the ISO 27001:2022 structure, principles, and requirements
Learn to plan, conduct, and report ISMS audits following ISO 19011
Strengthen your ability to evaluate ISMS effectiveness
Support organizations in achieving ISO 27001:2022 certification
Earn a Certificate of Completion to validate your expertise
Course Outline & Details
-
Introduction to ISO 27001:2022 and its importance in managing information security
In-depth review of the ISO 27001:2022 standard, including scope, context, and leadership requirements
Risk assessment and risk treatment methodologies
Understanding the Statement of Applicability and risk treatment plans
Exploring Annex A controls and their implementation
-
Principles and best practices of auditing management systems
Audit planning and preparation, including the use of audit checklists and tools
Conducting on-site audit activities and effective communication with auditees
Evaluating and reporting audit findings, including identifying non-conformities and opportunities for improvement
Audit follow-up and closure processes
-
Cost: 4 days – $2,200 USD per student.
Delivery: Online
Start time: 9 am, EST.
Meet Your Instructor
Petru Dragnef is the Practice Lead of Audit & Compliance at Seratos and is a certified ISO/IEC 27001:2022 Lead Auditor. He has conducted audits and advisory engagements for Fortune 100 companies in the semiconductor and medical/laboratory device industries, in addition to working with many international law firms headquartered in North America.
Specialties:
ISO 27001, 27701, 27017
IT & cloud security architecture
Mathematical modelling for risk management
Petru holds an academic background in mathematics and philosophy. He applies a systems-thinking approach to cybersecurity and information governance, ensuring compliance with standards and ensuring the operational functionality of an organization’s management systems.