From ISO/IEC 27001 Requirements to Audit Assurance
Auditing an Information Security Management System, a comprehensive professional training series designed to help auditors, Information Security Managers, consultants, compliance professionals and certification candidates understand how to effectively audit an Information Security Management System (ISMS).
This series goes beyond simply explaining the requirements of ISO/IEC 27001:2022. It provides a practical, end-to-end understanding of how Information Security Management Systems are planned, implemented, evaluated and continually improved, and how auditors provide independent assurance that these systems are achieving their intended objectives.
Throughout this series, we explore:
✅ The foundations of Information Security Management Systems (ISMS)
✅ The ISO/IEC 27001:2022 management system requirements
✅ The ISO/IEC 27000 family of standards
✅ Information security principles, risk management and security controls
✅ ISO 19011 auditing guidelines
✅ ISO/IEC 17021-1 certification requirements
✅ Audit principles and auditor competence
✅ Developing and managing audit programmes
✅ Planning and conducting ISMS audits
✅ Audit evidence, interviews, sampling and testing
✅ Evaluating conformity and control effectiveness
✅ Audit findings, nonconformities and opportunities for improvement
✅ Audit reporting and corrective action
✅ Certification, surveillance and recertification
✅ Practical ISO 27001 internal auditing using real-world examples
This course combines internationally recognised standards with practical auditing experience to explain not only what auditors should do, but why they do it and how professional judgement is applied throughout the audit process.
Whether you are preparing for certification, developing your auditing skills, implementing an ISMS or simply wanting to better understand management system auditing, this series provides a structured learning journey from the fundamentals through to advanced auditing concepts.
📚 Series Structure
Part One – Understanding the Information Security Management System
Part Two – Understanding ISO/IEC 27001:2022 Requirements
Part Three – Fundamentals and Principles of Auditing
Part Four – Managing and Planning ISMS Audits
Part Five – Conducting the ISMS Audit
Part Six – Evidence, Testing, Findings and Audit Conclusions
Part Seven – Audit Reporting, Certification and Continual Improvement
Part Eight – Practical ISO 27001 Internal Auditing
🎯 Who Should Watch?
Information Security Managers
Internal Auditors
Lead Auditors
ISO/IEC 27001 Implementers
Compliance Professionals
Risk Managers
Governance Professionals
Cybersecurity Professionals
Consultants
Students preparing for ISO/IEC 27001 auditing roles
⚠️ Disclaimer
This series has been developed for educational purposes and reflects the author's professional interpretation and practical application of internationally recognised management system standards.
It is not an official ISO publication and does not reproduce ISO standards. ISO standards remain the intellectual property of the International Organization for Standardization. Readers and organisations should obtain official copies of the applicable standards from ISO or their authorised national standards body.
👍 If You Enjoyed This Series
If you found this content valuable:
✔ Subscribe for future auditing and information security content
✔ Like the video to support the channel
✔ Share it with colleagues and fellow auditors
✔ Leave your questions and experiences in the comments
© 2026 Alison Mary Wickens. All Rights Reserved.
Auditing an Information Security Management System – From ISO/IEC 27001 Requirements to Audit Assurance is an original educational series developed to support professional learning in Information Security Management Systems and management system auditing. Unauthorized reproduction or commercial use is prohibited.