Upgrade to Pro — share decks privately, control downloads, hide ads and more …

ISO 27001 - Auditing an Information Security Ma...

Sponsored · Ship Features Fearlessly Turn features on and off without deploys. Used by thousands of Ruby developers.

ISO 27001 - Auditing an Information Security Management System

From ISO/IEC 27001 Requirements to Audit Assurance

Auditing an Information Security Management System, a comprehensive professional training series designed to help auditors, Information Security Managers, consultants, compliance professionals and certification candidates understand how to effectively audit an Information Security Management System (ISMS).

This series goes beyond simply explaining the requirements of ISO/IEC 27001:2022. It provides a practical, end-to-end understanding of how Information Security Management Systems are planned, implemented, evaluated and continually improved, and how auditors provide independent assurance that these systems are achieving their intended objectives.

Throughout this series, we explore:

✅ The foundations of Information Security Management Systems (ISMS)

✅ The ISO/IEC 27001:2022 management system requirements

✅ The ISO/IEC 27000 family of standards

✅ Information security principles, risk management and security controls

✅ ISO 19011 auditing guidelines

✅ ISO/IEC 17021-1 certification requirements

✅ Audit principles and auditor competence

✅ Developing and managing audit programmes

✅ Planning and conducting ISMS audits

✅ Audit evidence, interviews, sampling and testing

✅ Evaluating conformity and control effectiveness

✅ Audit findings, nonconformities and opportunities for improvement

✅ Audit reporting and corrective action

✅ Certification, surveillance and recertification

✅ Practical ISO 27001 internal auditing using real-world examples

This course combines internationally recognised standards with practical auditing experience to explain not only what auditors should do, but why they do it and how professional judgement is applied throughout the audit process.

Whether you are preparing for certification, developing your auditing skills, implementing an ISMS or simply wanting to better understand management system auditing, this series provides a structured learning journey from the fundamentals through to advanced auditing concepts.

📚 Series Structure

Part One – Understanding the Information Security Management System

Part Two – Understanding ISO/IEC 27001:2022 Requirements

Part Three – Fundamentals and Principles of Auditing

Part Four – Managing and Planning ISMS Audits

Part Five – Conducting the ISMS Audit

Part Six – Evidence, Testing, Findings and Audit Conclusions

Part Seven – Audit Reporting, Certification and Continual Improvement

Part Eight – Practical ISO 27001 Internal Auditing

🎯 Who Should Watch?
Information Security Managers
Internal Auditors
Lead Auditors
ISO/IEC 27001 Implementers
Compliance Professionals
Risk Managers
Governance Professionals
Cybersecurity Professionals
Consultants
Students preparing for ISO/IEC 27001 auditing roles
⚠️ Disclaimer

This series has been developed for educational purposes and reflects the author's professional interpretation and practical application of internationally recognised management system standards.

It is not an official ISO publication and does not reproduce ISO standards. ISO standards remain the intellectual property of the International Organization for Standardization. Readers and organisations should obtain official copies of the applicable standards from ISO or their authorised national standards body.

👍 If You Enjoyed This Series

If you found this content valuable:

✔ Subscribe for future auditing and information security content

✔ Like the video to support the channel

✔ Share it with colleagues and fellow auditors

✔ Leave your questions and experiences in the comments

© 2026 Alison Mary Wickens. All Rights Reserved.

Auditing an Information Security Management System – From ISO/IEC 27001 Requirements to Audit Assurance is an original educational series developed to support professional learning in Information Security Management Systems and management system auditing. Unauthorized reproduction or commercial use is prohibited.

Avatar for Alison

Alison PRO

July 24, 2026

Video

More Decks by Alison

Other Decks in Business

Transcript

  1. Part 8 - Auditing an Information Security Management System From

    ISO/IEC 27001 Requirements to Audit Assurance © 2026 Alison Mary Wickens. All Rights Reserved.
  2. DISCLAIMER  This presentation has been developed for educational and

    training purposes and provides a general overview of Information Security Management Systems and management system auditing.  The content is based on the principles, concepts and requirements associated with ISO/IEC 27001, ISO 19011, ISO/IEC 17021-1 and other relevant standards and guidance publications.  This presentation does not reproduce, replace or constitute an official copy or interpretation of any ISO standard. Users should refer to the applicable published standards and official guidance documents for the complete and authoritative requirements.  The examples, audit scenarios, diagrams, interpretations and practical guidance included in this presentation are provided for illustrative and educational purposes. Their application may vary depending on the organisation, audit objectives, scope, criteria, risks and circumstances.  Nothing in this presentation should be interpreted as legal, regulatory, certification or professional advice, nor does the content guarantee certification or conformity with any management system standard.  The views and interpretations presented are those of the author and should be considered alongside applicable standards, accreditation requirements, certification body procedures, contractual obligations, legislation and regulatory requirements.  ISO standards and associated trademarks remain the intellectual property of their respective owners.
  3. Auditing an Information Security Management System Part 01 Understanding the

    ISMS ISO, management systems, information security, ISO 27000 family, ISMS overview, PDCA
  4. Auditing an Information Security Management System Part 2: Understanding ISO/IEC

    27001:2022 Requirements Clauses 4–10, Annex A, SoA, risk management and how the ISMS fits together
  5. Auditing an Information Security Management System Part 3: Fundamentals and

    Principles of Auditing What an audit is, audit types, ISO 19011, ISO 17021, principles, impartiality, objectivity, competence and roles
  6. Auditing an Information Security Management System Part 4 Managing and

    Planning ISMS Audits Audit programme, risks and opportunities, objectives, scope, criteria, team selection, Stage 1 and Stage 2 planning
  7. Auditing an Information Security Management System Part 5 Conducting the

    ISMS Audit Opening meeting, communication, interviews, document review, sampling, evidence, testing and working papers
  8. Auditing an Information Security Management System Part 6 & 7

    Audit Findings, Reporting, Certification and Continual Improvement Evaluating evidence, findings, NCs, corrective action, conclusions, reports, certification decisions, surveillance, recertification, appeals and complaints