RivedixRivedix Academy
← Rivedix.comEnquire Now
AcademyCoursesISO 27001 Lead Implementer & Internal Auditor
LiveCertification

ISO 27001 Lead Implementer & Internal Auditor

Comprehensive ISO 27001:2022 training covering ISMS design, implementation, Annex A controls, risk assessment, internal audit methodology, and certification preparation. Led by a former Head of IT Security at Deutsche Bank.

FormatOnline & Pune
LevelIntermediate
FormatOnline & Pune
LevelIntermediate
CertificateRivedix Academy
Enquire & Enrol
Learning Outcomes

What you'll be able to do

Design an Information Security Management System (ISMS) aligned with ISO 27001:2022
Conduct a structured risk assessment and build an ISO 27001 risk register
Select and implement Annex A controls with a Statement of Applicability
Plan and execute an ISO 27001 internal audit
Write audit reports and manage non-conformities through to closure
Prepare an organisation for Stage 1 and Stage 2 certification audits
Understand the key changes from ISO 27001:2013 to ISO 27001:2022
Curriculum

Course Outline

Approx. 8 hours per day including hands-on exercises. All materials included.

Day 1 — ISMS Foundations & Risk~8 hours
01
ISO 27001:2022 Overview & Changes
Standard structure · Key changes from 2013 · ISMS scope · Context of the organisation · Interested parties
02
Risk Assessment Methodology
ISO 27005 risk framework · Threat & vulnerability analysis · Risk register design · Risk treatment options · Residual risk acceptance
03
ISMS Design: Clauses 4–10
Leadership & governance · Objectives · Support resources · Documented information · Operations · Performance evaluation
04
Hands-on: ISMS for a Sample Organisation
Scope definition · Context analysis · Risk register workshop · Controls selection · SoA draft
Day 2 — Annex A Controls~8 hours
05
Annex A: Organisational Controls (5.1–5.37)
Policies, roles, asset management, access control, supplier relationships, incident management
06
Annex A: People, Physical & Technological Controls
HR security · Physical security · New Annex A technological controls (threat intelligence, data masking, secure coding)
07
Statement of Applicability (SoA)
SoA structure · Justification for inclusion/exclusion · Linking controls to risks · SoA review process
08
Control Implementation Planning
Implementation roadmap · Quick wins vs long-term controls · Evidence requirements · KPIs and metrics for controls
Day 3 — Internal Audit & Certification~8 hours
09
Internal Audit Planning & Execution
Audit programme · Audit plan preparation · Sampling approach · Evidence collection techniques · Observation vs finding vs non-conformity
10
Audit Reporting & Non-Conformity Management
Audit report writing · NC classification (major/minor) · Corrective action process · CAPA verification · Management review inputs
11
Certification Process: Stage 1 & Stage 2
Certification body selection · Stage 1 document review · Stage 2 on-site audit · Common audit failures · Surveillance audit cycle
12
Final Assessment & Case Study
Full ISMS gap assessment scenario · Group audit exercise · Written assessment · Certificate of completion
FAQ

Common questions

ISO 27001 Lead Implementer & Internal Auditor
FormatOnline & Pune
LevelIntermediate
CertificateRivedix Academy
Enquire & Enrol
Related Courses
ISO 42001 Lead Implementer & AuditorData PrivacyCISA Exam Preparation
Enrol Today

Ready to get started?

Enquire now and we'll send you upcoming batch dates, pricing, and details within 24 hours.

Enquire & EnrolBrowse Other Courses