Visão Geral
O curso ISO 27001 Lead Auditor tem como objetivo capacitar profissionais para planejar, conduzir e gerenciar auditorias de Sistemas de Gestão de Segurança da Informação (SGSI) com base na norma ISO/IEC 27001. Durante o treinamento, os participantes irão aprender os princípios de auditoria, técnicas de avaliação de controles, gestão de riscos e conformidade, além de desenvolver habilidades práticas para liderar auditorias internas e externas.
Conteúdo Programatico
Module 1 – Introduction to Information Security Management Systems (ISMS)
- Overview of ISO/IEC 27001 standard
- ISMS principles and concepts
- Information security fundamentals (CIA triad)
- Context of the organization
- Interested parties and requirements
- Scope definition of ISMS
Module 2 – ISO/IEC 27001 Requirements and Clauses
- Detailed analysis of clauses 4 to 10
- Leadership and commitment
- Risk assessment and risk treatment
- Statement of Applicability (SoA)
- Support and operation processes
- Performance evaluation and improvement
Module 3 – Risk Management and Controls (Annex A)
- Information security risk management process
- Control objectives and controls from Annex A
- Selection and justification of controls
- Implementation of controls
- Monitoring and effectiveness of controls
Module 4 – Audit Principles and Preparation
- Audit concepts and definitions
- Types of audits (internal, external, certification)
- ISO 19011 guidelines
- Audit program management
- Audit planning and scope definition
- Audit checklist preparation
Module 5 – Conducting an Audit
- Opening meeting techniques
- Collecting and verifying audit evidence
- Interviewing techniques
- Observations and sampling methods
- Identifying nonconformities
- Audit documentation
Module 6 – Audit Reporting and Follow-up
- Writing audit findings
- Nonconformity classification
- Audit report structure
- Corrective actions and root cause analysis
- Follow-up audit activities
- Closing meeting
Module 7 – Lead Auditor Skills and Competencies
- Leadership and team management
- Communication skills
- Conflict resolution
- Ethical considerations
- Decision-making in audits
- Time management during audits
Module 8 – Certification Process and Practical Exercises
- Certification audit process
- Stage 1 and Stage 2 audits
- Auditor competence and qualification
- Practical case studies
- Mock audit exercises
- Final assessment