ISO 27001 Lead Auditor | Course

ISO 27001 lead auditor course, ISO 27001 lead auditor training, ISO 27001 lead auditor certification, ISO 27001 lead auditor exam, information security

Mastering the Audit of an Information Security Management System (ISMS) based on ISO 27001:2013


ISO 27001 Lead Auditor course, in addition to the approach to the standard, includes a practical part – the audit methodology of an Information Security Management System – guided by a case study. More than knowing concepts, principles and requirements, you will learn to put into practice an audit program, based on the methodology proposed by Behaviour, and develop in training resources and ways of working that will be useful to apply in a real context.

The fundamental knowledge of ISO 27001 Foundation is included, so it is not a prerequisite or a training path.

Course manual updated in June 2021. It already considers the two corrections that will come out in the new ISO 27001 and the draft of the new ISO 27002.


Next GUARANTEED DATES (*)       21-Feb-2022, Live Training   Register now       

course evaluation     4.8 in 5

ISO 27001 lead auditor course, ISO 27001 lead auditor training, ISO 27001 lead auditor certification, ISO 27001 lead auditor exam, information security


This course is available to be delivered in a classroom and Live-Training model.
Live Training brings you the dynamic environment of the classroom, to your desk. Using your computer, you interact with the trainer and the trainees as if you were with them in the classroom.

ISO 27001 Lead Auditor Path

This five-day intensive course enables participants to develop the necessary expertise to audit an Information Security Management System (ISMS) as specified in ISO/IEC 27001 and to manage a team of auditors by applying widely recognized audit principles, procedures and techniques.

During this training, the participant will acquire the necessary knowledge and skills to proficiently plan and perform internal and external audits in compliance with the certification process of the ISO 19011, ISO 27007, ISO 17021 and 27006 standards. Based on practical exercises, the participant will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary to efficiently conduct an audit.

Training Methodology
This training is based on both theory and practice:
  • Sessions of lectures illustrated with examples based on real cases
  • Practical exercises based on a full case study including role playings and oral presentations
  • Review exercises to assist the exam preparation
  • Practice test similar to the certification exam
To benefit from the practical exercises, the number of training participants is limited.

  • Internal auditors
  • Auditors wanting to perform and lead Information Security Management System (ISMS) certification audits
  • Project managers or consultants wanting to master the Information Security Management System audit process
  • CxO and Senior Managers responsible for the IT governance of an enterprise and the management of its risks
  • Members of an information security team
  • Expert advisors in information technology
  • Technical experts wanting to prepare for an Information security audit function

Participants should understand English as the course documentation is in this language.

Duration (days)
5 days

Learning Objectives
At the end of the course students should be able to:
  • Acquire knowledge on the operation of an Information Security Management System, based on ISO 27001 and its main processes and controls.
  • Acquire the knowledge on the goal, content and correlation between ISO 27001, ISO 27002 and other standarts and regulatory frameworks.
  • Acquire the knowledge on the fundamental audit concepts and principles, and on the fundamental concepts, approaches and techniques for implementation and management of an ISMS.
  • Understand an auditor's role: to plan, lead and follow-up on a Information Security Management System audit in accordance with ISO 19011.
  • Interpret the requirements of ISO 27001 in the context of an ISMS audit.
  • Acquire the competencies of an auditor to: plan an audit, lead an audit, draft reports, and follow up on an audit in compliance with ISO 19011.
  • Strengthen personal skills necessary for an auditor to act with due professional care during an audit.

  1. Introduction to Information Security and ISO 27001
    • Course objectives and structure
    • Standard and regulatory framework
    • Certification process
    • Fundamental principles of Information Security
    • Information Security Management System (ISMS) (Part1)

  2. ISMS and Audit concepts and principles
    • Information Security Management System (ISMS) (Part2)
    • Fundamental audit concepts and principles
    • ISO 27001 Lead Auditor Certification Exam (Exam - Part 1)

  3. Preparation and launching of an audit; On-site audit activities
    • Audit approach based on evidence and risk
    • Initiating the audit
    • Stage 1 audit
    • Preparing the stage 2 audit (on-site audit)
    • Stage 2 audit
    • Communicating during the audit
    • Audit procedures

  4. Concluding the on-site audit activities and closing the audit
    • Creating audit test plans
    • Drafting audit findings and non-conformity reports
    • Documentation of the audit and quality review
    • Closing the audit
    • Evaluating action plans by the auditor
    • Beyond the initial audit
    • Managing an internal audit programme
    • Competence and evaluation of auditors
    • Closing the training

  5. ISO 27001 Lead Auditor Certification Exam (Exam - Part 2)

  • The Certified ISO/IEC 27001 Lead Auditor exam covers the following competence domains:
    • Domain 1: Fundamental principles and concepts of information security
    • Domain 2: Information Security Management System (ISMS)
    • Domain 3: Fundamental concepts and principles of auditing
    • Domain 4: Preparation of an ISO 27001 audit
    • Domain 5: Conducting an ISO 27001 audit
    • Domain 6: Concluding an ISO 27001 audit
    • Domain 7: Managing an ISO 27001 audit programme
  • The Certified ISO/IEC 27001 Lead Auditor exam is available in English language.
  • Duration: 3 hours.
  • The exam result is sent via email to the candidate within eight weeks after the examination, being the exam result graduated in qualitative note: "Pass or Fail".
  • In the case of a failure, the result will be accompanied with the list of domains in which you had a mark lower than the passing grade.
If the candidate fails the exam, he is entitled to one free retake within a 12 month period from the initial exam date.

After successfully completing the exam, participants can apply for the credentials: "Certified ISO/IEC 27001 Provisional Auditor", "Certified ISO/IEC 27001 Auditor" or "Certified ISO/IEC 27001 Lead Auditor", depending on their level of experience.
Those credentials are available for internal and external auditors.
A certificate will be issued to participants who successfully pass the exam and comply with all the other requirements related to the selected credential.
ISO 27001 Lead Auditor is a certification program aligned with ISO 17024 standard.

Requirements for “Implementer” certification:
CertificationExamProfessional experienceISMS Audit experienceISMS project experience
ISO 27001 Provisional AuditorISO 27001 LA ExamNoneNoneNone
ISO 27001 AuditorISO 27001 LA Exam2 years
1 year of information security work experience
Audit activities totalling 200 hoursNone
ISO 27001 Lead AuditorISO 27001 LA Exam5 years
2 years of information security work experience
Audit activities totalling 300 hoursNone

Our specialists are renowned consultants and auditors, with several years of experience in the areas of implementation, auditing and training in family ISO 27000, with particular focus on standards ISO 27001, ISO 27005 and their associated standards.
Some of our experts work directly in the improvement of these standards through its participation in the committees responsible for these standards in various countries.

General Information
  • Training in English language.
  • Course manual in English, containing over 450 pages of information, practical examples, case-study and step-by-step audit methodology.
  • Behaviour Participation Certificate of 31 CPD (Continuing Professional Development) credits.
  • Certification Exam in English.
  • Certification Diploma after successful examination and formal process registration. This process has no associated cost.
  • Coffee break in the morning and afternoon (Applies to all training that take place in Behaviour facilities)
  • If the candidate fails the exam, he is entitled to one free retake within a 12 month period from the initial exam date.

  • ISO 27001 is an auditable Information Security Management System (ISMS).

  • ISO 27001 allows certification and international recognition of an organization. Allows access to new markets and optimization of operations. Allows improve quality, increase productivity, competitive advantage, customer satisfaction and sales.

  • ISO 27001 Lead Auditor course bases its pedagogical model in a certification program aligned in ISO 17024 standard, which defines the requirements for certification of people, fulfilling the recommendations of ISO.

  • ISO 27001 Lead Auditor course is geared towards to the audit of the standard, through a step-by-step audit process. Thus, throughout the course, in addition to the basic concepts of ISMS, are presented the steps needed to prepare and start the ISMS audit process and the management of audits through an audit program, which includes the selection of the approach, the audit methodology, selection and skills of the auditors, steps and approaches for evidence collection and drafting of findings and nonconformities, among other activities needed to prepare the auditor to audit the ISMS of his organization or to participate and lead audits for an certification body, using the best practices of audit according the ISO 19011 and the requirements for certification bodies in ISO 17021.

  • One of the strengths of the ISO 27001 Lead Auditor course, in addition to inclusion of implementation methodology, is that it allows to prepare professionals for the audit of ISO 27001 certification and the registration in the certifying body. Addresses itself to this end, the recommendations of ISO 19011 and the ISO 17021 - requirements for certification bodies.

  • Certification exam is monitored by an official Behaviour administrator.

  • ISO 27001 Lead Auditor certification exam is conducted at the end of the course, on the last day of training, which focuses on development questions and case studies allowing the certifying entity to measure, more effectively, the knowledge of the candidates.

  • Upon success in the exam, professional will achieve one of the ISO 27001 certifications levels. In case of failure, professional may repeat the exam at no additional cost, within 1 year after the date of the 1st examination.

  • Behaviour Pedagogical Model aims to provide a learning environment conducive to acquisition of competences, in accordance with objectives of each training program. Promoting interaction, participation and appreciation of experiences, we contribute to meaningful learning, certification and international recognition but, above all to the development of critical thinking and autonomy.

  • Behaviour is an organization accredited by DGERT (Portuguese Government Entity) and certified on ISO 9001. Behaviour has its Quality Management System (QMS) implemented in accordance with the requirements of ISO 9001, the requirements of DGERT, the requirements of the European standard NP 4512 and the standard ISO 10015.

Dates and Price

Guaranteed Dates Program (*)
All dates of this course are guaranteed only for the events that take place in Lisbon. In other locations the events are subject to a minimum number of participants.
On Behaviour all courses at Lisbon occur regardless of the number of trainees in room. The concept of setting up classes does not exist in our educational model, which is why all public dates, presented on the website, are guaranteed. So if you're in Portugal or anywhere else in the world, you can prepare your week or your trip, as long as you ensure your registration in the course.

Volume Discounts
For companies, Behaviour offer discounts, between 10% and 40% of the value of training, starting from the registration of the 2nd participant, in the same course and on the same date.
Simulate the prices for the number of participants you want to register to or contact us via chat.

Hotels and Useful Information
Know where you can stay in Lisbon, near Behaviour. For more information please see >> Booking <<