- An appreciation of the importance of controlling Information Security in all types of business activities;
- The ability to plan, conduct and report on a process based activity;
- An appreciation of Risk Analysis process;
- Detailed review and interpretation of the main requirements of ISO/IEC 27001:2013;
- Learn how to use Annexure A of ISO/IEC 27001:2013;
- Evaluating corrective actions for root cause and effectiveness;
- Auditor competence (as per ISO 19011, IRCA norms & industry best practices.
Delegates are expected to have prior knowledge of the following:
- Understand the Plan-Do-Check-Act (PDCA) cycle
- Knowledge of the following information security management principles and concepts:
- awareness of the need for information security;
- the assignment of responsibility for information security;
- incorporating management commitment and the interests of stakeholders;
- enhancing societal values;
- using the results of risk assessments to determine appropriate controls to reach acceptable levels of risk;
- incorporating security as an essential element of information networks and systems;
- the active prevention and detection of information security incidents;
- ensuring a comprehensive approach to information security management;
- continual reassessment of information security and making modifications as appropriate.
- Knowledge of the requirements of ISO/IEC 27001 (with ISO/IEC 27002) and the commonly used information security management terms and definitions, as given in ISO/IEC 27000.
The CQI-IRCA Exam will be administered online on Friday, at the conclusion of the training class.