Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 References  





2 External links  














ISO/IEC 27001 Lead Auditor







Add links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


The ISO/IEC 27001 Lead Auditor certification consists of a professional certification for auditors specializing in information security management systems (ISMS) based on the ISO/IEC 27001 standard and ISO 19011.

The training of lead auditors normally includes a classroom/online training and exam portion and a requirement to have performed a number of ISO/IEC 27001 audits and a number of years of information security experience. The training course is provided by any organisation wishing to deliver the training. Some certification bodies offer ISO/IEC 27001 Lead Auditor training courses such as BEHAVIOUR,[1] TRECCERT,[2] IRCA and PECB. Attending the course and passing the exam is not sufficient for an individual to use the credentials of Lead Auditor as professional and audit experience is required. The specific requirements to obtain a certificate stating the qualification of "ISO/IEC 27001 Lead Auditor" vary depending on the organisation issuing the certificate. Usually, all these programs are accredited or are in compliance with the ISO/IEC 17024 standard.

The course usually consists of around forty hours (four days) of training and a final exam on the fifth day. This certification is different from the ISO/IEC 27001 Lead Implementer certification which is targeted for information security professionals who want to implement the ISO/IEC 27001 standard rather than audit it. Most of the five-day ISO/IEC 27001 Lead Auditor courses require some prerequisite knowledge of ISO/IEC 27001 but the content of the courses may vary, depending on the certification body.

A management systems certification body (or, MSCB) usually requires that the ISO/IEC 27001 auditors hold this type of certification. To issue ISO/IEC 27001 certificates to organisations, a management systems certification body shall be accredited, usually by an National Accreditation Body (or, NAB) by complying with ISO/IEC 17021-1 and ISO/IEC 27006.

The professionals that hold the ISO/IEC 27001 Lead Auditor certification, have the required knowledge and expertise to conduct and lead ISO/IEC 27001 internal and external audits, either, as part of consultancy services or as management systems certification body auditors.

The main benefit from achieving the ISO/IEC 27001 Lead Auditor certification is the recognition that the individual has the required skills in information security, the ISO/IEC 27001 standard, and the audit methods and techniques based on ISO 19011.

The main ISO/IEC 27001 auditor certifications normally follow these designations:


References[edit]

External links[edit]


Retrieved from "https://en.wikipedia.org/w/index.php?title=ISO/IEC_27001_Lead_Auditor&oldid=1200852808"

Category: 
ISO/IEC 27001
Hidden categories: 
Articles needing additional references from July 2023
All articles needing additional references
Use Oxford spelling from January 2012
 



This page was last edited on 30 January 2024, at 11:03 (UTC).

Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



Privacy policy

About Wikipedia

Disclaimers

Contact Wikipedia

Code of Conduct

Developers

Statistics

Cookie statement

Mobile view



Wikimedia Foundation
Powered by MediaWiki