Overview
- Understand the key concepts and framework of ISO/IEC TS 27100:2020
- Assess the effectiveness of cybersecurity governance in an organization
- Plan, conduct, report, and follow up on cybersecurity audits
- Evaluate an organization’s response to threats and vulnerabilities
- Demonstrate compliance with ISO/IEC TS 27100 in the context of ISO 27001 audits
- Lead an audit team using ISO 19011 audit techniques
Objectives
- Build a clear working understanding of ISO 27100 Lead Auditor.
- Apply relevant principles, requirements and good practice in realistic organisational contexts.
- Prepare participants to contribute confidently to implementation, assurance or professional practice.
Learning outcomes
By the end of the programme, participants should be able to explain the core concepts, identify practical requirements, evaluate evidence and plan appropriate improvement actions.
Reference standard
- ISO/IEC TS 27100:2020 – Cybersecurity – Overview and Concepts
- ISO/IEC 27001:2022 – Information Security Management
- ISO/IEC 27032:2012 – Cybersecurity Guidelines
- ISO/IEC 27005:2022 – Information Security Risk Management
- ISO 19011:2018 – Guidelines for Auditing
- ISO/IEC 17021-1:2015 – Conformity Assessment Requirements for Auditing Bodies
- Understand cybersecurity fundamentals, including threat types and actors
- Conduct effective audits of cybersecurity controls and governance
- Evaluate compliance with ISO/IEC TS 27100 concepts
- Lead an audit team and manage audit programs
- Receive a Lead Auditor Certificate (exam-based)
- Cybersecurity scope and principles
- Introduction to ISO/IEC TS 27100:2020
- Relationship to ISO/IEC 27001 and other frameworks
- Cybersecurity domains and terminology
- Threat actors, attack vectors, and vulnerabilities
- Cybersecurity lifecycle and control categories
- Case study review of recent cyber incidents
- Group exercise: Identify gaps in cyber coverage
- Risk management in cybersecurity (ISO/IEC 27005 approach)
- Cyber governance vs. IT governance
- Regulatory & legal landscape overview (NIS, GDPR, etc.)
- Integrating TS 27100 into ISMS (ISO 27001)
- Maturity models and cybersecurity capability assessments
- Risk identification and mitigation workshop
- Interactive group discussion: Applying 27100 in different sectors
- Overview of ISO 19011 auditing guidelines
- Audit planning: scope, objectives, and team roles
- Document review and audit checklist development
- Conducting opening meetings and interviews
- Evidence collection, audit techniques (sampling, triangulation)
- Managing audit findings and nonconformities
- Role-play simulation: Audit interviews and observations
- Workshop: Drafting audit plan and checklist
- Audit reporting: structure and key content
- Follow-up and corrective action verification
- Presenting findings professionally
- Auditor code of ethics and behavior
- Final written Lead Auditor Examination
- Course wrap-up and Q&A
- Final practical audit simulation (team-based)
- Multiple-choice and scenario-based certification exam
- Final course review
- Final exam: multiple-choice and scenario-based questions
Target audience
- Cybersecurity professionals and risk managers
- Information Security Managers (ISMs)
- Lead Auditors or Internal Auditors
- IT/IS Consultants
- Professionals involved in GRC (Governance, Risk, and Compliance)
- Those seeking to qualify as ISO/IEC TS 27100 Lead Auditors
Benefits
- Stronger practical capability and professional confidence
- A structured approach that can be transferred to the workplace
- Assessment and a verifiable Cognicert certificate where the course requirements are met
Course content
The programme covers essential concepts, requirements, implementation considerations, evidence-based evaluation, common challenges and practical improvement planning.
Training methodologies
- Interactive lectures with real-world examples
- Workshops and breakout sessions
- Case studies based on real cyber incidents
- Mock audits and team simulations
- Quizzes & review sessions for exam readiness
- Final day proctored exam and certification
- Self-Study Material, Exam and Certification
- Online Training, Material, Exam and Certification
- Classroom Training Location: https://cognicert.com/delivery-partners/
