Coaching and Training

GIC Vietnam provides management system, product and process certification; verification and validation; improvement tool certification; and training. These services help businesses build trust, improve management effectiveness, enhance information transparency and meet customer and partner requirements.

Training and Coaching Programs

INTERNAL AUDITOR TRAINING

ISO/IEC 27001:2022 Information Security Management System Internal Auditor Training

This course helps participants understand the requirements of ISO/IEC 27001:2022 and develop the skills to plan, conduct, report on and follow up internal audits of an information security management system (ISMS), using the guidance in ISO 19011:2026. It focuses on risk assessment, the Statement of Applicability (SoA) and the effectiveness of controls in preserving the confidentiality, integrity and availability of information.

Standards and guidance
Information security management systems: ISO/IEC 27001:2022
Guidelines for auditing management systems: ISO 19011:2026
Guidance on security controls: ISO/IEC 27002:2022
Training focus: ISMS requirements · Risks and the SoA · Audit evidence
Confidentiality Integrity Availability

Course objectives

  1. Understand the structure and requirements of ISO/IEC 27001:2022 and the links between risk assessment, risk treatment, the SoA and security controls.
  2. Understand auditing principles, audit programme management and the steps involved in auditing management systems, following the guidance in ISO 19011:2026.
  3. Practise audit planning, checklist development, evidence collection, documenting findings and preparing ISMS internal audit reports.
  4. Develop interviewing, evidence analysis and corrective action follow-up skills to conduct objective audits, maintain confidentiality and contribute to ISMS improvement.

Who should attend

  • Managers
  • Information security and ISMS personnel
  • IT, operations and software development personnel
  • Risk management and compliance personnel, and information owners
  • Internal audit team members
  • Personnel seeking to develop internal auditing competence

Key considerations when auditing an ISMS

ISMS scope and information protection requirements:Review the scope, processes, interested parties and requirements for the confidentiality, integrity and availability of information.
Risk assessment and treatment:Compare risk assessment results with treatment plans, implementation responsibilities and the acceptance of residual risks.
Statement of Applicability (SoA):Review the necessary controls, the justification for their inclusion, their implementation status and the justification for excluding controls in Annex A.
Control effectiveness:Examine evidence of the implementation of selected controls, comparing documentation and records with actual practices.
Compliance and external relationships:Review legal, contractual and information security requirements in relationships with suppliers, third parties and cloud service providers, where applicable.
ISMS performance and improvement:Review objectives, monitoring indicators, information security incidents, management reviews and the effectiveness of corrective actions.

Course content

Select a section to expand or collapse its content.

01Overview of ISMS and ISO/IEC 27001:2022
  • Information security concepts; confidentiality, integrity, availability and the value of an ISMS.
  • Structure of Clauses 4 to 10, Annex A and the role of ISO/IEC 27002:2022 as guidance.
  • Key aspects of the 2022 edition and the climate change considerations introduced by ISO/IEC 27001:2022/Amd 1:2024.
  • The role of internal audits in maintaining ISMS conformity and effectiveness, and supporting improvement.
02ISMS requirements, risks and controls
  • ISMS context, scope and interested parties; leadership, policy, objectives and planning changes.
  • Resources, competence, awareness, communication and control of documented information.
  • Risk identification, analysis and evaluation; acceptance criteria and the responsibilities of risk owners.
  • Risk treatment plans and the SoA; comparison with Annex A to ensure that no necessary controls are overlooked.
  • Organisational, people, physical and technological controls; reviewing evidence of appropriate implementation.
  • Monitoring, measurement and performance evaluation; management review, corrective actions and ISMS improvement.
03Auditing principles and process in accordance with ISO 19011:2026
  • Auditing principles, objectivity and the confidentiality of information during audits.
  • Managing an audit programme and the steps involved in conducting an audit.
  • Defining audit objectives, scope, criteria and methods using a risk-based approach.
  • Roles, responsibilities and competence requirements for audit team leaders and members.
04Planning and preparing for internal audits
  • Reviewing the ISMS scope, risk records, treatment plans, the SoA and previous audit results.
  • Developing the audit plan, assigning responsibilities and agreeing access to information and systems.
  • Developing checklists based on the standard’s requirements, processes, risks and applicable controls.
  • Preparing the sampling approach, interview questions and evidence collection methods to maintain confidentiality and minimise operational disruption.
05Conducting audits and documenting findings
  • Conducting opening meetings, interviews, observations and reviews of documents and records.
  • Collecting and verifying evidence relating to access rights, backups, change management or incident handling within the audit scope.
  • Evaluating evidence against audit criteria, the SoA and risk treatment plans, and assessing ISMS conformity and effectiveness.
  • Clearly documenting findings and nonconformities based on requirements and evidence, and addressing issues arising during the audit.
06Reporting, audit follow-up and auditor skills
  • Consolidating audit results, presenting conclusions and conducting closing meetings.
  • Preparing clear, consistent reports with traceable evidence, and protecting sensitive information in audit records.
  • Following up on the implementation of corrective actions and verifying their effectiveness.
  • Developing communication, questioning, listening, analytical and conflict management skills.

Training methods

The course combines theory with practical activities to help participants apply their knowledge to internal auditing.

Presentations supported by practical examples.
Group discussions and analysis of risk records, the SoA and evidence of controls.
Exercises in audit planning and developing ISMS audit checklists.
Practical exercises in interviewing, documenting findings and preparing audit reports.

Trainers

Our trainers are professionals with experience in information security management and management system auditing in businesses. Training focuses on ISMS auditing methods, evidence analysis and practical scenarios.

ISO/IEC 27001:2022 Internal Auditor Training

Contact GIC Vietnam for advice on course schedules, training formats and a programme tailored to the needs of your organisation.

GIC VIETNAM
12F, 14 Lang Ha Building, Ba Dinh, Hanoi
Tel: 024.6275 2268 · Email: tuandm@gicvn.vn
Ho Chi Minh City Office: Room 502, 160 Nam Ky Khoi Nghia · Tel: 028.3930 7936
Chia sẻ:

Training and Coaching Programs

  • ISO 9001:2026 - Requirements Update and Transition Guidance

    Understand the changes in ISO 9001:2026 and learn how to transition your quality management system from ISO 9001:2015. Flexible programmes from half a day to three days combine training, practical system reviews, transition planning and certification audit preparation, tailored to your...
  • ISO 9001:2026 QMS Lead Auditor

    This five-day, 40-hour course develops the skills needed to conduct and lead quality management system audits. Designed with reference to CQI-IRCA’s QMS Auditor / Lead Auditor course framework, it combines ISO 9001:2026 learning with practical exercises in audit planning, evidence evaluation,...
  • ISO 9001:2026 QMS Internal Auditor

    Develop the knowledge and practical skills to audit a quality management system while exploring the key updates in ISO 9001:2026. The course covers audit planning, evidence collection, documenting findings, reporting and corrective action follow-up, using the guidance in ISO 19011:2026.
  • ISO 14001:2026 Internal Auditor Training

    The ISO 14001:2026 Environmental Management System Internal Auditor Training course helps participants understand ISO 14001 requirements and develop the practical skills needed to prepare, conduct, report and follow up internal audits. The program combines EMS knowledge with practical auditing methods and...
  • ISO/IEC 27001:2022 ISMS Internal Auditor

    Develop the knowledge and skills to conduct internal audits of an information security management system against ISO/IEC 27001:2022. Explore the links between risks, the Statement of Applicability (SoA) and security controls, and practise audit planning, evidence collection, reporting and corrective action...
  • Load more

Online Training (E-learning)

  • Overview of the ISO 9001:2026 Quality Management System

    The "Overview of the ISO 9001:2026 Quality Management System" online training course provides employees with a practical introduction to this standard. Learners gain an understanding of quality management principles, the process approach, and their roles and responsibilities in implementing, maintaining, and...
  • Workplace Information Security | Protecting Information in Daily Tasks

    “Information Security at Work | Protecting Information in Daily Work” is a foundation-level E-learning course designed to help employees understand their role in protecting organizational information. Referencing ISO/IEC 27001:2022, the course covers ISMS fundamentals, confidentiality, integrity and availability, information security risks,...