SlideShare ist ein Scribd-Unternehmen logo
1 von 4
Downloaden Sie, um offline zu lesen
CERTIFIED ISO 27034
LEAD AUDITOR
MASTERING THE AUDIT OF IT - SECURITY TECHNIQUES – APPLICATION SECURITY
BASED ON ISO 27034, IN COMPLIANCE WITH THE REQUIREMENTS OF ISO 19011 AND
ISO 17021
SUMMARY
This five-day intensive course enables the participants develop the necessary expertise to audit an Information technology
- Security techniques – Application Security as specified in ISO/IEC 27034, and manage a team of auditors by applying
widely recognized audit principles, procedures and techniques. During this training, the participant will acquire the
necessary knowledge and skills to proficiently plan and perform internal and external audits in compliance with ISO
19011 and ISO 17021. Based on practical exercises, the participant will develop the skills (mastering audit techniques)
and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.)
necessary for efficient conduct of an audit.

COURSE AGENDA

DURATION: 5 DAYS

DAY 1
Introduction to IT - Security techniques –
Application Security overview and concepts
as required by ISO 27034
▶▶ 	 ormative, regulatory and legal framework related to
N
application security
▶▶ 	 undamental principles of Application Security
F
▶▶ 	SO 27034 certification process
I
▶▶ 	T - Security Techniques – Application Security
I
▶▶ 	 etailed presentation of the clauses of ISO 27034
D

DAY 3
Conducting an ISO 27034 audit
▶▶ 	 ommunication during the audit
C
▶▶ 	 udit procedures: observation, document review,
A
interview, sampling techniques, technical verification,
corroboration and evaluation
▶▶ 	 udit test plans
A
▶▶ 	 ormulation of the audit findings
F
▶▶ 	 ocumenting nonconformities
D

DAY 5

DAY 2
Planning and initiating an ISO 27034 audit
▶▶
▶▶
▶▶
▶▶
▶▶

F
	 undamental audit concepts and principles
A
	 udit the approach based on evidence and risk
P
	 reparation of an ISO 27034 audit
A
	 pplication Security documentation audit
C
	 onducting an opening meeting

DAY 4
Concluding and ensuring the follow-up of
an ISO 27034 audit
▶▶ 	 udit documentation
A
▶▶ 	 uality review
Q
▶▶ 	 onducting a closing meeting and conclusion of an
C
ISO 27034 audit
▶▶ 	 valuation of corrective action plans
E
▶▶ 	SO 27034 surveillance audit
I
▶▶ ISO 27034 internal audit management program

Certification Exam
www.pecb.org
WHO SHOULD ATTEND?
▶▶
▶▶
▶▶
▶▶
▶▶
▶▶
▶▶

I
	nternal auditors
A
	 uditors wanting to perform and lead IT - Security techniques – Application Security audit
Project managers or consultants who want to master the IT - Security techniques – Application Security audit process
C
	 xO and senior managers responsible for the IT governance of an enterprise and the management of its risks
M
	 embers of an information security team
Expert advisors in Information Technology
Technical experts wanting to prepare for Application Security audit function

LEARNING OBJECTIVES
▶▶ 	 o acquire the expertise needed to perform an ISO 27034 internal audit following the ISO 19011 guidelines
T
▶▶ 	 o acquire the expertise needed to perform an ISO 27034 audit following the ISO 19011 guidelines and the
T
specifications of ISO 17021 and ISO 27006
▶▶ 	 o acquire the necessary expertise to manage an IT - Application Security audit team
T
▶▶ 	 o understand the operation of an ISO 27034 conformant Application Security management system
T
▶▶ 	 o understand the relationship between an IT - Security techniques – Application Security, including risk
T
management, controls and compliance with the requirements of different stakeholders of the organization
▶▶ 	 o improve the ability to analyze the internal and external environment of an organization, its risk assessment and
T
audit decision-making

PECB

www.pecb.org

Certified
ISO 27034
Lead Auditor
EXAMINATION
▶▶ The “Certified ISO 27034 Lead Auditor” exam fully meets the requirements of the PECB Examination and
Certification Program (ECP). The exam covers the following competence domains:
DOMAIN 1: FUNDAMENTAL PRINCIPLES AND CONCEPTS IN APPLICATION SECURITY

1

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and illustrate the
main Application Security concepts related to an Information Technology Application Security (AS)
DOMAIN 2: INFORMATION TECHNOLOGY APPLICATION SECURITY (AS)

2

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and illustrate the
main concepts and components of an Information Technology Application Security based on ISO 27034
DOMAIN 3: FUNDAMENTAL AUDIT CONCEPTS AND PRINCIPLES

3

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and apply the
main concepts and principles related to an AS audit in the context of ISO 27034
DOMAIN 4: PREPARATION OF AN ISO 27034 AUDIT

4

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can prepare appropriately an AS audit in
the context of ISO 27034
DOMAIN 5: CONDUCT OF AN ISO 27034 AUDIT

5

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can conduct efficiently an AS audit in the
context of ISO 27034
DOMAIN 6: CONCLUSION AND FOLLOW-UP OF AN ISO 27034 AUDIT

6

Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can conclude an AS audit and conduct
follow-up activities in the context of ISO 27034
DOMAIN 7: MANAGEMENT OF AN ISO 27034 AUDIT PROGRAM

7

Main Objective: To ensure that the ISO 27034 Lead Auditor understands how to establish and manage an AS
audit program

▶▶ The “Certified ISO/IEC 27034 Lead Auditor” exam is available in different languages, including English, French,
Spanish and Portuguese
▶▶ Duration: 3 hours
▶▶ For more information about the exam, please visit: www.pecb.org

www.pecb.org
CERTIFICATION
▶▶ 	 fter successfully completing the exam, participants can apply for the credentials of Certified ISO/IEC 27034
A
Provisional Auditor, Certified ISO/IEC 27034 Auditor or Certified ISO/IEC 27034 Lead Auditor depending on their
level of experience. Those credentials are available for internal and external auditors
▶▶ A certificate will be issued to those participants who successfully pass the exam and comply with all the other
requirements related to the selected credential:
Credential

Exam

Professional
Experience

ITST Audit
Experience

ITST Project
Experience

Other
Requirements

ISO 27034
Provisional
Auditor

ISO 27034
Lead Auditor
Exam

None

None

None

Signing the
PECB
code of ethics

ISO 27034
Auditor

ISO 27034
Lead Auditor
Exam

Two years
One year of
Information
Technology
Security Techniques
work experience

Audit activities
totaling
200 hours

None

Signing the
PECB
code of ethics

ISO 27034
Lead
Auditor

ISO 27034
Lead Auditor
Exam

Five years
Two years of
Information
Technology
Security Techniques
work experience

Audit activities
totaling
300 hours

None

Signing the
PECB
code of ethics

GENERAL INFORMATION
▶▶
▶▶
▶▶
▶▶

Certification fees are included in the exam price
Participant manual contains over 450 pages of information and practical examples
A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued to the participants
In case of failure of the exam, participants are allowed to retake it for free under certain conditions

For additional information,
please contact us at info@pecb.org

www.pecb.org

PECB

Certified
ISO 27034
Lead Auditor

Weitere ähnliche Inhalte

Was ist angesagt?

ISO 50001 Lead Auditor – Four Page Brochure
ISO 50001 Lead Auditor – Four Page Brochure	ISO 50001 Lead Auditor – Four Page Brochure
ISO 50001 Lead Auditor – Four Page Brochure
PECB
 

Was ist angesagt? (16)

ISO 17025 Lead Auditor - Two Page Brochure
ISO 17025 Lead Auditor - Two Page Brochure	ISO 17025 Lead Auditor - Two Page Brochure
ISO 17025 Lead Auditor - Two Page Brochure
 
ISO 17025 Lead Auditor - One Page Brochure
ISO 17025 Lead Auditor - One Page BrochureISO 17025 Lead Auditor - One Page Brochure
ISO 17025 Lead Auditor - One Page Brochure
 
Certified OHSAS-18001-Lead-Auditor.>>> CAIRO IN JULY19,2015
Certified OHSAS-18001-Lead-Auditor.>>> CAIRO IN JULY19,2015Certified OHSAS-18001-Lead-Auditor.>>> CAIRO IN JULY19,2015
Certified OHSAS-18001-Lead-Auditor.>>> CAIRO IN JULY19,2015
 
ISO 13053 Lead Auditor - Two Page Brochure
ISO 13053 Lead Auditor - Two Page Brochure	ISO 13053 Lead Auditor - Two Page Brochure
ISO 13053 Lead Auditor - Two Page Brochure
 
ISO 50001 Lead Auditor – Four Page Brochure
ISO 50001 Lead Auditor – Four Page Brochure	ISO 50001 Lead Auditor – Four Page Brochure
ISO 50001 Lead Auditor – Four Page Brochure
 
ISO 20121 Lead Auditor - Two Page Brochure
ISO 20121 Lead Auditor - Two Page Brochure	ISO 20121 Lead Auditor - Two Page Brochure
ISO 20121 Lead Auditor - Two Page Brochure
 
Certified ISO 22000 Lead Auditor - Two Page Brochure
Certified ISO 22000 Lead Auditor - Two Page BrochureCertified ISO 22000 Lead Auditor - Two Page Brochure
Certified ISO 22000 Lead Auditor - Two Page Brochure
 
ISO 22301 Lead Auditor – Two Page Brochure
ISO 22301 Lead Auditor – Two Page BrochureISO 22301 Lead Auditor – Two Page Brochure
ISO 22301 Lead Auditor – Two Page Brochure
 
ISO 20121 Lead Auditor - One Page Brochure
ISO 20121 Lead Auditor - One Page Brochure	ISO 20121 Lead Auditor - One Page Brochure
ISO 20121 Lead Auditor - One Page Brochure
 
ISO 13485 Lead Auditor - Two Page Brochure
ISO 13485 Lead Auditor - Two Page BrochureISO 13485 Lead Auditor - Two Page Brochure
ISO 13485 Lead Auditor - Two Page Brochure
 
ISO 13485 Lead Auditor - One Page Brochure
ISO 13485 Lead Auditor - One Page BrochureISO 13485 Lead Auditor - One Page Brochure
ISO 13485 Lead Auditor - One Page Brochure
 
ISO 50001 Lead Auditor - Two Page Brochure
ISO 50001 Lead Auditor - Two Page Brochure	ISO 50001 Lead Auditor - Two Page Brochure
ISO 50001 Lead Auditor - Two Page Brochure
 
ISO 13053 Lead Auditor - One Page Brochure
ISO 13053 Lead Auditor - One Page Brochure	ISO 13053 Lead Auditor - One Page Brochure
ISO 13053 Lead Auditor - One Page Brochure
 
2016-10_API-570
2016-10_API-5702016-10_API-570
2016-10_API-570
 
ISO 22301 Lead Auditor - One Page Brochure
ISO 22301 Lead Auditor - One Page BrochureISO 22301 Lead Auditor - One Page Brochure
ISO 22301 Lead Auditor - One Page Brochure
 
ISO 50001 Lead Auditor - One Page Brochure
ISO 50001 Lead Auditor - One Page Brochure	ISO 50001 Lead Auditor - One Page Brochure
ISO 50001 Lead Auditor - One Page Brochure
 

Ähnlich wie ISO 27034 Lead Auditor - Four Page Brochure

ISO 13485 Lead Auditor - Four Page Brochure
ISO 13485 Lead Auditor - Four Page Brochure	ISO 13485 Lead Auditor - Four Page Brochure
ISO 13485 Lead Auditor - Four Page Brochure
PECB
 
ISO 29001 Lead Auditor - Four Page Brochure
ISO 29001 Lead Auditor - Four Page Brochure	ISO 29001 Lead Auditor - Four Page Brochure
ISO 29001 Lead Auditor - Four Page Brochure
PECB
 

Ähnlich wie ISO 27034 Lead Auditor - Four Page Brochure (20)

ISO 27034 Lead Implementer - Four Page Brochure
ISO 27034 Lead Implementer - Four Page Brochure	ISO 27034 Lead Implementer - Four Page Brochure
ISO 27034 Lead Implementer - Four Page Brochure
 
ISO 21500 Lead Auditor - Four Page Brochure
ISO 21500 Lead Auditor - Four Page BrochureISO 21500 Lead Auditor - Four Page Brochure
ISO 21500 Lead Auditor - Four Page Brochure
 
ISO 22301 Lead Auditor - Four Page Brochure
ISO 22301 Lead Auditor - Four Page BrochureISO 22301 Lead Auditor - Four Page Brochure
ISO 22301 Lead Auditor - Four Page Brochure
 
Iso9001leadauditor fourpage-131129094738-phpapp01
Iso9001leadauditor fourpage-131129094738-phpapp01Iso9001leadauditor fourpage-131129094738-phpapp01
Iso9001leadauditor fourpage-131129094738-phpapp01
 
Certified ISO 22000 Lead Auditor - Two Page Brochure
Certified ISO 22000 Lead Auditor - Two Page BrochureCertified ISO 22000 Lead Auditor - Two Page Brochure
Certified ISO 22000 Lead Auditor - Two Page Brochure
 
Certified ISO 22000 Lead Auditor – Four Page Brochure
Certified ISO 22000 Lead Auditor – Four Page BrochureCertified ISO 22000 Lead Auditor – Four Page Brochure
Certified ISO 22000 Lead Auditor – Four Page Brochure
 
Certified ISO 22000 Lead Auditor - Four Page Brochure
Certified ISO 22000 Lead Auditor - Four Page BrochureCertified ISO 22000 Lead Auditor - Four Page Brochure
Certified ISO 22000 Lead Auditor - Four Page Brochure
 
ISO 13485 Lead Auditor - Four Page Brochure
ISO 13485 Lead Auditor - Four Page Brochure	ISO 13485 Lead Auditor - Four Page Brochure
ISO 13485 Lead Auditor - Four Page Brochure
 
ISO 21500 Lead Implementer - Four Page Brochure
ISO 21500 Lead Implementer - Four Page BrochureISO 21500 Lead Implementer - Four Page Brochure
ISO 21500 Lead Implementer - Four Page Brochure
 
ISO 17025 Lead Auditor - Four Page Brochure
ISO 17025 Lead Auditor - Four Page BrochureISO 17025 Lead Auditor - Four Page Brochure
ISO 17025 Lead Auditor - Four Page Brochure
 
ISO 39001 Lead Auditor - Four Page Brochure
ISO 39001 Lead Auditor - Four Page Brochure	ISO 39001 Lead Auditor - Four Page Brochure
ISO 39001 Lead Auditor - Four Page Brochure
 
ISO 22301 Lead Implementer - Four Page Brochure
ISO 22301 Lead Implementer - Four Page BrochureISO 22301 Lead Implementer - Four Page Brochure
ISO 22301 Lead Implementer - Four Page Brochure
 
ISO 29001 Lead Auditor - Four Page Brochure
ISO 29001 Lead Auditor - Four Page Brochure	ISO 29001 Lead Auditor - Four Page Brochure
ISO 29001 Lead Auditor - Four Page Brochure
 
ISO 29001 Lead Auditor - Two Page Brochure
ISO 29001 Lead Auditor - Two Page Brochure	ISO 29001 Lead Auditor - Two Page Brochure
ISO 29001 Lead Auditor - Two Page Brochure
 
Certified ISO 22000 Lead Implementer – Four Page Brochure
Certified ISO 22000 Lead Implementer –  Four Page BrochureCertified ISO 22000 Lead Implementer –  Four Page Brochure
Certified ISO 22000 Lead Implementer – Four Page Brochure
 
Certified ISO 22000 Lead Implementer – Four Page Brochure
Certified ISO 22000 Lead Implementer –  Four Page BrochureCertified ISO 22000 Lead Implementer –  Four Page Brochure
Certified ISO 22000 Lead Implementer – Four Page Brochure
 
ISO 27001 Lead Auditor with Net Security Training
ISO 27001 Lead Auditor with Net Security Training ISO 27001 Lead Auditor with Net Security Training
ISO 27001 Lead Auditor with Net Security Training
 
ISO 27034 Lead Implementer - One Page Brochure
ISO 27034 Lead Implementer - One Page Brochure	ISO 27034 Lead Implementer - One Page Brochure
ISO 27034 Lead Implementer - One Page Brochure
 
ISO 17025 Lead Implementer - Four Page Brochure
ISO 17025 Lead Implementer - Four Page Brochure	ISO 17025 Lead Implementer - Four Page Brochure
ISO 17025 Lead Implementer - Four Page Brochure
 
Certified iso-9001-lead-auditor
Certified iso-9001-lead-auditorCertified iso-9001-lead-auditor
Certified iso-9001-lead-auditor
 

Mehr von PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
PECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
PECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
PECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
PECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
PECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
PECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
PECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
PECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 

Mehr von PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Kürzlich hochgeladen

The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
heathfieldcps1
 

Kürzlich hochgeladen (20)

Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Advance Mobile Application Development class 07
Advance Mobile Application Development class 07Advance Mobile Application Development class 07
Advance Mobile Application Development class 07
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptx
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 

ISO 27034 Lead Auditor - Four Page Brochure

  • 1. CERTIFIED ISO 27034 LEAD AUDITOR MASTERING THE AUDIT OF IT - SECURITY TECHNIQUES – APPLICATION SECURITY BASED ON ISO 27034, IN COMPLIANCE WITH THE REQUIREMENTS OF ISO 19011 AND ISO 17021 SUMMARY This five-day intensive course enables the participants develop the necessary expertise to audit an Information technology - Security techniques – Application Security as specified in ISO/IEC 27034, and manage a team of auditors by applying widely recognized audit principles, procedures and techniques. During this training, the participant will acquire the necessary knowledge and skills to proficiently plan and perform internal and external audits in compliance with ISO 19011 and ISO 17021. Based on practical exercises, the participant will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary for efficient conduct of an audit. COURSE AGENDA DURATION: 5 DAYS DAY 1 Introduction to IT - Security techniques – Application Security overview and concepts as required by ISO 27034 ▶▶ ormative, regulatory and legal framework related to N application security ▶▶ undamental principles of Application Security F ▶▶ SO 27034 certification process I ▶▶ T - Security Techniques – Application Security I ▶▶ etailed presentation of the clauses of ISO 27034 D DAY 3 Conducting an ISO 27034 audit ▶▶ ommunication during the audit C ▶▶ udit procedures: observation, document review, A interview, sampling techniques, technical verification, corroboration and evaluation ▶▶ udit test plans A ▶▶ ormulation of the audit findings F ▶▶ ocumenting nonconformities D DAY 5 DAY 2 Planning and initiating an ISO 27034 audit ▶▶ ▶▶ ▶▶ ▶▶ ▶▶ F undamental audit concepts and principles A udit the approach based on evidence and risk P reparation of an ISO 27034 audit A pplication Security documentation audit C onducting an opening meeting DAY 4 Concluding and ensuring the follow-up of an ISO 27034 audit ▶▶ udit documentation A ▶▶ uality review Q ▶▶ onducting a closing meeting and conclusion of an C ISO 27034 audit ▶▶ valuation of corrective action plans E ▶▶ SO 27034 surveillance audit I ▶▶ ISO 27034 internal audit management program Certification Exam www.pecb.org
  • 2. WHO SHOULD ATTEND? ▶▶ ▶▶ ▶▶ ▶▶ ▶▶ ▶▶ ▶▶ I nternal auditors A uditors wanting to perform and lead IT - Security techniques – Application Security audit Project managers or consultants who want to master the IT - Security techniques – Application Security audit process C xO and senior managers responsible for the IT governance of an enterprise and the management of its risks M embers of an information security team Expert advisors in Information Technology Technical experts wanting to prepare for Application Security audit function LEARNING OBJECTIVES ▶▶ o acquire the expertise needed to perform an ISO 27034 internal audit following the ISO 19011 guidelines T ▶▶ o acquire the expertise needed to perform an ISO 27034 audit following the ISO 19011 guidelines and the T specifications of ISO 17021 and ISO 27006 ▶▶ o acquire the necessary expertise to manage an IT - Application Security audit team T ▶▶ o understand the operation of an ISO 27034 conformant Application Security management system T ▶▶ o understand the relationship between an IT - Security techniques – Application Security, including risk T management, controls and compliance with the requirements of different stakeholders of the organization ▶▶ o improve the ability to analyze the internal and external environment of an organization, its risk assessment and T audit decision-making PECB www.pecb.org Certified ISO 27034 Lead Auditor
  • 3. EXAMINATION ▶▶ The “Certified ISO 27034 Lead Auditor” exam fully meets the requirements of the PECB Examination and Certification Program (ECP). The exam covers the following competence domains: DOMAIN 1: FUNDAMENTAL PRINCIPLES AND CONCEPTS IN APPLICATION SECURITY 1 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and illustrate the main Application Security concepts related to an Information Technology Application Security (AS) DOMAIN 2: INFORMATION TECHNOLOGY APPLICATION SECURITY (AS) 2 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and illustrate the main concepts and components of an Information Technology Application Security based on ISO 27034 DOMAIN 3: FUNDAMENTAL AUDIT CONCEPTS AND PRINCIPLES 3 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can understand, interpret and apply the main concepts and principles related to an AS audit in the context of ISO 27034 DOMAIN 4: PREPARATION OF AN ISO 27034 AUDIT 4 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can prepare appropriately an AS audit in the context of ISO 27034 DOMAIN 5: CONDUCT OF AN ISO 27034 AUDIT 5 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can conduct efficiently an AS audit in the context of ISO 27034 DOMAIN 6: CONCLUSION AND FOLLOW-UP OF AN ISO 27034 AUDIT 6 Main Objective: To ensure that the ISO 27034 Lead Auditor candidate can conclude an AS audit and conduct follow-up activities in the context of ISO 27034 DOMAIN 7: MANAGEMENT OF AN ISO 27034 AUDIT PROGRAM 7 Main Objective: To ensure that the ISO 27034 Lead Auditor understands how to establish and manage an AS audit program ▶▶ The “Certified ISO/IEC 27034 Lead Auditor” exam is available in different languages, including English, French, Spanish and Portuguese ▶▶ Duration: 3 hours ▶▶ For more information about the exam, please visit: www.pecb.org www.pecb.org
  • 4. CERTIFICATION ▶▶ fter successfully completing the exam, participants can apply for the credentials of Certified ISO/IEC 27034 A Provisional Auditor, Certified ISO/IEC 27034 Auditor or Certified ISO/IEC 27034 Lead Auditor depending on their level of experience. Those credentials are available for internal and external auditors ▶▶ A certificate will be issued to those participants who successfully pass the exam and comply with all the other requirements related to the selected credential: Credential Exam Professional Experience ITST Audit Experience ITST Project Experience Other Requirements ISO 27034 Provisional Auditor ISO 27034 Lead Auditor Exam None None None Signing the PECB code of ethics ISO 27034 Auditor ISO 27034 Lead Auditor Exam Two years One year of Information Technology Security Techniques work experience Audit activities totaling 200 hours None Signing the PECB code of ethics ISO 27034 Lead Auditor ISO 27034 Lead Auditor Exam Five years Two years of Information Technology Security Techniques work experience Audit activities totaling 300 hours None Signing the PECB code of ethics GENERAL INFORMATION ▶▶ ▶▶ ▶▶ ▶▶ Certification fees are included in the exam price Participant manual contains over 450 pages of information and practical examples A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued to the participants In case of failure of the exam, participants are allowed to retake it for free under certain conditions For additional information, please contact us at info@pecb.org www.pecb.org PECB Certified ISO 27034 Lead Auditor