ISO/IEC 27001:2022 & ISO 19011:2026 Auditor Training – Internal Auditor and ISMS Auditor Skills
ISO/IEC 27001:2022 & ISO 19011:2026 Auditor Training is designed for professionals who need to develop practical competence in auditing an Information Security Management System (ISMS), including ISO/IEC 27001:2022 Internal Auditors, ISMS Auditors, Information Security Managers, IT Security Professionals, Compliance Officers and professionals responsible for information security audits.
The course combines the requirements of ISO/IEC 27001:2022 Information Security Management Systems – Requirements with the auditing principles, audit programme management and audit techniques provided by ISO 19011:2026 Guidelines for Auditing Management Systems.
ISO/IEC 27001:2022 defines the requirements an ISMS must meet, while ISO 19011:2026 provides a structured framework for planning and conducting management system audits, including audit principles, audit programme management, audit activities and auditor competence.
For organizations managing confidential information, customer data, intellectual property, cloud services, information technology infrastructure and cybersecurity risks, an effective ISMS audit should go beyond checking whether policies and procedures exist. Auditors need to evaluate whether information security risks are identified, controls are implemented, evidence is available and the ISMS is effectively maintained.
VINTECOM International provides ISO/IEC 27001:2022 Auditor Training combined with ISO 19011:2026 auditing skills, with a practical approach to ISMS auditing, risk-based auditing, evidence-based auditing, interview techniques, control verification, nonconformity reporting and corrective-action evaluation.
1. What Is ISO/IEC 27001:2022 Auditor Training?
ISO/IEC 27001:2022 Auditor Training develops the knowledge and practical skills required to audit an Information Security Management System against the requirements of ISO/IEC 27001:2022.
ISO/IEC 27001:2022 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an ISMS. It is designed to help organizations manage information security risks affecting information they own or handle.
An ISO/IEC 27001:2022 Internal Auditor should be able to:
- Understand the structure and requirements of ISO/IEC 27001:2022.
- Understand the organization's ISMS scope.
- Understand information security risks and risk treatment.
- Identify applicable audit criteria.
- Prepare an ISMS audit plan.
- Conduct process-based and risk-based audits.
- Collect and verify objective evidence.
- Interview personnel responsible for information security.
- Evaluate the implementation of information security controls.
- Identify conformity and nonconformity.
- Record clear and evidence-based audit findings.
- Evaluate corrective actions.
- Prepare an audit report.
- Follow up on corrective actions and audit results.
The objective is therefore not simply to teach auditors how to complete an ISO 27001 checklist. The objective is to develop the ability to determine whether the organization's ISMS is implemented, maintained and effective within its defined scope.
2. What Is ISO 19011:2026 and Why Is It Important for ISMS Auditors?
ISO 19011:2026 – Guidelines for Auditing Management Systems provides guidance on auditing management systems, including audit principles, management of audit programmes, conducting audits and evaluating the competence of individuals involved in the audit process.
The 2026 edition is particularly relevant to modern audit environments because it addresses developments such as technology, digitization and virtual environments and places increased focus on risk analysis and mitigation.
For an ISMS auditor, this is highly relevant because information security audits frequently involve:
- Cloud-based systems.
- Remote working.
- Digital records.
- Information technology infrastructure.
- Access management systems.
- Security monitoring platforms.
- Electronic evidence.
- Virtual interviews.
- Remote audits.
- Cybersecurity-related risks.
ISO 19011:2026 should therefore be used as an auditing methodology framework, while ISO/IEC 27001:2022 provides the principal ISMS requirements against which conformity may be evaluated.
3. ISO/IEC 27001:2022 and ISO 19011:2026 – How Do They Work Together?
The relationship can be summarized as:
ISO/IEC 27001:2022 → What the ISMS is required to achieve
ISO 19011:2026 → How the management system audit is planned and conducted
For example, when auditing information security risk management:
ISO/IEC 27001 requirement → Audit criteria
Organizational process → Audit trail
Records and evidence → Evidence evaluation
Auditor evaluation → Audit finding
Corrective action → Follow-up and effectiveness evaluation
This combination gives auditors both the technical management-system criteria and the structured auditing methodology needed to conduct an effective ISMS audit.
4. Understanding the ISO/IEC 27001:2022 ISMS
Before conducting an audit, auditors need to understand the organization's information security management framework.
Important areas include:
- Organizational context.
- Interested parties.
- ISMS scope.
- Information security objectives.
- Information security policy.
- Risk assessment.
- Risk treatment.
- Statement of Applicability.
- Information security controls.
- Operational planning.
- Performance evaluation.
- Internal audit.
- Management review.
- Corrective action.
- Continual improvement.
An ISMS audit should consider the relationship between these elements rather than treating each requirement as an isolated checklist item.
For example:
Information asset → Risk → Risk treatment → Control → Implementation → Monitoring → Evidence → Performance evaluation
This is the type of audit trail that helps an auditor evaluate whether the ISMS operates as an integrated management system.
5. ISMS Scope and Audit Scope
An auditor must understand the defined ISMS scope before starting the audit.
The scope may include:
- Specific business units.
- Offices.
- Data centers.
- Cloud services.
- IT infrastructure.
- Software development.
- Customer information.
- Personal information.
- Production systems.
- Corporate information systems.
- Outsourced services.
The auditor should verify that the audit activities correspond to the established scope and applicable audit criteria.
A common audit problem is reviewing isolated IT controls without understanding how they relate to the organization's defined ISMS.
A competent ISMS auditor therefore asks:
What information and processes are within the ISMS scope?
What risks are relevant to those activities?
Which controls have been selected?
How are those controls implemented and monitored?
6. Information Security Risk-Based Auditing
Risk-based auditing is particularly important for an ISMS.
Auditors should understand how the organization:
- Identifies information security risks.
- Analyzes risks.
- Evaluates risks.
- Determines risk treatment.
- Selects appropriate controls.
- Implements controls.
- Monitors treatment effectiveness.
- Reviews risks when circumstances change.
An auditor should not simply verify that a risk register exists.
The audit should trace actual evidence.
For example:
Asset → Threat/Vulnerability → Risk → Risk Evaluation → Treatment → Control → Implementation → Monitoring
The auditor can then determine whether the organization's risk management process is operating as intended.
7. Auditing the Statement of Applicability
The Statement of Applicability (SoA) is an important element of an ISO/IEC 27001 ISMS.
During an audit, the auditor may need to examine the relationship between:
- Information security risks.
- Risk treatment decisions.
- Selected controls.
- Excluded controls and justification where applicable.
- Control implementation status.
- Supporting evidence.
The auditor should avoid treating the SoA as merely a document to be checked.
Instead, the audit should establish whether the SoA is consistent with the organization's risk treatment process and actual ISMS implementation.
8. Auditing Information Security Controls
An ISMS auditor needs to evaluate controls according to the organization's defined criteria and implementation context.
Potential audit areas may include:
Access control
- User access authorization.
- Privileged access.
- Access reviews.
- Authentication.
- Password management.
- User lifecycle management.
Asset management
- Asset identification.
- Asset ownership.
- Classification.
- Acceptable use.
- Asset lifecycle.
Human resource security
- Security responsibilities.
- Awareness.
- Competence.
- Joiner/mover/leaver processes.
- Confidentiality requirements.
Physical security
- Physical access.
- Secure areas.
- Equipment protection.
- Environmental controls.
Operational security
- Malware protection.
- Backup.
- Logging.
- Monitoring.
- Change management.
- Vulnerability management.
Communications security
- Network security.
- Information transfer.
- Segmentation.
- Secure communication.
Supplier security
- Supplier requirements.
- Security clauses.
- Supplier monitoring.
- Outsourced services.
- Cloud service security.
Incident management
- Incident reporting.
- Incident response.
- Investigation.
- Lessons learned.
- Evidence preservation.
Business continuity and information security
- Continuity planning.
- Recovery arrangements.
- Testing.
- Availability of critical information and systems.
The auditor should evaluate the controls in relation to the organization's actual risks and ISMS scope rather than treating the controls as isolated technical requirements.
9. Evidence-Based ISMS Auditing
One of the most important skills developed in the course is evidence-based auditing.
A statement such as:
“Our information is secure.”
is not audit evidence.
The auditor needs to identify objective evidence that supports the conclusion.
Examples include:
- Access control records.
- User access review records.
- Risk assessment records.
- Risk treatment plans.
- Security incident records.
- Backup logs.
- Vulnerability assessment results.
- Security monitoring records.
- Training records.
- Supplier evaluation records.
- Internal audit reports.
- Management review records.
- Corrective action records.
ISO 19011:2026 explicitly identifies the evidence-based approach as one of its auditing principles.
The auditor should therefore distinguish between:
Claim → Evidence → Verification → Audit conclusion
10. ISMS Audit Interview Techniques
Interviewing is a critical skill for an internal ISMS auditor.
Instead of asking only:
“Do you have an access control procedure?”
the auditor can ask:
“Please show me how access is requested, approved, provisioned, reviewed and removed.”
This allows the auditor to follow an actual audit trail.
Useful questions include:
- Who approves access?
- What determines the level of access?
- How is privileged access controlled?
- How are terminated users removed from systems?
- How frequently are access rights reviewed?
- What happens when unauthorized access is detected?
- How are security incidents reported?
- How is backup effectiveness verified?
- How are suppliers evaluated for information security risks?
- How are changes to information systems controlled?
The auditor should then verify the answers against objective evidence.
11. Auditing Digital and Remote Environments
Modern ISMS audits increasingly involve digital systems and remote working environments.
Examples include:
- Microsoft 365.
- Cloud infrastructure.
- SaaS platforms.
- VPN.
- Remote access.
- Cloud storage.
- ERP systems.
- SIEM platforms.
- Endpoint protection.
- Identity and access management systems.
ISO 19011:2026 specifically recognizes the changing audit environment associated with technology, digitization and virtual environments.
Therefore, ISMS auditor training should address questions such as:
- How should remote audit evidence be verified?
- How can an auditor maintain confidentiality during a remote audit?
- How should electronic records be sampled?
- How can audit trails be followed through digital systems?
- What limitations may exist when evidence is reviewed remotely?
- How should audit risks associated with virtual environments be considered?
12. Nonconformity Identification for ISO/IEC 27001:2022
An ISMS auditor needs to write findings based on objective evidence.
A useful structure is:
Requirement + Objective Evidence + Gap
For example:
Requirement: The organization has defined requirements for periodic review of user access rights.
Objective evidence: During the audit, access review records for the selected application were examined. Evidence of the required review could not be demonstrated for the sampled review period.
Gap: The available evidence does not demonstrate that the defined access review activity was consistently implemented for the sampled period.
This provides a more useful basis for corrective action than a general statement such as:
“Access control is not effective.”
The finding should be sufficiently specific for the organization to understand what was observed and why it does not meet the applicable audit criteria.
13. Root Cause and Corrective Action in ISMS Audits
ISMS auditors also need to evaluate corrective actions.
For example:
Finding: Periodic access review was not demonstrated.
Possible correction:
- Complete the overdue review.
But the auditor should also consider:
Why was the review missed?
Possible underlying causes might include:
- Undefined responsibility.
- Inadequate workflow.
- Missing automated reminder.
- Incomplete system ownership.
- Inadequate monitoring.
- Poor integration between HR and IT processes.
The corrective action should address the underlying cause where appropriate.
The auditor should then evaluate effectiveness rather than simply confirming that a corrective action document has been completed.
14. Internal ISMS Auditor Competence
An effective internal ISMS auditor requires several areas of competence.
ISO/IEC 27001 knowledge
Understanding:
- ISMS requirements.
- Risk assessment.
- Risk treatment.
- Information security objectives.
- Control implementation.
- Performance evaluation.
- Internal audit.
- Management review.
- Improvement.
Auditing competence
Understanding:
- Audit planning.
- Audit scope.
- Audit criteria.
- Evidence collection.
- Sampling.
- Interview techniques.
- Audit findings.
- Reporting.
- Corrective action.
Information security awareness
Depending on the audit scope, the auditor may need knowledge of:
- IT infrastructure.
- Access control.
- Network security.
- Cloud security.
- Data protection.
- Incident management.
- Backup.
- Vulnerability management.
- Supplier security.
- Business continuity.
The required depth should correspond to the audit objectives, scope and complexity.
15. ISO/IEC 27001:2022 Internal Auditor Training Program
A customized VINTECOM training programme may include the following modules.
Module 1 – Introduction to Information Security and ISMS
- Information security concepts.
- Confidentiality, integrity and availability.
- ISMS principles.
- ISO/IEC 27001 framework.
- Organizational context.
Module 2 – ISO/IEC 27001:2022 Requirements
- Context of the organization.
- Leadership.
- Planning.
- Support.
- Operation.
- Performance evaluation.
- Improvement.
Module 3 – Information Security Risk Management
- Risk identification.
- Risk analysis.
- Risk evaluation.
- Risk treatment.
- Risk acceptance.
- Risk monitoring.
- Risk review.
Module 4 – Statement of Applicability and Controls
- Control selection.
- Applicability.
- Implementation.
- Control evidence.
- Relationship between risks and controls.
Module 5 – ISO 19011:2026 Auditing Principles
- Integrity.
- Fair presentation.
- Due professional care.
- Confidentiality.
- Independence.
- Evidence-based approach.
- Risk-based approach.
These principles are explicitly included in ISO 19011:2026.
Module 6 – Audit Programme Management
- Audit programme objectives.
- Audit programme risks and opportunities.
- Audit planning.
- Auditor competence.
- Audit resources.
- Monitoring the audit programme.
- Continual improvement.
Module 7 – ISMS Audit Planning
- Audit objectives.
- Scope.
- Criteria.
- Audit plan.
- Sampling.
- Audit trails.
- Audit resources.
Module 8 – Conducting an ISMS Audit
- Opening meeting.
- Document review.
- Interviews.
- Observation.
- Evidence verification.
- Sampling.
- Audit trails.
- Closing meeting.
Module 9 – Audit Findings and Reporting
- Conformity.
- Nonconformity.
- Objective evidence.
- Finding statements.
- Audit conclusions.
- Audit reporting.
Module 10 – Corrective Action and Follow-Up
- Correction.
- Root cause analysis.
- Corrective action.
- Effectiveness evaluation.
- Follow-up audit.
Module 11 – Practical ISMS Audit
- Case studies.
- Interview exercises.
- Evidence evaluation.
- Control verification.
- Nonconformity writing.
- Mock audit.
- Audit report preparation.
16. Who Should Attend ISO/IEC 27001:2022 & ISO 19011:2026 Auditor Training?
The course is suitable for:
- ISMS Managers.
- Information Security Managers.
- IT Managers.
- Cybersecurity Professionals.
- ISO 27001 Coordinators.
- Information Security Officers.
- Compliance Officers.
- Risk Managers.
- Internal Auditors.
- ISMS Internal Auditors.
- Management System Auditors.
- IT Auditors.
- Supplier Auditors.
- Consultants.
- Professionals responsible for ISO/IEC 27001 implementation.
It is especially relevant to organizations preparing for ISO/IEC 27001 certification, maintaining an existing ISMS or strengthening their internal audit capability.
17. ISO/IEC 27001 Internal Auditor vs. ISMS Auditor
The terms are related but can be used in different contexts.
An ISO/IEC 27001 Internal Auditor generally audits the organization's internal ISMS against defined criteria.
An ISMS Auditor is a broader term describing an auditor who conducts audits of information security management systems.
Depending on the organization and audit purpose, ISMS auditing may include:
- First-party internal audits.
- Second-party supplier audits.
- External audit preparation.
- Management system audit activities.
The audit criteria, auditor competence and audit objectives should always be defined for the specific assignment.
18. ISO 19011:2026 Auditor Skills Applied to ISMS
ISO 19011:2026 provides general management-system auditing guidance rather than being an ISO/IEC 27001-specific certification standard.
For ISMS audits, its principles can be applied together with the specific requirements of ISO/IEC 27001:2022.
The practical audit sequence can therefore be understood as:
1. Define audit objectives
↓
2. Define scope and criteria
↓
3. Understand ISMS risks and processes
↓
4. Prepare audit plan
↓
5. Conduct interviews and collect evidence
↓
6. Follow audit trails
↓
7. Evaluate evidence against criteria
↓
8. Record findings
↓
9. Prepare audit conclusions
↓
10. Report and follow up
This approach helps auditors maintain a consistent and evidence-based audit process.
19. Practical ISO/IEC 27001 Auditor Training at VINTECOM
VINTECOM International's training approach can combine standard interpretation with practical auditing exercises.
Depending on the organization's requirements, training may include:
Case-based learning
Participants analyze realistic ISMS situations.
Audit interview simulation
Participants practice interviewing:
- IT personnel.
- System owners.
- Information security officers.
- HR personnel.
- Procurement personnel.
- Management.
- External service providers.
Evidence evaluation
Participants determine whether information provided by the auditee is sufficient to support an audit conclusion.
Control audit exercises
Participants examine how selected information security controls are implemented.
Nonconformity writing
Participants practice writing evidence-based audit findings.
Corrective action review
Participants assess whether proposed actions address the underlying cause and whether effectiveness can be demonstrated.
Mock ISMS audit
Participants conduct an audit from planning through reporting.
20. ISO/IEC 27001:2022 Auditor Training for FDI and Global Supply Chains
For FDI companies and organizations participating in global supply chains, information security requirements increasingly extend beyond internal IT operations.
Organizations may need to manage information security risks involving:
- Customers.
- Suppliers.
- Cloud providers.
- Software vendors.
- Outsourced IT services.
- Engineering partners.
- Manufacturing partners.
- Logistics providers.
- Business partners.
Supplier and second-party auditing can therefore become an important part of the organization's information security assurance programme.
An auditor may need to examine:
Supplier requirement → Security risk → Contractual requirement → Control → Evidence → Monitoring → Corrective action
This approach can be particularly relevant for organizations handling confidential engineering information, customer information, product data, intellectual property or commercially sensitive information.
21. ISO/IEC 27001:2022, ISO 19011:2026 and ISO/IEC 27002:2022
These standards and guidance documents should not be confused.
|
Document
|
Main purpose
|
|
ISO/IEC 27001:2022
|
Requirements for an Information Security Management System
|
|
ISO/IEC 27002:2022
|
Reference set of information security controls and implementation guidance
|
|
ISO 19011:2026
|
Guidelines for auditing management systems
|
ISO identifies ISO/IEC 27001:2022 as the ISMS requirements standard and ISO/IEC 27002:2022 as a reference set of information security controls with implementation guidance.
This distinction is important when designing an auditor training programme.
The auditor should know:
What is the audit criterion?
What information security controls are relevant?
What evidence demonstrates implementation?
How should the evidence be evaluated?
How should findings be reported?
22. Why Combine ISO/IEC 27001:2022 and ISO 19011:2026 in One Training Course?
A combined programme can connect three levels of competence:
Level 1 – ISMS requirements
Participants understand what ISO/IEC 27001:2022 requires.
Level 2 – Information security implementation
Participants understand how requirements and controls can be implemented in organizational processes.
Level 3 – Auditing competence
Participants learn how to plan, conduct, document and follow up an audit using ISO 19011:2026 principles and methods.
This creates a practical learning chain:
ISO/IEC 27001 knowledge → ISMS understanding → Audit competence → Evidence evaluation → Audit conclusion
23. Frequently Asked Questions – ISO/IEC 27001:2022 & ISO 19011:2026 Auditor Training
What is ISO/IEC 27001:2022 Auditor Training?
It is training designed to develop the knowledge and practical auditing skills needed to evaluate an Information Security Management System against ISO/IEC 27001:2022 requirements.
What is ISO 19011:2026?
ISO 19011:2026 is an international standard providing guidelines for auditing management systems, including audit principles, audit programme management, audit activities and auditor competence.
Is ISO 19011:2026 a certification standard?
No. ISO 19011:2026 provides auditing guidance. It does not itself establish requirements for certification of an organization.
Can ISO 19011:2026 be used for ISO/IEC 27001 audits?
Yes. Its general management-system auditing guidance can be applied to ISMS audits, while ISO/IEC 27001:2022 provides the specific ISMS requirements used as audit criteria.
What is an ISO 27001 Internal Auditor?
An ISO 27001 Internal Auditor is a person who conducts first-party audits of an organization's ISMS against defined audit criteria.
What is an ISMS Auditor?
An ISMS Auditor is an auditor who evaluates an Information Security Management System. Depending on the assignment, this may involve internal, supplier or other management-system audit activities.
Does the course include information security controls?
Yes. A customized programme can include auditing of relevant information security controls, risk treatment, access control, asset management, supplier security, incident management, backup, physical security and other applicable areas.
Does the course include practical audit exercises?
Yes. The programme can include audit interviews, evidence evaluation, audit trails, control verification, nonconformity writing, corrective-action evaluation and mock ISMS audits.
Who should attend ISO 27001 Internal Auditor Training?
The course is suitable for ISMS managers, information security professionals, IT and cybersecurity personnel, ISO coordinators, compliance professionals, internal auditors, risk managers and personnel responsible for maintaining or auditing an ISMS.
24. VINTECOM ISO/IEC 27001:2022 Auditor Training and Consulting
VINTECOM International provides ISO/IEC 27001:2022 Training, ISMS Consulting and Auditor Training, with programmes that can be customized according to the organization's information security environment.
Training and consulting can be designed for:
- ISO/IEC 27001:2022 implementation.
- ISO 27001 Internal Auditor Training.
- ISMS Auditor Training.
- ISO 19011:2026 Auditor Skills.
- Information security risk assessment.
- ISMS internal audit.
- Supplier security audit.
- Second-party audit.
- Audit programme development.
- Corrective action evaluation.
- Certification audit preparation.
Depending on the customer's requirements, the programme can be delivered as:
- In-house training.
- On-site training.
- Online training.
- Customized corporate training.
- Combined training and consulting.
- Practical internal audit programme.
25. Registration – Quotation
Organizations interested in ISO/IEC 27001:2022 Auditor Training, ISO 27001 Internal Auditor Training, ISMS Auditor Training or ISO 19011:2026 Auditor Skills Training can contact VINTECOM International for a customized programme and quotation.
VINTECOM can develop the course according to:
- Industry.
- ISMS scope.
- Number of participants.
- Existing ISMS maturity.
- Information security risks.
- IT infrastructure.
- Cloud environment.
- Supplier structure.
- Customer requirements.
- Internal audit objectives.
The training can combine ISO/IEC 27001:2022 requirements, information security risk management, control auditing and ISO 19011:2026 audit techniques into one practical programme.
26. Contact VINTECOM International
📶 Register for a Training Course Quotation for ISO 27001: 2022 and ISO 19011: 2026 Standards
Customers, organizations, and businesses interested in receiving a quotation for training course for ISO/IEC 27001:2022 and ISO 19011: 2026 are invited to contact VINTECOM International to discuss a suitable consulting solution.
Click the [Registration - Quotation] button at the bottom-right corner of the screen to register and receive a quotation promptly.
🎁🎁🎁 Enjoy 5% discount on training and consulting fees when registering online!
📶📶📶 Further information, Please contact us as below:
☎ VINTECOM International Office in Ha Noi City: 16th Floor - Green Stars City, 234 Pham Van Dong Street, Phu Dien Ward, Ha Noi City. Hotline 094-886-5288/ (024) 730-588-58
☎ VINTECOM International Office in Ho Chi Minh City: Glory Height Vinhome Grand Park - Long Binh Ward, Ho Chi Minh City. Hotline 0938-083-998/ (028) 7300-7588
VINTECOM INTERNATIONAL MANAGEMENT CONSULTANCY COMPANY
Head Office: No. 5 Hoang Sam treet, Nghia Do, Cau Giay district, Ha noi City
HANOI VINTECOM INTERNATIONAL OFFICE
Address: 16th Floor - Green Stars City
234 Pham Van Dong Street, Phu Dien Ward, Hanoi City
Tel : (024) 730.588.58/ (024) 730.333.86
Hotline: 094 886 5288
Skype: kd.vintecom
Email : office-hn@vintecom.com.vn
Web : www.vintecom.com.vn
HCM VINTECOM INTERNATIONAL OFFICE
Address : Glory Heights - Vinhomes Grand Park
88 Phuoc Thien Street, Long Binh Ward, Ho Chi Minh City
Contact: Ms. Pham Thu Ha
Tel: (028) 7300 7588
Hotline: 0938 083 998
Email : office-hcm@vintecom.com.vn
Web : www.vintecom.com.vn