- ISO 27001 lead auditor
The ISO 27001 Lead Auditor certification consists of a professional certification for auditors specializing in information security management systems (
ISMS ) based on theISO/IEC 27001 standard. This certification is provided mainly by two personnal certification bodies, theInternational Register of Certificated Auditors (IRCA) and the Registrar Accreditation Board - Quality Society of Australasia (RABQSA International ). Both organizations mutually recognize each other's certifications.The course consists generally of four days of training and a final exam of the fifth day.
The main benefit from achieving the ISO 27001 Lead Auditor certification is the recognition that the individual can conduct process-based audits competently against ISO 27001 for clients worldwide.
The main ISO 27001 auditor certifications are as follow:
* Provisional ISMS Auditor
* ISMS Auditor
* ISMS Internal Auditor
* Lead ISMS AuditorProvisional ISMS Auditor
The Provisional ISMS Auditor / Provisional Internal ISMS Auditor certification is for an individual who doesn't have enough experience to conduct audits. Requirements are:
* Secondary education (minimum)
* 5 years of work experience (or 4 years plus degree / near degree)
* 1 year of work experience - information security related
* Having successfully completed an ISMS foundation course and an ISMS auditor course
* No audit experienceISMS Auditor
The ISMS Auditor certification is for an individual with substantial audit experience but no experience in leading an audit. Requirements are:
* Secondary education (minimum)
* 5 years of work experience (or 4 years plus degree / near degree)
* 2 year of work experience - information security related
* Having successfully completed an ISMS foundation course and an ISMS auditor course
* Having completed at least 4 audits for a total duration of at least 20 days.ISMS Internal Auditor
The ISMS Internal Auditor certification is for an individual with substantial internal audit experience. Requirements are:
* Secondary education (minimum)
* 5 years of work experience (or 4 years plus degree / near degree)
* 1 year of work experience - information security related
* Having successfully completed an ISMS foundation course and an ISMS auditor course
* Having completed at least 5 audits for a total duration of at least 15 hours.Lead ISMS Auditor
The Lead ISMS Auditor is for an individual with substantial experience in leading an audit. Requirements are:
* Secondary education (minimum)
* 5 years of work experience (or 4 years plus degree / near degree)
* 2 year of work experience - information security related
* Having successfully completed an ISMS foundation course and an ISMS auditor course
* Having completed at least 4 audits for a total duration of at least 20 days, as well as 3 audits as a lead auditor for a total duration of at least 15 days.Other Auditors Grades
* Principal ISMS Auditor (RABQSA only)
* Business Improvement ISMS Auditor (RABQSA only)
* Principal auditor - consultant (IRCA only)
* Principal auditor - team leader (IRCA only)List of organizations providing RABQSA or IRCA certified ISO 27001 Lead Auditor courses
*
BSI Group
*Bureau Veritas
* SAI Global
* VeridionExternal links
* [http://www.rabqsa.com RABQSA]
* [http://www.irca.org IRCA]
* [http://www.bsi-global.com BSI]
* [http://www.bvqi.com Bureau Veritas]
* [http://www.sai-global.com SAI Global]
* [http://www.veridion.net Veridion]
Wikimedia Foundation. 2010.