ISO 27701 PIMS provides guidance to organizations in order to manage privacy controls so that the risk to the privacy rights of individuals can be reduced. ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 Information Security Management and ISO/IEC 27002 Security Controls.
ISO 27701 Certification helps organizations to manage personal data in line with customers' expectations and the regulatory requirements. Implementing ISO 27701 enables you to meet the highest standards of responsibility and transparency in the processing of personal information.
Why Should You Attend?
The ISO/IEC 27701 Lead Auditor training course is designed to equip you with the skills needed to perform effective Privacy Information Management System (PIMS) audits. The course covers widely recognized audit principles, procedures, and techniques necessary for assessing PIMS compliance.
You will learn to plan and execute audits following ISO 19011 guidelines and the ISO/IEC 17021-1 certification process. The course includes practical exercises to help you understand privacy protection in the context of processing personally identifiable information (PII). Additionally, you will master audit techniques, manage audit programs and teams, establish communication with clients, and handle potential conflicts.
Upon successful completion of the course and the exam, you can apply for the “PECB Certified ISO/IEC 27701 Lead Auditor” credential. This certification demonstrates your proficiency in auditing organizations based on best practices in privacy management.
Who Should Attend?
-
Auditors seeking to perform and lead PIMS certification audits
-
Managers or consultants aiming to master the PIMS audit process
-
Individuals responsible for maintaining conformance with PIMS requirements
-
Technical experts preparing for a PIMS audit
-
Expert advisors in the protection of Personally Identifiable Information (PII)
Learning Objectives
By the end of this training course, you will be able to:
-
Understand PIMS: Comprehend Privacy Information Management Systems (PIMS) and their processes based on ISO/IEC 27701.
-
Relate Standards: Identify the relationship between ISO/IEC 27701, ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks.
-
Audit Competencies: Acquire the skills necessary for the auditor's role in planning, leading, and following up on PIMS audits in accordance with ISO 19011.
-
Interpret Requirements: Learn to interpret the requirements of ISO/IEC 27701 within the context of a PIMS audit.
Educational Approach
-
Theory and Best Practices: The training combines theoretical concepts with best practices used in PIMS audits.
-
Case Studies and Examples: Lecture sessions are illustrated with practical examples and case studies.
-
Practical Exercises: Engage in practical exercises, including role-playing and discussions, based on real-world scenarios.
-
Exam Preparation: Take practice tests similar in format to the certification exam to ensure readiness.
Course Outline:
-
Standards and regulatory frameworks
-
Certification process
-
Fundamental information security and privacy concepts and principles
-
Privacy Information Management System (PIMS)
-
Fundamental audit concepts and principles
-
The impacts and trends of technology in auditing
-
Evidence-based auditing
-
Risk-based auditing
-
Initiation of the audit process
-
Stage 1 audit
-
Preparing for stage 2 audit
-
Stage 2 audit
-
Communication during the audit
-
Audit procedures
-
Creating audit test plans
-
Drafting audit findings and non-conformity reports
-
Audit documentation and quality review
-
Closing of the audit
-
Evaluation of action plans by the auditor
-
Beyond the initial audit
-
Managing an internal audit programme