ISO 28000 Lead Auditor

ISO 28000 Lead Auditor Course

ISO 28000 Lead Auditor

Why should you attend?

The PECB ISO 28000 Lead Auditor training course enables you to develop the necessary competencies to perform security management system (SeMS) audits by applying widely recognized audit principles, procedures, and techniques. This training course integrates the ISO/IEC 17021-1 requirements, the ISO 19011 guidelines, and other best practices of auditing, in order to equip you with the necessary competencies for planning, conducting, and closing ISO 28000 conformity assessment audits successfully. 

Besides the theoretical basis, the training course also provides a hands-on approach by providing examples, exercises, and quizzes to reinforce your understanding of the key aspects of ISO 28000 conformity assessment audits, including the interpretation of ISO 28000 requirements in the context of an audit, the principles of auditing, the application of audit methods and approaches to evidence collection and verification, leading an audit team, drafting nonconformity reports, preparing the audit report, and following up on nonconformities.

After completing the training course, you can sit for the exam. If you successfully pass the exam, you can apply for the “PECB Certified ISO 28000 Lead Auditor” credential. The internationally recognized “PECB ISO 28000 Lead Auditor” certificate validates your professional expertise and demonstrates that you have the knowledge and skills to audit an SeMS based on ISO 28000.

Who should attend?

The ISO 28000 Lead Auditor training course is intended for:

  • Auditors seeking to perform and lead SeMS audits 
  • Individuals responsible for maintaining conformity to the ISO 28000 requirements
  • Technical experts seeking to prepare for an SeMS audit
  • Professionals wanting to pursue a career in management systems conformity assessments
  • Security management consultants 
  • Regulators responsible for ensuring compliance with security standards and regulations 
  • Management representatives seeking to master the SeMS audit process 

Learning objectives

By the end of this training course, the participants will be able to:

  • Explain the fundamental concepts and principles of a security management system based on ISO 28000
  • Interpret the ISO requirements of 28000 for a SeMS from the perspective of an auditor
  • Evaluate the SeMS conformity to ISO 28000 requirements by applying and utilizing widely recognized audit concepts and principles
  • Plan, conduct, and close an ISO 28000 conformity assessment audit, in accordance with the requirements of ISO/IEC 17021-1, the guidelines of ISO 19011, and other best practices of auditing
  • Manage an ISO 28000 audit program

Educational approach

This training course is participant centered and it:

  • Elaborates theories, approaches, and best practices used in SeMS audits 
  • Provides practical exercises which are based on scenarios inspired by real-life events 
  • Encourages interaction between the trainer and participants by means of questions and suggestions
  • Provides quizzes consisting of stand-alone and scenario-based questions, tailored to prepare the participants for the certification exam

Prerequisites

In order to fully benefit from this training course, participants should have a basic understanding of ISO 28000 and audit principles.


More Details

  • Day 1: Introduction to the security management system (SeMS) and ISO 28000

    Day 2: Audit principles and the preparation for and initiation of an audit

    Day 3: On-site audit activities

    Day 4: Closing of the audit

    Day 5: Certification exam

The “PECB Certified ISO 28000 Lead Auditor” exam fully meets the requirements of the PECB Examination and Certification Program (ECP). It covers the following competency domains:

Domain 1: Fundamental principles and concepts of a security management system

Domain 2: Security management system requirements

Domain 3: Fundamental audit concepts and principles

Domain 4: Preparing an ISO 28000 audit

Domain 5: Conducting an ISO 28000 audit 

Domain 6: Closing an ISO 28000 audit

Domain 7: Managing an ISO 28000 audit program

  • After successfully completing the exam, you can apply for one of the credentials shown on the table below. You will receive a certificate as soon as you fulfill all the requirements related to the selected credential. 

    The table below presents the requirements for PECB ISO 28000 Auditor certifications:

    CredentialExamProfessional experienceMS audit/assessment experienceOther requirements
    PECB Certified ISO 28000 Provisional AuditorPECB Certified ISO 28000 Lead Auditor Exam or equivalentNoneNoneSigning the PECB Code of Ethics
    PECB Certified ISO 28000 AuditorPECB Certified ISO 28000 Lead Auditor Exam or equivalentTwo years: One year of work experience in Supply Chain Security ManagementAudit activities: a total of 200 hoursSigning the PECB Code of Ethics
    PECB Certified ISO 28000 Lead AuditorPECB Certified ISO 28000 Lead Auditor Exam or equivalentFive years: Two years of work experience in Supply Chain Security ManagementAudit activities: a total of 300 hoursSigning the PECB Code of Ethics
    PECB Certified ISO 28000 Senior Lead AuditorPECB Certified ISO 28000 Lead Auditor Exam or equivalentTen years: Seven years of work experience in Supply Chain Security ManagementAudit activities: a total of 1,000 hoursSigning the PECB Code of Ethics

    Note: PECB Certified Individuals who do possess the Lead Implementer and Lead Auditor Credentials are qualified for the respective PECB Master Credential, given they have taken 4 additional Foundation Exams which are related to this scheme. 

    To be considered valid, the audit activities should follow best audit practices and include the following:

    1. Planning an audit
    2. Managing an audit program
    3. Drafting audit reports
    4. Drafting nonconformity reports
    5. Drafting audit working documents
    6. Reviewing documented information
    7. Conducting an on-site audit
    8. Following up on nonconformities
    9. Leading an audit team