Professional track

ISO/IEC 27001 Auditor

Develop the skills to plan, conduct and evaluate audits against ISO/IEC 27001 in real organisational contexts

AuditorInformation SecurityISO/IEC 27001
ISO/IEC 27001 auditor reviewing information security controls with an IT colleague in a data centre environment.

Auditing information security beyond control checklists

A modular training programme for information security auditors. Learn to audit ISO/IEC 27001 Information Security Management Systems based on risk, controls and evidence, not checklists alone.

Overview

What this track is about

A modular training programme that prepares you to conduct internal audits of an Information Security Management System (ISMS) against ISO/IEC 27001. Learn to evaluate controls, risks and processes effectively and support continual improvement of information security.

The ISO/IEC 27001 Auditor Track is designed for professionals responsible for auditing Information Security Management Systems (ISMS). It goes beyond clause-by-clause interpretation and teaches how to audit an ISMS holistically, using evidence-based and risk-focused methods.

The track covers the full audit life cycle and enables effective ISMS audits in internal auditing, supplier auditing as well as third-party auditing contexts.

Audience

Who it is for

The ISO 27001 Auditor Track equips professionals to plan, conduct, and report audits of Information Security Management Systems (ISMS) against the requirements of ISO 27001.

Current or aspiring internal, supplier, or third-party auditors who want to audit information security management systems against ISO/IEC 27001

Information security or risk professionals seeking to move into ISMS auditing roles

Auditors from other management system domains who want to expand their audit competence into information security

Practising ISO/IEC 27001 auditors who want to improve audit consistency, risk-based judgement, and handling of complex ISMS environments

Outcomes

Learning outcomes

4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.

01

Understand and interpret ISO/IEC 27001 requirements

Interpret ISO/IEC 27001 requirements consistently across different organisational contexts

Understand how ISMS are structured and applied in practice

02

Plan and conduct audits in a structured manner

Plan and perform internal, supplier and third-party ISMS audits in accordance with ISO 19011

Apply appropriate audit techniques to obtain objective and verifiable audit evidence

03

Evaluate conformity and audit findings professionally

Assess conformity of an ISMS against ISO/IEC 27001 requirements and defined audit criteria

Formulate clear, well-founded audit findings and nonconformities

04

Communicate audit results and support improvement

Communicate audit results professionally to auditees and management

Support improvement by providing clear, actionable audit feedback

Professional positioning

Build a recognised competence profile as an auditor for ISO/IEC 27001 across different organisational contexts

Assess information security management systems in a structured, independent and standard-compliant manner, and substantiate audit findings professionally

Act as a competent professional counterpart to organisations, management, certification bodies and other auditors

Credentials

Scalable credential model

Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.

Core credential

Diploma in Management System Auditing

Cross-domain management system foundation: the 17 core modules

Applicable across every ISO standard we teach

Reusable across every further specialisation in the same role

Specialisation credential

Halderstone Certified ISO/IEC 27001 Auditor

Fundamentals of information security management

Ability to audit ISO/IEC 27001-specific requirements

Registered credentials

Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.

How registered credentials work →
Registered credentials: Halderstone Certified ISO/IEC 27001 Auditor

The following Registered credentials can be applied for:

Registered Associate Auditor in ISO/IEC 27001 Auditing

Registered Professional Auditor in ISO/IEC 27001 Auditing

Registered Lead Auditor in ISO/IEC 27001 Auditing

Registered Senior Lead Auditor in ISO/IEC 27001 Auditing

Application requires meeting the experience requirements for the respective level.

For employers

How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.

View the credential framework →

Track price

CHF 8,500

All 20 modules, the capstone and the examination

approx. €8,940 · invoiced in CHFapprox. £7,460 · invoiced in CHFapprox. US$10,570 · invoiced in CHF

No VAT is charged.

Start with a single module at any time · credited in full if you continue

Bought from us before? Sign in to see the modules you already hold.

Track facts

Track ID
HAT-IS-A
ISO standard
ISO/IEC 27001

Modular approach

The core carries into every discipline

The 17 core modules are the same in every auditor track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about information security.

Core modules

Auditor capabilities across disciplines

17 modules · shared by every auditor track

Awarded as the Diploma in Management System Auditing: the credential you keep whichever discipline you specialise in.

A second auditor track is 2–4 modules, not 20

Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.

Compare the auditor tracks →

Curriculum

How the modules fit together

Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.

Core

Shared with every auditor track. Complete them once and they count towards any further qualification in the same role.

Any order
Management system core
HAM-AG-C-07Risk ManagementBuild the capability to surface, structure and act on risk while action is still possible
Audit core
HAM-AG-AC-01Audit PrinciplesApply evidence-based audit reasoning, materiality-focused prioritisation and structured audit test planningHAM-AG-AC-02Audit Communication & InterviewingPlan and conduct effective audit interviews, use structured questioning, and guide conversations to obtain reliable audit evidenceHAM-AG-AC-03Audit Reporting & Follow-upFormulate evidence-based audit findings, structure clear audit reports, and verify the effective closure of agreed actionsHAM-AG-AC-04Audit Programme ManagementDesign and govern risk-informed audit programmes across standards, group structures and programme-level reportingHAM-AG-AC-05Supplier AuditingPlan and conduct supplier audits using contract-based criteria, defined evidence targets and disciplined audit documentationHAM-AG-AC-06Third-Party AuditingNavigate accreditation, the certification ecosystem, the audit lifecycle, impartiality boundaries and certification decision interfaces
Management system auditing core
HAM-AG-A-01Auditing Context & ScopeAssess whether organisational context, interested parties, scope and system boundaries credibly reflect how the organisation operatesHAM-AG-A-02Auditing Leadership & GovernanceAssess whether leadership commitment, policy direction and governance structures credibly steer the management systemHAM-AG-A-03Auditing Risk & Opportunity ManagementAssess whether risk and opportunity management credibly informs organisational decisions and prioritiesHAM-AG-A-04Auditing Documented InformationAssess whether documented information is fit for use, internally consistent and credible as audit evidenceHAM-AG-A-05Auditing Objectives & Performance EvaluationAssess whether objectives and KPIs credibly measure and steer organisational performanceHAM-AG-A-06Auditing Operational ControlAssess whether operational controls and process interactions work reliably in day-to-day practiceHAM-AG-A-07Auditing Supplier & Outsourcing ManagementAssess whether supplier and outsourced process controls manage risk effectively and achieve intended outcomes across organisational boundariesHAM-AG-A-08Auditing Internal Audit & AssuranceAssess whether internal audit and related assurance mechanisms cover risk credibly and provide meaningful assuranceHAM-AG-A-09Auditing Management ReviewAssess whether management review credibly steers organisational priorities, risks and improvementHAM-AG-A-10Auditing Improvement ManagementAssess whether corrective action addresses nonconformities effectively and whether continual improvement strengthens performance beyond nonconformity response

ISO/IEC 27001 Auditing

These modules carry the same audit work into ISO/IEC 27001. The method does not change; the material does. What counts as evidence, which controls are worth sampling and where a system of this kind usually fails are specific to the standard. The aim is an audit of the system as it operates, not of the system as it is documented.

Any order

The capstone engagement

Practical application of the acquired auditing competencies

Demonstrates ability to audit an ISMS according to ISO/IEC 27001 in a real-world scenario

Based on case proposed by the candidate or provided by Halderstone

The final examination

Confirms solid and actionable understanding of information security management principles and ability to audit an ISMS based on ISO/IEC 27001

Covers all core and specialization modules of the track

Method

How you learn it

Two things separate knowing a standard from being able to audit a management system against it: what is trained, and what it is trained on.

Practical reflexes, not topics covered

Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.

Three examples from this track’s modules:

Real ownership and escalation

Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.

Residual exposure and explicit acceptance

See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.

Risk criteria and acceptance authority

Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.

Trained on one organisation

Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.

One organisation, carried across modules

Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.

It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones

Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in

Why it matters

Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.

How we teach →

Related track

The same discipline, the other role

The same discipline is taught from the manager’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.

Track price

CHF 8,500

20 modules, the capstone and the examination

Getting it signed off

Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.

Not sure this is the one?

Start with a single module and have it credited in full later. If the work is running and improving your own management system rather than assessing other people’s, the manager track is the one. Tell us the situation and we will say which, honestly.

Browse the modules →

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this track is the right one, or point you at a better fit.
About ISO/IEC 27001 Auditor Track · HAT-IS-A

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.