ISO 27031 Auditor

Conducting ICT readiness system audits

Requirements:
  • ISO 27031 Foundation

Who is the course for

Porovnat s ostatními kurzy
  • Internal and external auditors of information security, BCM, or ICT services

  • Managers responsible for risk management, business continuity, or IT system recovery

  • ICT specialists involved in disaster recovery planning and assessing organizational preparedness

  • Consultants and implementers of ISO 27001/22301 systems

  • Persons responsible for supplier relationships, cloud services, and IT governance

What will you learn

More information
  • Apply the principles of auditing according to ISO 19011.
  • Understand the requirements of ISO/IEC 27031:2025 and their auditability.
  • Identify shortcomings and formulate recommendations for improving the IRBC system.
  • Link ICT continuity with BCMS (ISO 22301) and ISMS (ISO 27001) within the framework of an audit.
  • Plan, implement, and report on internal or external audits focused on ICT readiness.
  • Assess whether an organization effectively protects its ICT systems and is prepared for potential incidents and outages.

Terms

Currency
Term
Place
Length
Language
Price without VAT

No results match the specified filters

Loading...

Do you want this course individually?

Let us know!

This course can be customized - either as an individual training 1:1 or for your team. Just leave us your contact and we will contact you with options tailored to your needs.

Successfully sent

We will contact you.

Timeline

Day 1

09:00 – 16:30 Introduction
  • Introduction to ICT Readiness for Business Continuity (IRBC)
Overview and key requirements
  • Context and purpose of the standard
  • Key chapters: planning, operation, improvement
  • New features in version 2025 (compared to version 2011)
  • Relationship to ISO 22301 (BCMS) and ISO 27001 (ISMS)
ISO 19011:2018 – audit guidelines
  • Auditing principles, role of the auditor
  • Planning and managing the audit program
  • Risk-based and evidence-based audit approach
  • Ethical principles and independence
IRBC Audit
  • Analysis of the context of the organization and determination of scope
  • Determination of audit criteria and purpose
  • Identification of key IRBC areas for audit
  • Creation of a checklist of audit questions
  • Creation of an audit plan and schedule
  • Identification of stakeholders and team organization

Day 2

09:00 – 16:30 Auditing methods and techniques
  • Interviews, observation, documentation review
  • Records as evidence
  • Working with cloud and external services
  • Practical demonstrations
Audit assessment of IRBC systems
  • Process effectiveness assessment: BIA (Business Impact Analysis), ICT risk management, recovery and backup strategies, testing and readiness tests
  • Assessment of compliance with ISO/IEC 27031:2025
Audit findings and processing of conclusions
  • Types of findings: compliance, non-compliance, recommendations
  • Formulation of clear, evidence-based statements
  • Preparation of audit reports in accordance with ISO 19011
  • Recommendations for improvement, measures, and monitoring of corrective actions
  • Communication with management and the audited team
  • Review of the effectiveness of measures during the next audit
Summary and conclusion of the course
  • Final summary and discussion
  • Recommended practices
  • Preparation for the test
  • Block length 90 min.
  • Teaching hours 16
  • Refreshments Yes
  • Exam Yes

This two-day course will prepare you to independently conduct internal and supplier audits of ICT readiness systems (IRBC) in accordance with ISO/IEC 27031:2025. You will gain a deep understanding of the requirements of the standard, learn how to audit them in accordance with ISO 19011 guidelines, and assess whether an organization effectively protects its ICT systems and ensures business continuity.

Prestigious certification included

ISO 27031:2025 Auditor

Obtain the prestigious world-class ICT Readiness certificate! It is issued by the internationally accredited organization RCB (Registered Certification Body) TAYLLORCOX, which focuses on the certification of ISMS (Information Security Management System) systems according to ISO/IEC 27031 standards.

Certification instructions

Exam format

Formát zkoušky

  • A total of 40 questions

  • Certification test (60 min.)

  • Certificate validity period: 3 years;

  • Multiple-choice questions;

  • Successful certification = 55% or more, or 22 questions out of a total of 40

  • Books, lecture notes, dictionaries, and electronic aids may not be used during the test.

Your next career step