Skip to main content

ISO 27001 Lead Auditor Preps: Part 2 — The Dreadful Preparation

·440 words·3 mins·
ISO 27001 Lead Auditor - This article is part of a series.
Part 2: This Article

Alright! In the previous post I wrote about how I ended up choosing PECB as the credentialing body. That means I now have access to the training materials and can start planning how to approach the exam.

Training materials
#

The training course is self-paced, with the materials taught over 4 days. Once the training is completed, I’ll be entitled to 31 CPDs (gotta love that Continuing Professional Development points). Each day has its own slide deck, totaling around 500 slides overall. On top of that, there is further documentation including case studies, exercises, and quizzes.

Materials not included
#

PECB does not provide copies of the standards covered in the course:

  • ISO/IEC 27001:2022: This is where it’s at. The myth, the legend, the framework for implementing, maintaining, and improving Information Security Management Systems (ISMS). It’s composed of two important parts:
    • Clauses 4 to 10, which describe the functional requirements.
    • Annex A, the Information Security Control Reference, which contains the 93 security controls needed to comply with ISO 27001. Not all controls will be implemented in every organization.
  • ISO/IEC 19011:2026: These are the guidelines for auditing programs, conducting internal and external audits, and evaluating auditor competence.
  • ISO/IEC 27002:2022: The supplementary guide with best practices and detailed implementation steps for the security controls in Annex A. The “how things are done around here.”

Exam planning
#

The exam is 3 hours, 80 multiple choice and scenario based questions. It’s an open book exam, but apparently only physical documentation (a wad of papers) is allowed. The good people of Reddit report that all the information needed can be found in the official materials.

That being said, the consensus is that getting familiar with the ISO documentation itself is also needed. The recommended order would be reading ISO 27001 first to understand the clauses and controls. Then 19011 to understand how audits take place, how evidence is gathered, and how nonconformities are written. Lastly, ISO 27002 to understand how the clauses are implemented and how compliance is demonstrated.

PECB materials are supposed to be covered in one week, that includes the videos, the 500-ish slides, and the quizzes. Then, on top of that, I have to read all the dreadful ISO documentation, some 230 pages (27001 at ~20 pages, 19011 at ~50 pages, and 27002 at ~160 pages. Lord have mercy!), which means giving it another week of just reading ISO material (grim). So that’s already two weeks of reading, plus another week of doing quizzes, printing the materials, and indexing them. I reckon 3 weeks of focused preparation should be enough. Only time will tell…

Rhystic Study
Rhystic Study, illustrated by Terese Nielsen, WotC
ISO 27001 Lead Auditor - This article is part of a series.
Part 2: This Article