Online Course: Internal Audit of Information Security in Civil Aviation
π‘ This course is part of the Academy of Information Security in Civil Aviation - PART-IS Manager training. |
Description and Objectives of the Training
The course Internal Audit of the Information Security Management System in Civil Aviation in accordance with PART-IS.I.OR requirements equips participants with the knowledge and skills required to plan, conduct, and evaluate internal audits in organisations that establish, maintain, or improve an Information Security Management System (ISMS) within the scope of civil aviation.
Special emphasis is placed on alignment with the Information Security and Oversight Requirements of the European Union Aviation Safety Agency (PART-IS.I.OR), which sets out oversight obligations in the context of civil aviation. The course covers all stages of the audit process β from understanding regulatory requirements to implementing practical activities and conducting final evaluations. Through simulations and practical exercises, participants gain the competencies needed for effective internal audit execution in compliance with EASA requirements and international standards.
Target Audience
The course is intended for professionals involved in the development, maintenance, and supervision of information security management systems within organisations that are part of the civil aviation system. The target group includes internal auditors, members of ISMS teams, information security advisors, security programme coordinators, and compliance officers responsible for meeting the requirements in the field of information security in civil aviation, in accordance with PART-IS.I.OR.
Course Content
β€ Introduction to Internal Audit Internal audit is a key tool for assessing the compliance and effectiveness of an Information Security Management System (ISMS). Its purpose lies in supporting the cycle of continual improvement and strengthening internal control and accountability within the organisation. Internal audit differs from self-assessment and external audit in its internal nature and improvement-driven focus. This section includes an overview of the essential normative and regulatory requirements based on ISO/IEC 27001:2022, ISO 19011:2018, and Annex II β Information Security β Organisation Requirements (PART-IS.I.OR), with a particular emphasis on management responsibilities and the requirement for periodic internal audits as set out in IS.I.OR.200(a)(12). β€ Audit Programme The audit programme defines the strategic framework within which multiple audits are planned and organised over a specific period. It includes the audit objectives, criteria, scope, frequency, resources, and responsibilities, and is based on risk assessment and applicable regulatory requirements. The development of the programme must align with the guidelines set out in ISO/IEC 19011 and ISO/IEC 27007, and the documented programme should be linked to scheduled records and allocated resources to ensure the audit is effective and consistent. β€ Audit Plan The audit plan is an operational document that details specific information for each individual audit, including the date and location, audited processes, daily schedule of activities, and the members of the audit team with their assigned responsibilities. It includes information on the audit methodology, communication channels, and logistical arrangements. The audit plan is prepared based on the audit programme and must be linked to the relevant organisational documentation, while also respecting the obligation to record audit evidence in accordance with requirement IS.I.OR.245. At this stage, the auditor reviews the relevant organisational documentation, prepares audit questions, identifies areas of interest, and plans the approach for conducting interviews and verifications. The auditor applies various information-gathering techniques such as interviews, observation, and record review. It is essential to know how to formulate questions, take notes, and select appropriate evidence to support audit conclusions. Nonconformities are defined and classified according to the standards ISO/IEC 27001 and ISO 19011, with a distinction made between major and minor nonconformities, observations, and recommendations. The auditor is responsible for recording audit findings and performing accurate analysis, including the identification of root causes. Proper management of nonconformities is essential for initiating effective corrective actions and for the successful closure of the audit.. β€ Corrections, Corrective Actions, and Continual Improvement of the ISMS During this workshop, participants use previously developed materials β the audit programme and audit plan, checklist, and supporting documentation β to conduct a simulated internal audit. Activities include scenario analysis, conducting interviews, reviewing evidence, and classifying findings. Based on the results, participants prepare an audit report, propose corrective actions, and jointly evaluate the overall process. This workshop integrates all previously completed exercises and serves as a practical application of the knowledge acquired throughout the course. β€ Final Exam The final exam consists of a written knowledge test comprising 20 questions and two audit scenarios. The exam covers all thematic units of the course and is designed to confirm the participantsβ competence in effectively conducting internal audits in accordance with the requirements of ISO standards and the regulatory framework defined by PART-IS.I.OR. β€ Certificate of Competence |
Certificate of Competence
All participants who successfully complete the practical exercises and pass the final exam will be awarded a certificate of competence for conducting internal audits of information security management systems in civil aviation, in accordance with the Information Security and Oversight Requirements of the European Union Aviation Safety Agency (PART-IS.I.OR).
Learning Outcomes
Upon completion of the training, participants will be able to:
- explain the purpose, objectives, and regulatory requirements for conducting internal ISMS audits,
- develop an Audit Programme and Audit Plan in accordance with applicable standards and requirements,
- create an effective audit checklist based on specific criteria and supporting documentation,
- classify and analyse audit findings in line with nonconformity criteria,
- evaluate and assess the effectiveness of corrective and improvement actions,
- conduct an internal audit in practice using prepared tools and methods,
- successfully pass the final exam and demonstrate competence to perform internal audits.
Literature
|
Discounts
We offer attractive discounts for group registrations. The applicable rates are as follows:
|
Additional information: Bojan Varga, e-mail: bojan.varga@siq.si
-
Dates: 29.07.2025-30.07.2025ID: 18740Please choose a dateRegistration
-
Duration:
2 Days (09:00 - 16:00)
16 school hours - Lecturer: Davorin Kacian
- Registration fee: 916,00 EUR (does not include VAT)
We value and reward your loyalty
That is why we are introducing the Loyalty Bonus to reward our loyal participants.
More about loyalty bonus