Programme purpose
Programme informationThe programme develops the knowledge and practical method needed to plan, conduct, report and follow up an audit of an information security management system.
Attendance may satisfy a learning requirement. A professional ERCA credential requires the evidence and assessment stated in the applicable certification programme.
Core audit capability
The detailed course specification remains the source for learning duration, assessment and admission conditions.
- Audit criteriaUnderstand the information security management-system requirements and the role of audit criteria.
- Audit planningDefine objectives, scope, methods, sampling and the resources needed for the audit.
- EvidenceCollect and evaluate evidence through interviews, records, observation and testing appropriate to the scope.
- Findings and conclusionsRecord findings accurately, reach supported conclusions and communicate them to the audited organisation.
- Lead-auditor workCoordinate the audit team, allocate tasks, manage communication and protect impartiality and confidentiality.
NIS2/KSC regulatory extension
The planned extension will connect the ISO/IEC 27001 foundation to a defined regulatory audit task, evidence map and sector context.
The extension is not yet presented as an approved certification route. A future private ERCA credential will not by itself confer statutory authority to perform an audit under the Polish Act on the National Cybersecurity System.
- Organisation qualificationIdentify which obligations and sector context apply to the audited organisation.
- Requirement-to-evidence mappingConnect legal duties to controls, processes, records and audit evidence.
- Cyber risk and incidentsAssess the organisation's treatment of risk, incident handling and continuity obligations.
- Supply chainExamine how relevant supplier and third-party risks are controlled and evidenced.
- Regulatory reportPrepare a report that identifies criteria, evidence, findings, limitations and conclusions without overstating the auditor's authority.
