Programme purpose

Programme information

The programme develops the knowledge and practical method needed to plan, conduct, report and follow up an audit of an information security management system.

Training completion and professional certification are separate.

Attendance may satisfy a learning requirement. A professional ERCA credential requires the evidence and assessment stated in the applicable certification programme.

Core audit capability

The detailed course specification remains the source for learning duration, assessment and admission conditions.

  • Audit criteriaUnderstand the information security management-system requirements and the role of audit criteria.
  • Audit planningDefine objectives, scope, methods, sampling and the resources needed for the audit.
  • EvidenceCollect and evaluate evidence through interviews, records, observation and testing appropriate to the scope.
  • Findings and conclusionsRecord findings accurately, reach supported conclusions and communicate them to the audited organisation.
  • Lead-auditor workCoordinate the audit team, allocate tasks, manage communication and protect impartiality and confidentiality.

NIS2/KSC regulatory extension

The planned extension will connect the ISO/IEC 27001 foundation to a defined regulatory audit task, evidence map and sector context.

Status: in development.

The extension is not yet presented as an approved certification route. A future private ERCA credential will not by itself confer statutory authority to perform an audit under the Polish Act on the National Cybersecurity System.