Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

Training and auditor development

ISO, NIS2 and GDPR training — from awareness to internal auditor

Every course is delivered personally by a Lead Auditor certified in six ISO standards, with over 25 years of operational IT and information security experience behind the material. Participants get answers about what actually happens in a certification audit, not a reading of the clauses.

AwarenessFoundationInternal AuditorNIS2 Art. 20(2)English or Turkish
Structure

Three levels, per standard

Most organisations run all three in sequence: awareness for everybody, foundation for the people who own processes, and internal auditor for the small group who will run the audit programme afterwards.

Awareness

Half day · all staff

Why the standard exists, what it means for daily work, and what each person is personally responsible for. Sector-specific examples throughout; no prior knowledge assumed.

Foundation

1–2 days · process owners, managers, project teams

Requirements clause by clause, terminology and concepts, control objectives, and how the management system components fit together. Prepares participants to contribute to an implementation.

Internal Auditor

2–3 days · audit, quality and compliance staff

Audit planning and programme design, evidence sampling, interview technique, nonconformity classification, report writing and corrective action follow-up — taught with real audit case material and practical exercises.

Per-standard programmes

Six ISO standards, each at the levels that make sense

ISO/IEC 27001

Awareness · Foundation · Internal Auditor

Information security, from principles to audit technique, risk matrices and treatment plans.

  • The 2022 revision and what changed in Annex A
  • Building and defending the Statement of Applicability
  • Mapping controls to NIS2 Article 21

ISO/IEC 27701

Awareness · Foundation · Internal Auditor

Privacy information management connected to the law that actually governs you.

  • Controller and processor roles
  • Records of processing that can be maintained
  • Transfers: SCCs, TIAs, supplementary measures

ISO 22301

Awareness · Foundation · Internal Auditor

Business continuity as culture, not only certification.

  • A BIA that produces usable recovery objectives
  • Designing an exercise that tests something real
  • Using the output as NIS2 Article 21(2)(c) evidence

ISO/IEC 20000-1

Awareness · Foundation · Internal Auditor

IT service management people can run and certify.

  • Service catalogue design the business can read
  • SLAs and KPIs you can actually collect
  • Where 20000-1 and 27001 share evidence

ISO/IEC 42001

Awareness · Foundation

AI management systems for staff using AI tools and for management, risk, IT and data teams.

  • Responsible AI use in practice
  • AI system impact assessment
  • Relationship to the EU AI Act and an existing ISMS

ISO 9001

Foundation · 1 day

Requirements, process approach, risk-based thinking and the harmonised structure that makes integration with the other standards possible.

  • Offered primarily for integrated management systems
Integrated Internal Auditor

Three days for multi-standard organisations

Auditing two or more management systems in one audit: combined programme and plan design, shared evidence, a single finding register, and reporting to one management review.

Organisations that certify several standards separately typically run separate audit programmes, produce separate finding registers and hold separate management reviews. Auditors trained to audit the integrated system reduce audit days and stop the systems drifting apart between cycles.

About certificates

Internal auditor courses — single-standard and integrated — include an assessment and a certificate of completion issued by Infosec Academy. This is not an accredited personnel certification (such as a Lead Auditor certificate under a certification scheme). It documents that the participant completed and passed the course, for your competence records.

NIS2 training

Management bodies, technical teams and suppliers

Under Article 20(2) of Directive (EU) 2022/2555, members of management bodies are required to follow training, and entities are encouraged to offer similar training to their staff.

For management bodies

Half day · board and executive team

Scope and classification, the ten Article 21 measures in business language, approval and oversight duties, personal liability, the reporting obligation, and what the supervisory authority can do. A working session with a documented attendance record.

For technical teams

1 day · IT, OT and security staff

Article 21 measure by measure, the national decree’s technical requirements, OT and ICS in scope, logging and detection expectations, the 24/72-hour reporting chain, and the evidence each measure has to produce.

For suppliers

Half day · third-party providers

What the customer is now contractually obliged to require, what notification timelines mean in practice, and what evidence the supplier will be asked for. Delivered in English or Turkish.

Country-specific content

The directive is the floor; the national act is what you are audited against. Sessions follow the applicable transposition:

  • Slovakia — Act 69/2018 Coll. as amended by Act 366/2024 Coll., Decree 227/2025 Coll., NBÚ and JISKB registration
  • Romania — GEO 155/2024 and the DNSC deadline sequence
  • Other member states on request, worked from the primary legal source

A note on documentation

Management-body training that happened but was not recorded does not exist as far as a supervisory authority is concerned. Every session we deliver comes with an attendance record, the agenda and the materials used — a complete evidence package for the compliance file.

GDPR and frameworks

Data protection and security framework courses

GDPR Awareness

Half day · all staff

What personal data is, lawful bases, data subject rights, and the everyday behaviours that cause most breaches.

GDPR for data owners and DPOs

1–2 days · privacy, legal, HR, IT

Records of processing, DPIAs, processor management under Article 28, retention, the 72-hour breach decision, and international transfers.

Cross-jurisdiction privacy

1 day · groups in several regimes

GDPR alongside Turkish KVKK, UAE PDPL and Qatar PDPPL — where obligations align, where they conflict, and how to run one programme.

CIS Controls v8.1

1 day · IT and security teams

The 18 controls in priority order, implementation groups IG1–IG3, and their use underneath an ISO/IEC 27001 or NIS2 programme — taught by a trainer whose master’s thesis was on CIS Controls implementation.

NIST CSF 2.0

1 day · security and risk functions

The six functions including Govern, profiles and tiers, maturity assessment, and mapping to ISO/IEC 27001 and NIS2 Article 21.

ITIL 4 Foundations

1–2 days · IT service and operations teams

The service value system and the practices that matter most in regulated environments: incident, problem, change enablement and service level management. ITIL (Version 5) developments covered as they are released.

Formats

On site, online, blended or closed group

On site

Anywhere in the EU or Türkiye, tailored to your own system.

Online

Live and interactive, in sessions sized for remote attention.

Blended

Online theory, on-site practical audit exercise.

Closed group

A single organisation, using your own documents as case material.

What participants take away

  • Course materials and reference documents
  • Worked exercises based on real audit findings
  • Templates they can use immediately — audit plan, checklist, finding report
  • Attendance record for the organisation’s training evidence
  • Assessment and certificate of completion for internal auditor courses
Booking

How a programme is put together

Most clients run a sequence rather than a single course — for example all-staff awareness, then a technical day, then an internal auditor course for a small group.

Tell us the brief

The standard or regulation, the audience and its size, and the deadline you are working to.

We propose a programme

Levels, sequence, duration and format, designed against your certification or compliance deadline — before any commercial discussion.

Delivery

On site, online or blended, in English or Turkish, with materials and records for your evidence file.

Frequently asked questions

Training questions we are asked

Do internal auditor courses lead to a certificate?

Internal auditor courses include an assessment and a certificate of completion issued by Infosec Academy. This is not an accredited personnel certification such as a Lead Auditor certificate awarded under a certification scheme; it documents that the participant completed and passed the course, which is what an organisation needs for its competence records.

Is NIS2 management-body training really mandatory?

Yes. Article 20(2) of Directive (EU) 2022/2555 requires members of management bodies to follow training and encourages entities to offer similar training to their staff. It is one of the few explicitly personal NIS2 obligations, and it only counts if it is recorded — so every session comes with an attendance record, agenda and materials.

Can you train on our own documents?

Yes. Closed-group courses use your own management system documents as case material, which makes internal auditor training directly usable for your first audit cycle. Content is also tailored to your sector and the national act that applies to you.

Which languages and formats are available?

Courses are delivered in English or Turkish, on site anywhere in the EU or Türkiye, online as live interactive sessions, or blended with online theory and an on-site practical audit exercise.

Who delivers the courses?

Every course is delivered personally by our founder, a Lead Auditor in six ISO standards with over 25 years of IT and information security experience — including fifteen years as the accountable person inside multinational organisations. There is no pool of subcontracted trainers.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.