ISO/IEC 27034 Lead Application Security Auditor

The PECB Certified ISO/IEC 27034 Lead Auditor training course provides participants with the skills and knowledge to audit application security processes based on ISO/IEC 27034 series.

On-Site
In-Person Training at Our Academy (Scheduled Sessions)
€3100.00
Online-Live
Live Instructor-led Sessions (Online via Zoom/MS Teams)
€2490.00

The PECB Certified ISO/IEC 27034 Lead Auditor training course provides participants with the skills and knowledge to audit application security processes based on ISO/IEC 27034 series.

Participants will learn to assess how application security is governed, implemented, and maintained, focusing on key ISO/IEC 27034 concepts such as the Organizational Normative Framework (ONF), Application Normative Framework (ANF), and Application Security Controls (ASCs). The course draws on auditing principles from ISO 19011 and ISO/IEC 17021-1 to support a structured approach to auditing application security. These standards are used as guidance rather than for certification, as ISO/IEC 27034 itself is not a certifiable standard.

Through practical exercises and scenario-based activities, participants will build competence in conducting application security audits in various organizational contexts.

Why Should You Attend?

As application security threats grow increasingly complex, organizations must ensure that all applications, whether internally developed, outsourced, or commercially purchased, are properly secured throughout their lifecycle. ISO/IEC 27034 provides structured guidance for achieving this.

By attending this course, participants will gain the skills to plan, manage, and report on audit activities; evaluate an organization’s ONF, its processes, and components associated with application security, the application security management process (ASMP), and the application’s level of trust.

This training is ideal for professionals seeking to enhance their auditing capabilities, contribute to organizational compliance, and support the ongoing development of application security practices.

Who Should Attend?

This training course is intended for:

  • Auditors seeking to perform and lead audits of application security processes
  • Information security and IT professionals responsible for application security governance
  • Consultants and managers involved in application security compliance assessments
  • Members of audit teams and individuals preparing for ISO/IEC 27034 application security audit

Learning Objectives

By the end of this training course, participants will be able to:

  1. Explain the fundamental concepts and principles of application security based on ISO/IEC 27034
  2. Interpret the ISO/IEC 27034 guidelines for application security from the perspective of an auditor
  3. Evaluate the application security conformity to ISO/IEC 27034 guidelines, in accordance with the fundamental audit concepts and principles
  4. Plan, conduct, and close an ISO/IEC 27034 compliance audit, in accordance with ISO/IEC 17021-1 requirements, ISO 19011 guidelines, and other best practices of auditing
  5. Manage an ISO/IEC 27034 audit program

Educational Approach

  • This training course includes essay-type exercises, multiple-choice quizzes, examples and best practices used in application security.
  • Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions.
  • The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared for the exam.

PECB offers various training course delivery formats, from traditional classroom settings to modern, technology-driven solutions. To learn more about these formats, please click here.

Prerequisites

Participants who attend this course must be familiar with application security concepts and have in-depth knowledge of application security principles.


  • Certificate and examination fees are included in the price of the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12-month period from the initial date of the exam.

Examination

The “PECB ISO/IEC 27034 Lead Auditor” exam fully meets the PECB Examination and Certification Program (ECP) requirements. It covers the following competency domains:

Domain 1: Fundamental principles and concepts of application security

Domain 2: Application security audit concepts and principles

Domain 3: Initiating an application security audit

Domain 4: Preparing an ISO/IEC 27034 audit

Domain 5: Conducting an ISO/IEC 27034 audit

Domain 6: Audit closure and follow-up for application security 

  • Certificate and examination fees are included in the price of the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12-month period from the initial date of the exam. 

Certification

After passing the exam, you can apply for one of the credentials in the table below. You will receive a certificate once you fulfill all the requirements of the selected credential.

The certification requirements for PECB ISO/IEC 27034 Lead Auditor are:

 

CredentialExamProfessional experienceMS audit/assessment experienceOther requirements
PECB Certified ISO/IEC 27034 Provisional Application Security AuditorPECB Certified ISO/IEC 27034 Lead Auditor Exam or equivalentNoneNoneSigning the PECB Code of Ethics
PECB Certified ISO/IEC 27034 Application Security AuditorPECB Certified ISO/IEC 27034 Lead Auditor Exam or equivalentTwo years: One year of work experience in Application SecurityAudit activities: a total of 200 hoursSigning the PECB Code of Ethics
PECB Certified ISO/IEC 27034 Lead Application Security AuditorPECB Certified ISO/IEC 27034 Lead Auditor Exam or equivalentFive years: Two years of work experience in Application SecurityAudit activities: a total of 300 hoursSigning the PECB Code of Ethics
PECB Certified ISO/IEC 27034 Senior Lead Application Security AuditorPECB Certified ISO/IEC 27034 Lead Auditor Exam or equivalentTen years: Seven years of work experience in Application SecurityAudit activities: a total of 1,000 hoursSigning the PECB Code of Ethics

 

The application security audit activities should follow best practices and include the following:

  1. Planning an audit
  2. Preparing audit working papers or test plans
  3. Reviewing documented information
  4. Conducting opening and closing meetings
  5. Conducting audit interviews
  6. Collecting and analyzing audit evidence
  7. Documenting nonconformities 
  8. Preparing audit reports 
  9. Following up on nonconformities
  10. Leading an audit team 
  11. Managing an audit program

Additional Information

  • Certificate and examination fees are included in the price of the training course.
  • Participants will receive more than 450 pages of comprehensive training materials, including practical examples, exercises, and quizzes.
  • Participants who have attended the training course will receive an attestation of course completion worth 31 CPD (Continuing Professional Development) credits.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12-month period from the initial date of the exam. 
  • For additional information, please contact us at info@dsgacademy.de, or visit www.dsgacademy.de

Curriculum

  • 1 Section
  • 0 Lessons
  • 5 Days
Expand all sectionsCollapse all sections
  • 0