Skip to main content
Cybersecurity ops

ISO 27034 Lead Application Security Auditor

ISO 27034 Lead Application Security Auditor. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Auditors seeking to perform and lead audits of application security processes and controls
  • Information security and IT professionals responsible for application security governance within their organisation
  • Consultants and managers involved in application security compliance assessments
  • Members of audit teams preparing to conduct ISO/IEC 27034 application security audits
  • Individuals working towards a formal ISO/IEC 27034 application security auditor qualification

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Developers or engineers seeking a course focused on secure coding techniques rather than audit and governance processes
  • Professionals whose primary interest is information security risk management frameworks rather than application security auditing
  • Individuals with no prior knowledge of application security who are looking for an introductory overview of the field
  • Those seeking a network security management course rather than one focused on application-layer security auditing

What you'll be able to do

  • 1Explain the fundamental concepts and principles of application security as defined by ISO/IEC 27034
  • 2Interpret ISO/IEC 27034 guidelines from an auditor's perspective to assess application security conformity
  • 3Evaluate an organisation's application security practices against ISO/IEC 27034 guidelines using established audit concepts
  • 4Plan, conduct, and close an ISO/IEC 27034 compliance audit in accordance with ISO/IEC 17021-1 requirements and ISO 19011 guidelines
  • 5Manage an ISO/IEC 27034 audit programme across multiple engagements within an organisation
  • 6Apply best practices from ISO 19011 to lead application security audit teams effectively

Day by day

Day 1Introduction to application security and the ISO/IEC 27034 family of standards
  • Overview of the ISO/IEC 27034 family of standards

    This module introduces the structure and scope of the ISO/IEC 27034 series, explaining how each part addresses different aspects of application security governance.

  • Fundamental application security concepts and principles

    Participants examine the core concepts underpinning application security, including the organisation normative framework and application normative framework defined in ISO/IEC 27034.

  • Role of the auditor in application security

    This module establishes the auditor's perspective within the ISO/IEC 27034 context, introducing the audit principles and independence requirements that govern the role.

By end of day

  • Describe the structure of the ISO/IEC 27034 family and its relevance to application security governance
  • Articulate core application security principles from an auditor's viewpoint
Day 2Initiating and preparing an application security audit
  • Audit programme management

    This module covers how to establish and manage an ISO/IEC 27034 audit programme, including defining objectives, scope, and scheduling across multiple audit cycles.

  • Audit planning and document review

    Participants learn how to plan an individual audit engagement, define audit criteria, and conduct a preliminary document review to assess application security documentation.

  • Audit team preparation and logistics

    This module addresses how to assemble and brief an audit team, assign responsibilities, and manage pre-audit logistics in line with ISO 19011 guidelines.

By end of day

  • Develop an ISO/IEC 27034 audit plan with defined scope, criteria, and team responsibilities
  • Apply ISO 19011 guidance to organise and prepare an audit team for an application security engagement
Day 3Conducting an on-site application security audit
  • Opening meeting and evidence collection

    This module covers how to open an audit formally, gather objective evidence through interviews and process observation, and manage auditee interactions professionally.

  • Evaluating conformity with ISO/IEC 27034

    Participants practise assessing application security processes and controls against ISO/IEC 27034 requirements, documenting findings and identifying nonconformities.

  • Managing audit complexity and scope changes

    This module addresses how to handle unexpected findings, scope adjustments, and sensitive situations during the on-site phase of an application security audit.

By end of day

  • Collect and evaluate audit evidence to assess conformity with ISO/IEC 27034 guidelines
  • Document nonconformities accurately and manage on-site audit challenges in a professional manner
Day 4Reporting, completing, and following up on the audit
  • Drafting the audit report

    This module covers the structure and content of an ISO/IEC 27034 audit report, including how to present findings, nonconformities, and conclusions clearly to stakeholders.

  • Closing meeting and audit finalisation

    Participants learn how to conduct a closing meeting, communicate audit results to the auditee, and formally close the audit engagement in line with ISO/IEC 17021-1 requirements.

  • Follow-up activities and corrective action review

    This module examines how to manage post-audit follow-up, review corrective action plans submitted by the auditee, and verify the resolution of identified nonconformities.

By end of day

  • Produce a clear and structured ISO/IEC 27034 audit report that meets professional and regulatory expectations
  • Manage audit closing activities and follow-up processes that support genuine improvement in application security
Day 5Consolidation and exam preparation
  • Review of audit competency domains

    This session consolidates learning across all five course days by revisiting the core competency domains aligned with the PECB Lead Application Security Auditor exam.

  • Practical scenarios and Q&A

    Participants work through realistic audit scenarios and address remaining questions with trainer support to reinforce confidence and exam readiness.

By end of day

  • Consolidate knowledge across all audit competency domains covered during the course
  • Identify and address remaining gaps before sitting the PECB certification exam independently

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of application security
  • Domain 2: Application security audit concepts and principles
  • Domain 3: Initiating an application security audit
  • Domain 4: Preparing an ISO/IEC 27034 audit
  • Domain 5: Conducting an ISO/IEC 27034 audit
  • Domain 6: Audit closure and follow-up for application security

The certification requirements for PECB ISO/IEC 27034 Lead Auditor are:

  1. Planning an audit
  2. Preparing audit working papers or test plans
  3. Reviewing documented information
  4. Conducting opening and closing meetings
  5. Conducting audit interviews
  6. Collecting and analyzing audit evidence
  7. Documenting nonconformities
  8. Preparing audit reports
  9. Following up on nonconformities
  10. Leading an audit team
  11. Managing an audit program

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational Approach

  • This training course contains various activities such as exercises, multiple-choice quizzes, real-life scenarios, and best practices used in the implementation of application security.
  • Participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
  • The quizzes are structured to reflect the style and format of the certification exam.

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What application security knowledge do I need before attending this course?+

Participants are expected to arrive with familiarity with application security concepts and in-depth knowledge of application security principles. This course is pitched at an advanced level and builds on that foundation rather than introducing it from scratch.

If your background is primarily in network or infrastructure security rather than application security specifically, reviewing the ISO/IEC 27034 series and fundamental application security concepts before attending would be beneficial.

Which auditing standards and guidelines does this course draw on alongside ISO/IEC 27034?+

The course incorporates ISO/IEC 17021-1, which sets conformity assessment requirements for audit and certification bodies, and ISO 19011, which provides guidelines for auditing management systems. Together these standards frame the audit planning, conduct, and reporting activities covered in the programme.

Understanding the relationship between these standards and ISO/IEC 27034 gives participants a well-rounded approach to leading application security audits that are both technically sound and procedurally rigorous.

How does completing this training relate to obtaining a PECB Lead Application Security Auditor credential?+

Completing the five-day Cyber Academy training means you have participated in the full curriculum. It does not automatically result in PECB certification.

To obtain a PECB credential you would need to pass the PECB certification exam and meet the professional experience requirements defined by PECB for the relevant credential tier. Please refer to PECB's Certification Rules and Policies for the most current requirements.

Is this course suitable for someone who already holds an ISO/IEC 27001 Lead Auditor qualification?+

Professionals who hold an ISO/IEC 27001 Lead Auditor qualification will already be familiar with audit processes and principles based on ISO 19011, which provides a useful foundation for this course.

The ISO/IEC 27034 Lead Application Security Auditor programme builds on that audit methodology expertise by focusing specifically on application security governance and the ISO/IEC 27034 standard. The application security content is distinct from ISMS auditing, so participants should ensure they also have the application security domain knowledge expected for this course.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.