Answer: ISO does not issue certificates, only standards. Those who issue certificates to persons are accredited training providers. At the end of an ISO 27001 Lead Implementer course you can take an exam, and if approved, you will receive a certificate of Lead Implementer.
2. Internal audit is responsibility of the security team or other departments?
Answer: ISO 27001 does not prescribe who has to be responsible for the internal audit, so you can define this responsibility according your needs, provid ed that you can evidence the auditors have the proper competence and they have no conflict of interest (i.e., auditor must not audit their own work).