Expert Advice Community

Guest

Internal audit

  Quote
Guest
Guest user Created:   Jul 26, 2017 Last commented:   Jul 26, 2017

Internal audit

As an implementer of ISO 27001 & the Information security manager writing the security policies at the company could I also perform internal audits myself for the ISMS too?
0 0

Assign topic to the user

ISO 27001 INTERNAL AUDITOR COURSE

Everything you need to perform the internal audit for the first time.

ISO 27001 INTERNAL AUDITOR COURSE

Everything you need to perform the internal audit for the first time.

Expert
Rhand Leal Jul 26, 2017

Answer: As an ISMS implementer, such situation should be avoided, otherwise you could have problems at the certification audit. The best course of action is that the internal auditor should be a different person from the implementer, because according ISO 27001, you must ensure objectivity and the impartiality of the audit process, so you should not audit your own activities as information security manager, including ISO 27001 implementation.

This article will provide you further explanation about Internal audit:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/

This material will also help you regarding Internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 26, 2017

Jul 26, 2017

Suggested Topics