Expert Advice Community

Guest

Audit scope

  Quote
Guest
Guest user Created:   Mar 05, 2019 Last commented:   Mar 07, 2019

Audit scope

My ISO 27k certification auditor is asking to audit one critical service provider (internal service in the company), this will be part of the surveillance audit . Is he authorized to do so?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Mar 05, 2019

Answer:

If this service provider is included in the certified ISMS scope then it has to be audited at some point during the certification cycle (i.e., during surveillance audits), and as part of the certification process the auditor has authorization to perform the audit.

This article may provide you further information:
- Which questions will the ISO 27001 certification auditor ask? https://advisera.com/27001academy/blog/2015/07/20/which-questions-will-the-iso-27001-certification-auditor-ask/

Quote
0 0
Expert
Rhand Leal Mar 07, 2019

We've received additional question:

>Just to mention the team is not part of the scope as reply to the answer .

Answer: In this case the auditor has no previous authorization to audit this provider. He must justify his intention and the organization can decide to authorize or not the audit at its own discretion, but his most probable action is to check how you are managing the relationship with this service provider, i.e., how you can assure that this service provider is fulfilling your security requirements.

This article can provide you further information:
- How to perform an ISO 27001 second-party audit of an outsourced supplier https://advisera.com/27001academy/blog/2017/10/10/how-to-perform-an-iso-27001-second-party-audit-of-an-outsourced-supplier/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 05, 2019

Mar 07, 2019

Suggested Topics