Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
In case you are planning a single audit to cover all the ISMS scope at once, these references you defined are sufficient.
In case you are planning to perform multiple audits to cover small parts of the scope each time (e.g., IT processes audit, HR processes, etc.), then you need to be more specific about which criteria you will use. For example, in the case of auditing HR processes, most probably controls from section A.14 System acquisition, development and maintenance won’t be part of your checklist, while controls from section A.7 Human resource security will take more space in your checklist.
This article will provide you a further explanation about building an audit checklist:
These materials will also help you regarding building the audit program: