Certification Process
Assign topic to the user
HI, just following on from the webinar last week regarding the Certification Process - which was very good thank you – I’ve a couple of questions if that’s OK:
1 - Training / Awareness
Prior to the webinar we had been led to believe that our planned approach – namely:
Publish the IS policy & notify everyone it is available – but not actually record who has read it
Publish a number of awareness bulletins and encourage people to discuss them at team meetings
Run a small number of online sessions whereby information on various aspects of ISO 27001 / Information Security are presented. The attendee list for these events would be retained
would be sufficient. Would you agree with that or, as I think you implied would the auditor expect that we had a more formal approach to training with people being recorded against the training sessions they have completed?
Please note that while your proposed approaches cover the communication from organization to employees, you are not considering an approach to ensure employees have understood your message, i.e., that they understand the importance of information security, the impacts in case it is compromised, and what they can do to protect information.
So, you should also consider the application of small quizzes or other methods to evaluate employees' understanding.
For further information, see:
- How to perform training & awareness for ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/05/19/how-to-perform-training-awareness-for-iso-27001-and-iso-22301/
- What are the benefits of security awareness training for organizations? https://advisera.com/27001academy/blog/2019/03/27/what-are-the-benefits-of-security-awareness-training-for-organizations/
2 - Internal Auditor
Is it mandatory that the internal audit is carried out by a certified auditor (whether that’s an internal member of staff that’s been trained or a 3rd party retained for the audits)? One thought was that following the first initial audit where we would use a qualified third party we would compile questions that would need to be completed for subsequent audits. Selected people would then take those questions round the business at the appropriate time – though they would not necessarily be accredited.
Any information you can give would be greatly appreciated.
Thanks
You do not need a certified auditor to perform an internal audit, provided that you can evidence his audit competencies by other means, like previous experience, or formal education in an audit.
These articles will provide you a further explanation about internal auditor:
- Qualifications for an ISO 27001 Internal Auditor https://advisera.com/27001academy/blog/2015/03/30/qualifications-for-an-iso-27001-internal-auditor/
- Dilemmas with ISO 27001 & BS 25999-2 internal auditors https://advisera.com/27001academy/blog/2010/03/22/dilemmas-with-iso-27001-bs-25999-2-internal-auditors/
These materials will also help you regarding internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- Free online training ISO 27001:2013 Internal Auditor Course https://training.advisera.com/course/iso-27001-internal-auditor-course/
Comment as guest or Sign in
Jun 23, 2021