Evidences for audit
Assign topic to the user
Answer: ISO 27001 does not prescribe the need to evidence what did not happen (i.e., if there was no incident or no change), but it could make sense during the measurement and monitoring process to create a record that says that none of these things have happened.
2. As a part of implementation process we have installed firewall in our organization for log generation. Can we conduct internal audit based on logs of 10 days?
Answer: A good reference you can use to define the time you need a process or control to be operating to have enough data to be audited is to ensure it has already completed at l east three cycles of operation. For example, if a full backup process is performed once a week, then you should wait at least three weeks to audit this process.
Comment as guest or Sign in
May 24, 2019