Frequency of performing internal audit of ISMS
Assign topic to the user
Answer: ISO 27001 is not prescriptive about a specific frequency to perform internal audits, but when defining it, the standard requires you to take in consideration the importance of the processes concerned and the results of previous audits (the more problematic or critical is the process, more frequent it should be audited, and vice versa). Additionally, if your organization is iso 27001 certified, the certification auditor will expect to see internal audit performed at least once a year, so you also should take this in consideration.
This article will provide you further explanation about planing audits:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
These materials will also help you regardi ng planing audits:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
Comment as guest or Sign in
Jan 12, 2018