Internal audit
Assign topic to the user
Answer: As an ISMS implementer, such situation should be avoided, otherwise you could have problems at the certification audit. The best course of action is that the internal auditor should be a different person from the implementer, because according ISO 27001, you must ensure objectivity and the impartiality of the audit process, so you should not audit your own activities as information security manager, including ISO 27001 implementation.
This article will provide you further explanation about Internal audit:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
This material will also help you regarding Internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
Comment as guest or Sign in
Jul 26, 2017