Expert Advice Community

Guest

Internal Audit after the ISMS release

  Quote
Guest
Viktor Created:   Sep 14, 2017 Last commented:   Sep 18, 2017

Internal Audit after the ISMS release

How long Do I need to wait once the ISMS is released for start with the internal audit?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 18, 2017

I'd say something between 30 and 90 days after the ISMS has been on regular operations you will have enough evidences and records produced to consider performing the internal audit.

For a more precise answer you have to consider the duration cycle of the processes in the ISMS scope. For example, for a software development process that works with agile methodologies (e.g., SCRUM), in a period of one month you already run approximately 4 cycles (sprints), while for a payroll process in the same period you may have one or two cycles. Some other processes, like equipment maintenance or systems maintenance, may have longer cycles, so you have to consider these when planning you internal audit.

This article will provide you further explanation about internal audit:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/

These materials will also help you regarding internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-gu ide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/

Quote
0 1
Guest
Viktor Oct 03, 2017

Thank you for your answer.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 14, 2017

Oct 02, 2017

Suggested Topics