Expert Advice Community

Guest

Number of controls for audit

  Quote
Guest
Guest user Created:   May 18, 2020 Last commented:   May 18, 2020

Number of controls for audit

1 - One initial question I have is whether there is a “required” number of controls that need to be audited for a certification?  I was thinking that an auditor would check 15-20 randomly selected controls? 

2 - Any thoughts or recommendations for how best to approach this would be helpful and appreciated!

0 0

Assign topic to the user

ISO 27001 INTERNAL AUDIT CHECKLIST

List of questions to ask during the ISO 27001 audit.

ISO 27001 INTERNAL AUDIT CHECKLIST

List of questions to ask during the ISO 27001 audit.

Expert
Rhand Leal May 18, 2020

One initial question I have is whether there is a “required” number of controls that need to be audited for a certification?  I was thinking that an auditor would check 15-20 randomly selected controls? 

For a certification audit, all controls identified as applicable in the Statement of Applicability will be audited, and this number will vary depending on the results of risk assessment and legal requirements you have to comply to. A reduced number of controls will be audited only during surveillance audits, where the auditor will focus on the controls applicable in the scope of the audit.

For further information, see:

Any thoughts or recommendations for how best to approach this would be helpful and appreciated!

The best way to approach this situation is to prepare a proper internal audit checklist for your internal audit (performing at least one internal audit is also mandatory for certification). This way you will have a good understanding of the status of your ISMS before the certification audit

This article will provide you a further explanation about internal audit:

These materials will also help you regarding internal audit:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 18, 2020

May 18, 2020