Expert Advice Community

Guest

Preparing for an audit

  Quote
Guest
Guest user Created:   Jun 26, 2017 Last commented:   Jun 26, 2017

Preparing for an audit

I need to perform Live Auditing of IT company what things i need to take care.
0 0

Assign topic to the user

ISO 27001 INTERNAL AUDIT CHECKLIST

List of questions to ask during the ISO 27001 audit.

ISO 27001 INTERNAL AUDIT CHECKLIST

List of questions to ask during the ISO 27001 audit.

Expert
Rhand Leal Jun 26, 2017

Answer: I'm not sure what do you mean by "live auditing" but I'll assume you are referring to normal on-site audit.

Regarding its execution, since it focuses on observing the person responsible while he performs his jobs, the auditor has to be well prepared and informed about the process being audited, so he can quickly identify and ask activity related questions. Additionally, since this kind of audit practically happens at live environment, you should take measures to avoid the audit may impact on production (e.g., avoid as much as you can the execution of emergency procedures for example).

So, in short, you should consider to ask and study the process documentation previously, take notes on critical activities sequences to be performed, and think about questions to ask like "why this kind of activity is performed?" and "why this kind of activity is performed in this sequence?" (these questions can help you verify if people performing the activity understand w hat is being done and why).

This article will provide you further explanation about preparing for an audit:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/

These materials will also help you regarding preparing for an audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 26, 2017

Jun 26, 2017

Suggested Topics

Guest user Created:   Jan 15, 2021 ISO 27001 & 22301
Replies: 2
0 0

How to prepare an audit?

Guest user Created:   May 19, 2020 ISO 27001 & 22301
Replies: 1
0 0

Surveillance audit