Query Regarding Internal Audit
Assign topic to the user
1 - Can ISMS policies (ex: Access Control Policy, Human Resource Security Policy,..) be scope for Internal Audit
The internal audit can be performed in terms of implemented ISMS policies. You only need to ensure that all mandatory clauses and applicable controls are audited before the next certification/surveillance audit.
For further information, see:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
2 - Can requirements within the ISMS policies be audit criteria ex: HR screening criteria - BS7858 as per regulatory requirements
First is important to note that audit criteria need to be something against which ISMS policies are compared, not within ISMS policies, so you should think about requirements “applied” to ISMS policies, not “within” them.
Considering that, requirements used to develop ISMS policies can be used as audit criteria. In your example, BS7858 requirements are the criteria against which you evaluate your HR screening policy.
Comment as guest or Sign in
Jun 29, 2021