Expert Advice Community

Guest

Remote audit

  Quote
Guest
Guest user Created:   Nov 15, 2019 Last commented:   Nov 15, 2019

Remote audit

Hi - I am getting ready to conduct an ISO 27001:2013 internal audit of an organization. The plan was to conduct onsite visits in other countries. Question: Can I conduct a remote audit if possible?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 15, 2019

A remote internal audit is possible, provided that required evidence of conformance does not need the physical presence of the auditor on-site. For example, to audit the conformance of an information system that can be remotely accessed or the conformance of a procedure, there is no need for the auditor's presence (he only needs to have access to the system or receive a scanned copy of physical documents and records). On the other hand, to audit the conformance of physical security controls, it might be necessary for the auditor to be on-site if the company cannot provide evidence of such controls remotely (e.g. through photographs, plans, maps, etc.).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 15, 2019

Nov 15, 2019

Suggested Topics