To whom will the auditor speak to?
Assign topic to the user
Answer: During the ISMS audit both internal and external (certification) auditor has the right to speak to anyone in the company, so he can speak to people from IT department, security department, to the CEO or to any business department.
The point of the audit is to find out whether the employees are complying to the policies and procedures, and these documents are not only applicable to security department.
This free online training explains the whole audit process: ISO 27001 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
Comment as guest or Sign in
Oct 24, 2016