Learn Preparing an ISO/IEC 27001 Audit (ISO 27001 LA) with Interactive Flashcards

Master key concepts in Preparing an ISO/IEC 27001 Audit through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.

Steps and Activities to Prepare an ISMS Audit

Preparing an ISMS audit follows the audit process in ISO 19011 and ISO/IEC 17021-1, as covered in the PECB ISO/IEC 27001 Lead Auditor course. Preparation turns the audit objectives into a realistic, risk-based plan. Step 1, Initiating the audit: The audit team leader is appointed and contacts the auditee. This contact confirms communication channels and the auditee's authority. It also requests access to documented information, confirms the audit objectives, scope and criteria, and identifies site-specific security, confidentiality and health and safety requirements. Step 2, Determining audit feasibility: The leader checks whether there is enough information, enough cooperation from the auditee, and enough time and resources. If the audit is not feasible, an alternative is proposed to the audit client. Step 3, Stage 1 audit and documentation review: The auditor reviews the ISMS documentation. This includes the scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, objectives, and results of internal audits and management reviews. The review helps the auditor understand the organization's context, processes, assets and readiness for Stage 2. It also identifies areas of concern, which are documented in a Stage 1 report. Step 4, Audit planning: The team leader prepares an audit plan using a risk-based approach. The plan defines objectives, scope, criteria, locations, dates, duration, audit methods, sampling, roles and responsibilities, and logistics. It is communicated to the auditee, and any objections are resolved. Step 5, Assigning work to the audit team: Tasks are allocated according to each auditor's competence, independence and the need to avoid conflicts of interest. Technical experts and guides are assigned where needed. Step 6, Preparing work documents: Auditors develop checklists, audit test plans, sampling plans, interview guides and forms for recording evidence, findings and meetings. These documents support consistent evidence collection but must stay flexible. Together, these activities ensure the audit is efficient, objective, evidence-based and properly aligned with ISO/IEC 27001 requirements.

Initial Contact with the Auditee

In ISO/IEC 27001 audit preparation, initial contact with the auditee is the first formal communication between the audit team leader and the organization being audited. It follows the acceptance of the audit mandate and is guided by ISO 19011 (clause 6.2.2) and ISO/IEC 17021-1 for certification audits. Its purpose is to establish a professional working relationship, confirm feasibility, and gather the information needed to plan an effective audit. The contact may be formal or informal, by phone, email, or meeting, and is usually made by the audit team leader. Key objectives include: confirming communication channels and identifying the auditee representative or guide; confirming the authority to conduct the audit; and communicating the audit objectives, scope, criteria, methods, duration, and audit team composition, including technical experts and observers. The auditor also requests access to relevant documented information for planning, such as the ISMS scope, information security policy, risk assessment and treatment methodology, and Statement of Applicability. The auditor determines applicable legal, regulatory, and contractual requirements, and identifies risks and opportunities related to the audit. Because ISO/IEC 27001 audits involve sensitive information, initial contact is critical for agreeing on confidentiality, the extent of disclosure, handling of classified or personal data, and any non-disclosure agreements. Practical arrangements are also made, including scheduling dates, site locations, multi-site sampling, remote audit technology, access permissions, security clearances, health and safety rules, and the need for interpreters. The auditee can raise objections to specific team members, which should be resolved before the audit proceeds. The auditor also identifies areas of particular interest or concern to the auditee, such as previous nonconformities. Successful initial contact sets clear expectations, reduces misunderstandings, demonstrates professionalism and impartiality, and supports a feasibility determination, ensuring the audit can achieve its objectives with sufficient information, cooperation, time, and resources.

Terms of the Audit Engagement

In the ISO/IEC 27001 Lead Auditor framework, the terms of the audit engagement are the formal, agreed conditions under which an audit will be carried out. They are set during audit preparation, after initial contact between the certification body (or audit team leader) and the auditee, and before detailed planning begins. Their purpose is to make sure both parties share the same expectations, which reduces misunderstandings, disputes and surprises during the audit.

The terms are usually documented in a contract or engagement letter, in line with ISO/IEC 17021-1, ISO/IEC 27006 and the guidance in ISO 19011. Key elements typically include:

- Audit objectives: what the audit must achieve, such as initial certification, surveillance or recertification.
- Audit scope: the ISMS boundaries, including sites, processes, organizational units, technologies and the Statement of Applicability.
- Audit criteria: ISO/IEC 27001 requirements, applicable legal and contractual obligations, and the organization's own policies.
- Audit duration: the number of audit days, often calculated with the ISO/IEC 27006 methodology based on the number of employees and the complexity of the ISMS.
- Schedule and logistics: dates, locations, the use of remote auditing, working language and the facilities needed.
- Audit team composition: auditor names, technical experts, observers and guides, giving the auditee the right to object to specific members.
- Roles and responsibilities: who provides access to documents, people and premises, and who acts as the main point of contact.
- Confidentiality and information security: how sensitive information will be handled, including any restrictions on access or copying.
- Reporting and follow-up: report format, distribution, handling of nonconformities and timelines for corrective actions.
- Commercial and legal conditions: fees, cancellation terms, liability, and procedures for appeals and complaints.

The audit team leader must also confirm that the audit is feasible. This means checking that enough information, cooperation, time and resources are available. Clearly agreed terms protect auditor independence and impartiality, and they create a sound basis for an effective, credible ISO/IEC 27001 audit.

Audit Feasibility

In ISO/IEC 27001 auditing, audit feasibility is the assessment made before the audit to confirm whether it can realistically meet its objectives. ISO 19011:2018 (clause 6.2.3) states that feasibility should be determined to give reasonable confidence that the audit objectives can be achieved. The audit team leader carries out this assessment while preparing the audit, after the objectives, scope and criteria have been defined and initial contact with the auditee has been made.

The assessment considers three main factors. First, there must be sufficient and appropriate information for planning and conducting the audit, such as the ISMS scope, the information security policy, the risk assessment and treatment results, the Statement of Applicability and records of internal audits and management reviews. Second, the auditee must cooperate adequately by granting access to sites, personnel, systems and evidence. Third, there must be adequate time and resources, including competent auditors and technical experts, travel arrangements and, for remote audits, reliable information and communication technology.

For information security audits, ISO/IEC 27007 also highlights some specific concerns. The auditee may restrict access to confidential or classified information, which could limit the evidence available. Legal and regulatory constraints, safety and security rules on site, language barriers and complex or outsourced processes can also affect the audit. In certification audits, the auditor must also check that the ISMS has been operating long enough to produce objective evidence of its effectiveness.

If the audit is found not to be feasible, the team leader should propose alternatives to the audit client after consulting the auditee. Options include changing the scope or objectives, rescheduling, adding resources or experts, or postponing the audit until the ISMS is mature enough. The reasons for the decision should be documented. When feasibility is confirmed, the auditor can proceed with the document review, the audit plan and the assignment of work to the audit team. A feasibility check reduces the risk of inconclusive results, wasted effort and disputes with the auditee, and it supports an audit that is credible, efficient and evidence-based.

Audit Objectives

In ISO/IEC 27001 auditing, audit objectives define what a specific audit is meant to accomplish. ISO 19011 guidance treats them as the foundation of audit preparation, and certification audits follow ISO/IEC 17021-1 and ISO/IEC 27006. Objectives are set by the audit programme manager or certification body, agreed with the audit client, and given to the lead auditor before planning begins. They differ from the audit scope, which sets the boundaries such as locations, processes, assets and time period. They also differ from audit criteria, which are the requirements used as reference, such as ISO/IEC 27001, the Statement of Applicability, policies, and legal or contractual obligations. Objectives answer the question of why the audit is being conducted. Typical objectives for an ISO/IEC 27001 audit include: confirming that the ISMS conforms to all requirements of the standard; determining whether the ISMS is effectively implemented and maintained; evaluating its ability to meet the organization's information security objectives; verifying that applicable statutory, regulatory and contractual requirements are addressed; and identifying opportunities for improvement. Objectives also vary by audit stage. A Stage 1 audit assesses documentation, scope, the risk assessment and treatment approach, and readiness for Stage 2. A Stage 2 audit evaluates the implementation and effectiveness of the ISMS and controls. Surveillance and recertification audits focus on continued conformity, changes and ongoing effectiveness. Clearly defined objectives drive every later preparation activity. They determine the audit plan, duration, sampling approach, competence and size of the audit team, the audit methods used, and the information requested from the auditee. Vague objectives risk an audit that misses critical risks or cannot support a reliable certification decision. A competent lead auditor confirms that the objectives are clear, achievable and consistent with the scope and criteria. The lead auditor also checks that access, resources and time are sufficient. If an objective cannot be met, the lead auditor reports this to the audit client before the audit proceeds.

Audit Criteria

In ISO/IEC 27001 auditing, audit criteria are the set of requirements used as a reference against which objective evidence is compared. ISO 19011 and ISO/IEC 17021-1 define them this way. They are the benchmark that lets an auditor decide whether a finding is a conformity or a nonconformity. Without clearly defined criteria, findings would be subjective opinions rather than verifiable conclusions. When preparing an ISO/IEC 27001 audit, the Lead Auditor must identify, confirm and document the criteria together with the audit objectives and scope. These three elements form the foundation of the audit plan. Typical criteria include: the requirements of ISO/IEC 27001 clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement; the Annex A controls that the organization has declared applicable in its Statement of Applicability; and the organization's own ISMS documentation, such as the information security policy, risk assessment methodology, risk treatment plan and operational procedures. Applicable legal, regulatory and contractual obligations also count, for example data protection laws or customer security requirements. During preparation, the Lead Auditor reviews documented information to confirm that the criteria are clear, current and accessible. The auditor also checks whether the scope and criteria are consistent, and whether the audit is feasible within the time and resources available. The criteria are communicated to and agreed with the auditee, often during the pre-audit contact and in the audit plan. They are then translated into working documents such as checklists and sampling plans that guide evidence collection. Each audit finding should reference the specific criterion involved, such as clause 6.1.2 or control 5.15, so that it is traceable and defensible. Criteria must remain stable throughout the audit, and any change requires agreement with the audit client. Properly defined criteria ensure objectivity, consistency and repeatability. They also ensure fair evaluation and support credible certification decisions.

Audit Scope Versus ISMS Scope

In ISO/IEC 27001 auditing, the ISMS scope and the audit scope are related but different. Confusing them is a common mistake when preparing an audit.

The ISMS scope is set by the auditee, as required by Clause 4.3 of ISO/IEC 27001. The organization decides the boundaries and applicability of its information security management system. It considers internal and external issues (4.1), the requirements of interested parties (4.2), and the interfaces and dependencies between its own activities and those performed by others. The ISMS scope must be documented. It typically names the organizational units, locations, assets, technologies and processes covered. It is closely tied to the Statement of Applicability and the risk assessment.

The audit scope is set for a particular audit, following the guidance of ISO 19011 and the requirements of ISO/IEC 17021-1 and ISO/IEC 27006 for certification bodies. It describes the extent and boundaries of that audit: which sites, departments, processes, activities and time period will be examined. The audit scope is agreed between the audit team leader, the audit client and the auditee, and it is recorded in the audit plan.

The key relationship is that the audit scope can equal the ISMS scope or be a subset of it, but it should not go beyond it. An initial certification audit (Stage 1 and Stage 2) must cover the entire ISMS scope. Surveillance audits and internal audits may cover only selected parts, provided the whole scope is covered over the certification cycle. Multi-site organizations may be audited through sampling.

During preparation, the Lead Auditor checks that the ISMS scope is appropriate. They confirm that it is clearly defined and justified, and that it has not been artificially narrowed to leave out risky areas. They also check that interfaces with external parties are addressed. The certificate scope must accurately reflect what was audited. Any change to the audit scope should be formally agreed, because it affects audit duration, team competence, sampling and the validity of audit conclusions.

Materiality in an ISMS Audit

In an ISO/IEC 27001 audit, materiality is the significance of a matter, such as a weakness, omission or nonconformity, judged by whether it could reasonably influence the audit conclusions or the decisions of those relying on them, including the auditee's top management and the certification body. Financial audits often set numeric thresholds. ISMS audits instead treat materiality mainly as a qualitative judgment based on information security risk, business impact and the effectiveness of the management system.

When preparing the audit, the lead auditor uses materiality to apply the risk-based approach recommended by ISO 19011 and ISO/IEC 27007. The auditor reviews several inputs:
- the ISMS scope
- the risk assessment and risk treatment plan
- the Statement of Applicability
- previous audit results and security incidents
- legal, regulatory and contractual obligations
- the criticality of information assets and processes

From this review, the auditor identifies the areas where failures would matter most. Typical examples are access control for sensitive customer data, cryptographic key management, supplier security and business continuity of critical services. These areas then receive more audit time, larger samples, more experienced team members and deeper testing. Low-risk areas may be sampled more lightly.

Materiality also guides how findings are evaluated and graded:
- A major nonconformity usually involves the absence or total breakdown of a required process or control, or a situation that raises significant doubt about the ability of the ISMS to achieve its intended outcomes.
- A minor nonconformity is typically an isolated lapse that does not undermine the system as a whole.
- Observations and opportunities for improvement record matters below the materiality threshold that are still worth noting.

The lead auditor must exercise professional judgment, remain objective and apply materiality consistently across the audit team. The reasoning behind planning decisions and finding classifications should be documented so that conclusions are transparent, defensible and repeatable. Properly applied, materiality makes the audit efficient and focused, and gives reasonable assurance that significant information security risks and ISMS deficiencies are not overlooked.

Reasonable Assurance

In ISO/IEC 27001 auditing, reasonable assurance is a high, but not absolute, level of confidence that an organization's Information Security Management System (ISMS) conforms to the requirements of ISO/IEC 27001 and is effectively implemented and maintained. A lead auditor can never guarantee that every nonconformity has been found. Audits are conducted within limited time, rely on sampling, and depend on the information made available by the auditee. The audit conclusion is therefore an informed professional opinion supported by evidence, not a certificate of perfection.

The concept follows principles in ISO 19011 and ISO/IEC 17021-1, especially the evidence-based approach. Auditors must collect audit evidence that is sufficient (enough quantity) and appropriate (relevant and reliable) to support their findings. Evidence comes from interviews, observation of activities, and review of documented information such as the risk assessment, Statement of Applicability, policies, records, and the results of internal audits and management reviews.

When preparing an ISO/IEC 27001 audit, reasonable assurance shapes the planning. The lead auditor should:
- Define clear audit objectives, scope, and criteria.
- Apply a risk-based approach, focusing effort on areas with the greatest information security risks or the highest likelihood of nonconformity.
- Determine audit duration and team competence, using guidance such as ISO/IEC 27006.
- Design sampling plans that are representative of processes, locations, and Annex A controls.
- Review stage 1 documentation to identify gaps and concerns before stage 2.

Audit risk is the possibility that the auditor reaches an incorrect conclusion, for example by missing a significant nonconformity. Good planning, competent auditors, professional skepticism, triangulation of evidence, and sound judgment reduce this risk to an acceptable level.

Ultimately, reasonable assurance allows the certification body to make a credible certification decision. Stakeholders can trust the result while understanding its inherent limitations. Continual surveillance audits and recertification audits then maintain this confidence over the full certification cycle.

Inherent, Control and Detection Risk

When preparing an ISO/IEC 27001 audit, a Lead Auditor uses the audit risk model to plan an effective, risk-based audit. Audit risk is the risk that the auditor reaches an incorrect conclusion, such as recommending certification when the ISMS contains significant nonconformities, or reporting a nonconformity that does not exist. It is commonly described as the product of three components: Audit Risk = Inherent Risk x Control Risk x Detection Risk.

1. Inherent Risk: This is the likelihood that a significant nonconformity or information security weakness exists before any controls are considered. It arises from the nature of the auditee, including its industry, regulatory exposure, size, process complexity, technology, outsourcing, rate of change and the sensitivity of the information it handles. A cloud service provider processing health data has higher inherent risk than a small office with limited IT. The auditor cannot change inherent risk, only assess it.

2. Control Risk: This is the risk that the organization's ISMS processes and Annex A controls fail to prevent, or to detect and correct, a nonconformity in time. Weak risk assessment, poor internal audits, an immature management review or ineffective corrective action all increase control risk. The auditor evaluates it during the document review and Stage 1 audit, but cannot directly reduce it.

3. Detection Risk: This is the risk that the auditor's own procedures fail to detect an existing nonconformity. It is the only component under the audit team's control. It depends on sampling methods, sample size, audit duration, team competence, the audit plan and the evidence-gathering techniques used, such as interviews, observation and technical verification.

Planning implication: Because the auditor must keep overall audit risk at an acceptably low level, detection risk is set inversely to the assessed inherent and control risks. Where these are high, the Lead Auditor lowers detection risk by allocating more audit time, larger and more targeted samples, technical experts and deeper testing of high-risk processes and controls.

Risk-Based Audit Planning

Risk-based audit planning is the approach, promoted by ISO 19011 and ISO/IEC 27006, in which the lead auditor allocates audit effort according to the risks relevant to the audit and to the auditee's information security management system (ISMS). Rather than examining every clause and Annex A control with equal depth, the auditor focuses time, sampling and expertise where nonconformities or significant information security failures are most likely and would have the greatest consequences.

Planning considers two dimensions of risk. The first is audit risk, meaning the risk that the audit fails to achieve its objectives. Causes include insufficient audit time, unclear scope, lack of auditor competence, limited access to information or personnel, inadequate sampling, and threats to impartiality. The second is the auditee's information security risk. This covers the threats, vulnerabilities and impacts identified in the organization's own risk assessment, as well as its context, interested parties, legal and contractual obligations, and key business processes.

To build a risk-based plan, the lead auditor reviews documented information such as the ISMS scope, the risk assessment methodology, the risk treatment plan and the Statement of Applicability. Previous audit reports, incident records and the results of the Stage 1 audit are also examined. From this review, the auditor identifies critical processes, high-value assets, outsourced services, recent organizational or technological changes, and controls that were excluded or newly implemented. These areas receive more attention in the audit plan, larger samples, and team members with the relevant technical competence.

The audit plan then defines the objectives, criteria, scope, schedule, locations, methods (including remote auditing), resources and roles. It remains flexible enough to be adjusted if new risks emerge during fieldwork. Lower-risk areas still receive adequate coverage to confirm conformity with all ISO/IEC 27001 requirements.

The benefits include efficient use of audit time, more meaningful findings, greater confidence in the certification decision, and added value for the auditee. The audit concentrates on what genuinely matters for protecting the confidentiality, integrity and availability of information.

Audit Team Leader Responsibilities

In ISO/IEC 27001 certification audits, the Audit Team Leader is the person ultimately accountable for the audit from preparation through reporting. The role follows ISO 19011, ISO/IEC 17021-1 and ISO/IEC 27006. During preparation, the leader first confirms the audit objectives, scope and criteria with the certification body and the auditee. This includes the ISMS boundaries, the Statement of Applicability, sites, processes and any exclusions. The leader assesses feasibility, which means checking whether enough information, resources, time and cooperation are available, and identifies audit risks such as access restrictions or sensitive information. The leader helps determine audit time and makes sure the team as a whole has the competence the audit needs. That means knowledge of information security, the relevant sector, legal requirements and the technologies in use, adding technical experts or translators where necessary. The leader establishes initial contact with the auditee to agree on logistics, communication channels, confidentiality arrangements, safety rules and access to documented information. A central duty is preparing the audit plan. The plan defines the activities, schedule, sampling approach, interviewees, locations and any remote audit methods, and is shared with the auditee in advance. The leader assigns tasks to team members according to their competence and independence, avoiding conflicts of interest. The leader also allocates the review of key documents such as the risk assessment methodology, risk treatment plan, policies and the SoA. During the audit, the leader chairs the opening and closing meetings, and coordinates team communication and daily briefings. The leader monitors progress against the plan and adjusts it if needed, resolves disagreements, escalates serious issues and protects objectivity and evidence integrity. The leader guides less experienced auditors and reviews their findings for consistency. Finally, the leader consolidates the findings, grades nonconformities and agrees the audit conclusions with the team. The leader presents these conclusions to the auditee, prepares or approves the audit report and makes a recommendation regarding certification. Throughout, the leader upholds integrity, confidentiality, impartiality, due professional care and an evidence-based approach.

Audit Team Members and Technical Experts

When preparing an ISO/IEC 27001 audit, the audit team leader, working with the certification body or audit programme manager, forms a competent team. Guidance comes from ISO 19011 and ISO/IEC 27006, which sets requirements for certification bodies.

Audit team members are qualified auditors who collect and assess evidence, interview personnel, observe activities, review documented information and record findings. The team leader assigns each member specific ISMS processes, Annex A controls, sites or functions, and briefs them on the audit objectives, scope, criteria and plan. Selection should consider the team's combined competence, including knowledge of information security management, risk assessment and treatment, relevant legal and regulatory requirements, the auditee's sector and technologies, and audit principles and techniques. Team size depends on the scope, complexity, number of sites, risk level and time available. Members must be independent of the audited activities, free from conflicts of interest, and impartial and objective. Language, culture and the auditee's working practices should also be considered. Auditors-in-training may join, but they must work under the guidance of a qualified auditor.

Technical experts provide specialised knowledge or expertise that the audit team lacks, for example in cryptography, cloud architecture, industrial control systems, healthcare data or a particular regulatory regime. They are not auditors. They do not audit independently, draw audit conclusions or grade nonconformities. Instead, they act under the direction of an auditor, advising on technical matters, helping interpret evidence and answering questions. Technical experts must meet the same requirements for confidentiality, impartiality and freedom from conflicts of interest as auditors. Their role should be defined and communicated to the auditee in advance, and the auditee may object to particular individuals.

Observers, such as accreditation assessors, and guides provided by the auditee are not part of the audit team and must not influence the audit. A well-balanced team of competent auditors and technical experts helps make audit findings credible, reliable and objective.

Audit Team Selection and Audit Time

Audit team selection and audit time determination are key planning activities when preparing an ISO/IEC 27001 certification audit. They are governed mainly by ISO/IEC 17021-1, ISO/IEC 27006 and the guidance in ISO 19011.

Audit Team Selection: The certification body appoints an audit team leader, usually a qualified ISO/IEC 27001 Lead Auditor. The team leader is responsible for planning, managing and reporting the audit. The team as a whole must have the competence needed to achieve the audit objectives. This includes knowledge of information security management, the Annex A controls, risk assessment and treatment, and relevant legal and regulatory requirements. It also includes familiarity with the auditee's sector and technologies, such as cloud services, software development or finance. Where gaps exist, technical experts may be added. Technical experts provide specialist knowledge but do not act as auditors. Auditors-in-training may join under supervision. Selection must also ensure impartiality and independence. Team members must not have provided consultancy to the auditee, typically within the previous two years, and must have no other conflicts of interest. Other factors include language skills, cultural awareness, security clearance requirements, availability and the size and complexity of the organization. Roles such as guides and observers should be agreed in advance.

Audit Time: Audit duration is calculated using the audit time tables in ISO/IEC 27006. The starting point is the effective number of personnel within the ISMS scope, including part-time staff and contractors. This baseline is then adjusted for factors such as:
- the complexity of the ISMS
- the business type and its regulatory environment
- the IT infrastructure
- outsourcing arrangements
- the number of sites
- previous audit results

Reductions are limited, commonly to no more than 30 percent of the table value, and every adjustment must be justified and recorded. The total time covers Stage 1, which reviews documentation and readiness, and Stage 2, which evaluates implementation and effectiveness. As a rule of thumb, surveillance audits take about one third of the initial audit time, and recertification audits about two thirds. Travel time is excluded. Multi-site sampling and remote auditing techniques may affect how the time is allocated, but they must still allow sufficient evidence to be gathered for a reliable audit conclusion.

Audit Plan Preparation

Audit plan preparation is a critical step in preparing an ISO/IEC 27001 audit. It turns the audit program into a practical, time-bound roadmap for a specific audit. Guided by ISO 19011 and, for certification audits, ISO/IEC 27006, the audit team leader develops the plan after reviewing the auditee's documented information. This information typically includes the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability (SoA), and results from previous audits or the Stage 1 review.

A well-structured audit plan typically defines:
(1) audit objectives, such as determining ISMS conformity with ISO/IEC 27001 requirements and evaluating its effectiveness;
(2) audit scope, including organizational units, processes, physical locations, and the Annex A controls covered;
(3) audit criteria, such as ISO/IEC 27001 clauses, legal and contractual requirements, and internal policies;
(4) dates, times, and duration of activities, including opening and closing meetings;
(5) audit methods, such as interviews, observation, document review, technical verification, and sampling techniques;
(6) roles and responsibilities of team members, technical experts, and guides;
(7) the resources needed; and
(8) arrangements for confidentiality, reporting, and follow-up.

The plan should be risk-based. Audit time and focus should go to the areas with the greatest information security risks, significant changes, critical processes, or past nonconformities. Lead auditors should also consider remote auditing, multi-site sampling, and the availability of key personnel.

The plan is shared with the auditee in advance so that it can raise any objections and prepare resources. Any disputes are resolved before the audit begins. The plan must also remain flexible, allowing adjustments as audit evidence emerges during fieldwork. Finally, the team leader uses the plan to assign tasks and prepare work documents such as checklists and sampling plans.

Effective audit plan preparation ensures that the audit is efficient, objective, and consistent, and that it delivers reliable conclusions about the organization's ISMS.

Multi-Site Audits and Site Sampling

Multi-site audits apply when an organization runs a single Information Security Management System (ISMS) across several locations, such as headquarters, branches, data centres or remote offices. When planning the audit, the Lead Auditor must decide whether sampling is allowed or whether every site has to be visited. The main references are IAF MD 1 (certification of multiple sites based on sampling) and ISO/IEC 27006-1, which adds ISMS-specific requirements for certification bodies.

Sampling is only allowed if certain conditions are met. All sites must operate under one ISMS that is centrally administered and covered by a common management review. Internal audits must have covered every site. A central function must have the authority to require corrective action at any site. The sites should also carry out similar activities with comparable information security risks. If sites differ significantly in processes, risk or technology, they may need separate or full coverage.

IAF MD 1 bases the minimum sample size on the square root of the number of sites. It uses roughly √x for initial audits, 0.6√x for surveillance and 0.8√x for recertification, always rounded up. The sample is then adjusted for risk factors, including:
- the complexity and size of each site
- internal audit results and complaints
- legal and regulatory differences
- geographic, cultural and language differences
- recent changes and the criticality of the information assets involved

Part of the sample is selected on a risk basis and part at random. The central function is audited at every audit. Across the certification cycle, the audit programme must cover all ISMS clauses and all applicable Annex A controls.

A nonconformity found at one site is treated as potentially affecting every site. The organization must investigate how widespread it is and apply corrective action across the whole network. Certification cannot proceed until this is done, and problem sites cannot simply be removed from scope to avoid findings.

When preparing the audit, the Lead Auditor documents the sampling rationale in the audit plan. The plan should allocate auditor competence, language skills and time, and consider remote auditing techniques under IAF MD 4 where appropriate.

Cultural Aspects in an Audit

In ISO/IEC 27001 audits, cultural aspects are the national, regional, organizational and individual norms, values and behaviors that affect how auditors and auditees communicate, share information and react to findings. ISO 19011 lists 'culturally sensitive' among the personal behaviors expected of auditors, so a Lead Auditor should consider culture while preparing the audit, not only on site.

Culture has several layers. National or regional culture shapes language, communication style (direct versus indirect), attitudes toward hierarchy and authority, punctuality, working hours, religious observances, public holidays, dress codes, gender norms and body language. Organizational culture shapes how openly staff discuss problems, how decisions are made, how mature the security awareness is, and whether an audit is seen as a chance to improve or as a threat. In hierarchical cultures, staff may hesitate to answer without a manager present or may avoid admitting weaknesses. In indirect cultures, 'yes' may mean 'I understand' rather than 'I agree.'

During preparation, the Lead Auditor should research the auditee's context and plan for these factors. This can include selecting team members with relevant language skills or cultural familiarity, arranging qualified and impartial interpreters, scheduling around holidays, prayer times and local working hours, and choosing an appropriate tone for the opening meeting. The auditor should also think about how to word questions and how to present nonconformities so they are understood and accepted. Remote and multi-site audits across time zones need extra care.

On site, auditors should show respect, listen actively, avoid stereotypes, and confirm their understanding by paraphrasing and checking objective evidence rather than relying on assumptions. They should watch nonverbal cues while staying aware that their meaning differs between cultures.

Cultural sensitivity must never compromise independence, objectivity or the audit criteria. Auditors adapt how they communicate, but not what they require. Handling culture well builds trust, encourages honest disclosure, reduces misunderstandings and conflict, and produces more reliable audit conclusions and more effective corrective actions.

More Preparing an ISO/IEC 27001 Audit questions
456 questions (total)
Practice questions
One session at a time, always new questions