Conducting an ISO/IEC 27001 Audit
Conducting the certification audit: stage 1 and stage 2, the opening meeting, communication, guides and observers, evidence collection, sampling, checklists, working papers and test plans, corroboration, drafting findings and nonconformities, and the benefit of the doubt.
5 minutes
5 Questions
Conducting an ISO/IEC 27001 audit is the core competency of a Lead Auditor. It follows the guidance of ISO 19011 (auditing management systems) and, for certification bodies, ISO/IEC 27006 and ISO/IEC 17021-1. The goal is to gather objective evidence showing whether an organization's Information Sec…
Concepts covered
The Benefit of the DoubtDocumented Information ReviewGuides and ObserversAudit InterviewsAudit Sampling MethodsAudit Test PlansCorroboration and Evaluation of EvidenceDrafting Audit FindingsAudit Checklists: Advantages and DisadvantagesAuditing the Risk Assessment and the Statement of ApplicabilityCommunication During the AuditNonconformity ReportsStage 1 Versus Stage 2 AuditMajor and Minor NonconformitiesAudit Working PapersStage 1 Audit Objectives and ActivitiesObservation and Technical VerificationStage 2 Audit Objectives and ActivitiesQuality Review of Audit DocumentationAuditing the Implementation of Annex A ControlsAuditing Internal Audit and Management ReviewDocumented Information Evaluation CriteriaAudit Observations and Opportunities for ImprovementThe Opening MeetingConflict Resolution During an Audit
Test mode:
More Conducting an ISO/IEC 27001 Audit questions
671 questions (total)