ISMS Audit Expert
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
Table of Contents
Audit Program Management
Risk-Based Audit Schedule
| Risk Level |
Audit Frequency |
Examples |
| Critical |
Quarterly |
Privileged access, vulnerability management, logging |
| High |
Semi-annual |
Access control, incident response, encryption |
| Medium |
Annual |
Policies, awareness training, physical security |
| Low |
Annual |
Documentation, asset inventory |
Annual Audit Planning Workflow
- Review previous audit findings and risk assessment results
- Identify high-risk controls and recent security incidents
- Determine audit scope based on ISMS boundaries
- Assign auditors ensuring independence from audited areas
- Create audit schedule with resource allocation
- Obtain management approval for audit plan
- Validation: Audit plan covers all Annex A controls within certification cycle
Auditor Competency Requirements
- ISO 27001 Lead Auditor certification (preferred)
- No operational responsibility for audited processes
- Understanding of technical security controls
- Knowledge of applicable regulations (GDPR, HIPAA)
Audit Execution
Pre-Audit Preparation
- Review ISMS documentation (policies, SoA, risk assessment)
- Analyze previous audit reports and open findings
- Prepare audit plan with interview schedule
- Notify auditees of audit scope and timing
- Prepare checklists for controls in scope
- Validation: All documentation received and reviewed before opening meeting
Audit Conduct Steps
Opening Meeting
- Confirm audit scope and objectives
- Introduce audit team and methodology
- Agree on communication channels and logistics
Evidence Collection
- Interview control owners and operators
- Review documentation and records
- Observe processes in operation
- Inspect technical configurations
Control Verification
- Test control design (does it address the risk?)
- Test control operation (is it working as intended?)
- Sample transactions and records
- Document all evidence collected
Closing Meeting
- Present preliminary findings
- Clarify any factual inaccuracies
- Agree on finding classification
- Confirm corrective action timelines
Validation: All controls in scope assessed with documented evidence
Evidence Collection Methods
| Method |
Use Case |
Example |
| Inquiry |
Process understanding |
Interview Security Manager about incident response |
| Observation |
Operational verification |
Watch visitor sign-in process |
| Inspection |
Documentation review |
Check access approval records |
| Re-performance |
Control testing |
Attempt login with weak password |
Control Assessment
ISO 27002 Control Categories
Organizational Controls (A.5):
- Information security policies
- Roles and responsibilities
- Segregation of duties
- Contact with authorities
- Threat intelligence
- Information security in projects
People Controls (A.6):
- Screening and background checks
- Employment terms and conditions
- Security awareness and training
- Disciplinary process
- Remote working security
Physical Controls (A.7):
- Physical security perimeters
- Physical entry controls
- Securing offices and facilities
- Physical security monitoring
- Equipment protection
Technological Controls (A.8):
- User endpoint devices
- Privileged access rights
- Access restriction
- Secure authentication
- Malware protection
- Vulnerability management
- Backup and recovery
- Logging and monitoring
- Network security
- Cryptography
Control Testing Approach
- Identify control objective from ISO 27002
- Determine testing method (inquiry, observation, inspection, re-performance)
- Define sample size based on population and risk
- Execute test and document results
- Evaluate control effectiveness
- Validation: Evidence supports conclusion about control status
Finding Management
Finding Classification
| Severity |
Definition |
Response Time |
| Major Nonconformity |
Control failure creating significant risk |
30 days |
| Minor Nonconformity |
Isolated deviation with limited impact |
90 days |
| Observation |
Improvement opportunity |
Next audit cycle |
Finding Documentation Template
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]
Corrective Action Workflow
- Auditee acknowledges finding and severity
- Root cause analysis completed within 10 days
- Corrective action plan submitted with target dates
- Actions implemented by responsible parties
- Auditor verifies effectiveness of corrections
- Finding closed with evidence of resolution
- Validation: Root cause addressed, recurrence prevented
Certification Support
Stage 1 Audit Preparation
Ensure documentation is complete:
Stage 2 Audit Preparation
Verify operational readiness:
Surveillance Audit Cycle
| Period |
Focus |
| Year 1, Q2 |
High-risk controls, Stage 2 findings follow-up |
| Year 1, Q4 |
Continual improvement, control sample |
| Year 2, Q2 |
Full surveillance |
| Year 2, Q4 |
Re-certification preparation |
Validation: No major nonconformities at surveillance audits.
Tools
scripts/
| Script |
Purpose |
Usage |
isms_audit_scheduler.py |
Generate risk-based audit plans |
python scripts/isms_audit_scheduler.py --year 2025 --format markdown |
Audit Planning Example
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
References
| File |
Content |
| iso27001-audit-methodology.md |
Audit program structure, pre-audit phase, certification support |
| security-control-testing.md |
Technical verification procedures for ISO 27002 controls |
| cloud-security-audit.md |
Cloud provider assessment, configuration security, IAM review |
Audit Performance Metrics
| KPI |
Target |
Measurement |
| Audit plan completion |
100% |
Audits completed vs. planned |
| Finding closure rate |
>90% within SLA |
Closed on time vs. total |
| Major nonconformities |
0 at certification |
Count per certification cycle |
| Audit effectiveness |
Incidents prevented |
Security improvements implemented |
Compliance Framework Integration
| Framework |
ISMS Audit Relevance |
| GDPR |
A.5.34 Privacy, A.8.10 Information deletion |
| HIPAA |
Access controls, audit logging, encryption |
| PCI DSS |
Network security, access control, monitoring |
| SOC 2 |
Trust Services Criteria mapped to ISO 27002 |
1---2name: isms-audit-expert3description: Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support4---5
6# ISMS Audit Expert
7
8Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
9
10## Table of Contents
11
12- [Audit Program Management](#audit-program-management)
13- [Audit Execution](#audit-execution)
14- [Control Assessment](#control-assessment)
15- [Finding Management](#finding-management)
16- [Certification Support](#certification-support)
17- [Tools](#tools)
18- [References](#references)
19
20---
21
22## Audit Program Management
23
24### Risk-Based Audit Schedule
25
26| Risk Level | Audit Frequency | Examples |
27|------------|-----------------|----------|
28| Critical | Quarterly | Privileged access, vulnerability management, logging |
29| High | Semi-annual | Access control, incident response, encryption |
30| Medium | Annual | Policies, awareness training, physical security |
31| Low | Annual | Documentation, asset inventory |
32
33### Annual Audit Planning Workflow
34
351. Review previous audit findings and risk assessment results
362. Identify high-risk controls and recent security incidents
373. Determine audit scope based on ISMS boundaries
384. Assign auditors ensuring independence from audited areas
395. Create audit schedule with resource allocation
406. Obtain management approval for audit plan
417. **Validation:** Audit plan covers all Annex A controls within certification cycle
42
43### Auditor Competency Requirements
44
45- ISO 27001 Lead Auditor certification (preferred)
46- No operational responsibility for audited processes
47- Understanding of technical security controls
48- Knowledge of applicable regulations (GDPR, HIPAA)
49
50---
51
52## Audit Execution
53
54### Pre-Audit Preparation
55
561. Review ISMS documentation (policies, SoA, risk assessment)
572. Analyze previous audit reports and open findings
583. Prepare audit plan with interview schedule
594. Notify auditees of audit scope and timing
605. Prepare checklists for controls in scope
616. **Validation:** All documentation received and reviewed before opening meeting
62
63### Audit Conduct Steps
64
651. **Opening Meeting**
66 - Confirm audit scope and objectives
67 - Introduce audit team and methodology
68 - Agree on communication channels and logistics
69
702. **Evidence Collection**
71 - Interview control owners and operators
72 - Review documentation and records
73 - Observe processes in operation
74 - Inspect technical configurations
75
763. **Control Verification**
77 - Test control design (does it address the risk?)
78 - Test control operation (is it working as intended?)
79 - Sample transactions and records
80 - Document all evidence collected
81
824. **Closing Meeting**
83 - Present preliminary findings
84 - Clarify any factual inaccuracies
85 - Agree on finding classification
86 - Confirm corrective action timelines
87
885. **Validation:** All controls in scope assessed with documented evidence
89
90### Evidence Collection Methods
91
92| Method | Use Case | Example |
93|--------|----------|---------|
94| Inquiry | Process understanding | Interview Security Manager about incident response |
95| Observation | Operational verification | Watch visitor sign-in process |
96| Inspection | Documentation review | Check access approval records |
97| Re-performance | Control testing | Attempt login with weak password |
98
99---
100
101## Control Assessment
102
103### ISO 27002 Control Categories
104
105**Organizational Controls (A.5):**
106- Information security policies
107- Roles and responsibilities
108- Segregation of duties
109- Contact with authorities
110- Threat intelligence
111- Information security in projects
112
113**People Controls (A.6):**
114- Screening and background checks
115- Employment terms and conditions
116- Security awareness and training
117- Disciplinary process
118- Remote working security
119
120**Physical Controls (A.7):**
121- Physical security perimeters
122- Physical entry controls
123- Securing offices and facilities
124- Physical security monitoring
125- Equipment protection
126
127**Technological Controls (A.8):**
128- User endpoint devices
129- Privileged access rights
130- Access restriction
131- Secure authentication
132- Malware protection
133- Vulnerability management
134- Backup and recovery
135- Logging and monitoring
136- Network security
137- Cryptography
138
139### Control Testing Approach
140
1411. Identify control objective from ISO 27002
1422. Determine testing method (inquiry, observation, inspection, re-performance)
1433. Define sample size based on population and risk
1444. Execute test and document results
1455. Evaluate control effectiveness
1466. **Validation:** Evidence supports conclusion about control status
147
148---
149
150## Finding Management
151
152### Finding Classification
153
154| Severity | Definition | Response Time |
155|----------|------------|---------------|
156| Major Nonconformity | Control failure creating significant risk | 30 days |
157| Minor Nonconformity | Isolated deviation with limited impact | 90 days |
158| Observation | Improvement opportunity | Next audit cycle |
159
160### Finding Documentation Template
161
162```
163Finding ID: ISMS-[YEAR]-[NUMBER]
164Control Reference: A.X.X - [Control Name]
165Severity: [Major/Minor/Observation]
166
167Evidence:
168- [Specific evidence observed]
169- [Records reviewed]
170- [Interview statements]
171
172Risk Impact:
173- [Potential consequences if not addressed]
174
175Root Cause:
176- [Why the nonconformity occurred]
177
178Recommendation:
179- [Specific corrective action steps]
180```
181
182### Corrective Action Workflow
183
1841. Auditee acknowledges finding and severity
1852. Root cause analysis completed within 10 days
1863. Corrective action plan submitted with target dates
1874. Actions implemented by responsible parties
1885. Auditor verifies effectiveness of corrections
1896. Finding closed with evidence of resolution
1907. **Validation:** Root cause addressed, recurrence prevented
191
192---
193
194## Certification Support
195
196### Stage 1 Audit Preparation
197
198Ensure documentation is complete:
199- [ ] ISMS scope statement
200- [ ] Information security policy (management signed)
201- [ ] Statement of Applicability
202- [ ] Risk assessment methodology and results
203- [ ] Risk treatment plan
204- [ ] Internal audit results (past 12 months)
205- [ ] Management review minutes
206
207### Stage 2 Audit Preparation
208
209Verify operational readiness:
210- [ ] All Stage 1 findings addressed
211- [ ] ISMS operational for minimum 3 months
212- [ ] Evidence of control implementation
213- [ ] Security awareness training records
214- [ ] Incident response evidence (if applicable)
215- [ ] Access review documentation
216
217### Surveillance Audit Cycle
218
219| Period | Focus |
220|--------|-------|
221| Year 1, Q2 | High-risk controls, Stage 2 findings follow-up |
222| Year 1, Q4 | Continual improvement, control sample |
223| Year 2, Q2 | Full surveillance |
224| Year 2, Q4 | Re-certification preparation |
225
226**Validation:** No major nonconformities at surveillance audits.
227
228---
229
230## Tools
231
232### scripts/
233
234| Script | Purpose | Usage |
235|--------|---------|-------|
236| `isms_audit_scheduler.py` | Generate risk-based audit plans | `python scripts/isms_audit_scheduler.py --year 2025 --format markdown` |
237
238### Audit Planning Example
239
240```bash
241# Generate annual audit plan
242python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
243
244# With custom control risk ratings
245python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
246```
247
248---
249
250## References
251
252| File | Content |
253|------|---------|
254| [iso27001-audit-methodology.md](references/iso27001-audit-methodology.md) | Audit program structure, pre-audit phase, certification support |
255| [security-control-testing.md](references/security-control-testing.md) | Technical verification procedures for ISO 27002 controls |
256| [cloud-security-audit.md](references/cloud-security-audit.md) | Cloud provider assessment, configuration security, IAM review |
257
258---
259
260## Audit Performance Metrics
261
262| KPI | Target | Measurement |
263|-----|--------|-------------|
264| Audit plan completion | 100% | Audits completed vs. planned |
265| Finding closure rate | >90% within SLA | Closed on time vs. total |
266| Major nonconformities | 0 at certification | Count per certification cycle |
267| Audit effectiveness | Incidents prevented | Security improvements implemented |
268
269---
270
271## Compliance Framework Integration
272
273| Framework | ISMS Audit Relevance |
274|-----------|---------------------|
275| GDPR | A.5.34 Privacy, A.8.10 Information deletion |
276| HIPAA | Access controls, audit logging, encryption |
277| PCI DSS | Network security, access control, monitoring |
278| SOC 2 | Trust Services Criteria mapped to ISO 27002 |