ISMS Audit Expert
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
Table of Contents
Audit Program Management
Risk-Based Audit Schedule
| Risk Level |
Audit Frequency |
Examples |
| Critical |
Quarterly |
Privileged access, vulnerability management, logging |
| High |
Semi-annual |
Access control, incident response, encryption |
| Medium |
Annual |
Policies, awareness training, physical security |
| Low |
Annual |
Documentation, asset inventory |
Annual Audit Planning Workflow
- Review previous audit findings and risk assessment results
- Identify high-risk controls and recent security incidents
- Determine audit scope based on ISMS boundaries
- Assign auditors ensuring independence from audited areas
- Create audit schedule with resource allocation
- Obtain management approval for audit plan
- Validation: Audit plan covers all Annex A controls within certification cycle
Auditor Competency Requirements
- ISO 27001 Lead Auditor certification (preferred)
- No operational responsibility for audited processes
- Understanding of technical security controls
- Knowledge of applicable regulations (GDPR, HIPAA)
Audit Execution
Pre-Audit Preparation
- Review ISMS documentation (policies, SoA, risk assessment)
- Analyze previous audit reports and open findings
- Prepare audit plan with interview schedule
- Notify auditees of audit scope and timing
- Prepare checklists for controls in scope
- Validation: All documentation received and reviewed before opening meeting
Audit Conduct Steps
Opening Meeting
- Confirm audit scope and objectives
- Introduce audit team and methodology
- Agree on communication channels and logistics
Evidence Collection
- Interview control owners and operators
- Review documentation and records
- Observe processes in operation
- Inspect technical configurations
Control Verification
- Test control design (does it address the risk?)
- Test control operation (is it working as intended?)
- Sample transactions and records
- Document all evidence collected
Closing Meeting
- Present preliminary findings
- Clarify any factual inaccuracies
- Agree on finding classification
- Confirm corrective action timelines
Validation: All controls in scope assessed with documented evidence
Control Assessment
Control Testing Approach
- Identify control objective from ISO 27002
- Determine testing method (inquiry, observation, inspection, re-performance)
- Define sample size based on population and risk
- Execute test and document results
- Evaluate control effectiveness
- Validation: Evidence supports conclusion about control status
For detailed technical verification procedures by Annex A control, see security-control-testing.md.
Finding Management
Finding Classification
| Severity |
Definition |
Response Time |
| Major Nonconformity |
Control failure creating significant risk |
30 days |
| Minor Nonconformity |
Isolated deviation with limited impact |
90 days |
| Observation |
Improvement opportunity |
Next audit cycle |
Finding Documentation Template
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]
Corrective Action Workflow
- Auditee acknowledges finding and severity
- Root cause analysis completed within 10 days
- Corrective action plan submitted with target dates
- Actions implemented by responsible parties
- Auditor verifies effectiveness of corrections
- Finding closed with evidence of resolution
- Validation: Root cause addressed, recurrence prevented
Certification Support
Stage 1 Audit Preparation
Ensure documentation is complete:
Stage 2 Audit Preparation
Verify operational readiness:
Surveillance Audit Cycle
| Period |
Focus |
| Year 1, Q2 |
High-risk controls, Stage 2 findings follow-up |
| Year 1, Q4 |
Continual improvement, control sample |
| Year 2, Q2 |
Full surveillance |
| Year 2, Q4 |
Re-certification preparation |
Validation: No major nonconformities at surveillance audits.
Tools
scripts/
| Script |
Purpose |
Usage |
isms_audit_scheduler.py |
Generate risk-based audit plans |
python scripts/isms_audit_scheduler.py --year 2025 --format markdown |
Audit Planning Example
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
References
| File |
Content |
| iso27001-audit-methodology.md |
Audit program structure, pre-audit phase, certification support |
| security-control-testing.md |
Technical verification procedures for ISO 27002 controls |
| cloud-security-audit.md |
Cloud provider assessment, configuration security, IAM review |
Audit Performance Metrics
| KPI |
Target |
Measurement |
| Audit plan completion |
100% |
Audits completed vs. planned |
| Finding closure rate |
>90% within SLA |
Closed on time vs. total |
| Major nonconformities |
0 at certification |
Count per certification cycle |
| Audit effectiveness |
Incidents prevented |
Security improvements implemented |
1---2name: isms-audit-expert3description: Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicabilit...4license: MIT5---6
7# ISMS Audit Expert
8
9Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
10
11## Table of Contents
12
13- [Audit Program Management](#audit-program-management)
14- [Audit Execution](#audit-execution)
15- [Control Assessment](#control-assessment)
16- [Finding Management](#finding-management)
17- [Certification Support](#certification-support)
18- [Tools](#tools)
19- [References](#references)
20
21---
22
23## Audit Program Management
24
25### Risk-Based Audit Schedule
26
27| Risk Level | Audit Frequency | Examples |
28|------------|-----------------|----------|
29| Critical | Quarterly | Privileged access, vulnerability management, logging |
30| High | Semi-annual | Access control, incident response, encryption |
31| Medium | Annual | Policies, awareness training, physical security |
32| Low | Annual | Documentation, asset inventory |
33
34### Annual Audit Planning Workflow
35
361. Review previous audit findings and risk assessment results
372. Identify high-risk controls and recent security incidents
383. Determine audit scope based on ISMS boundaries
394. Assign auditors ensuring independence from audited areas
405. Create audit schedule with resource allocation
416. Obtain management approval for audit plan
427. **Validation:** Audit plan covers all Annex A controls within certification cycle
43
44### Auditor Competency Requirements
45
46- ISO 27001 Lead Auditor certification (preferred)
47- No operational responsibility for audited processes
48- Understanding of technical security controls
49- Knowledge of applicable regulations (GDPR, HIPAA)
50
51---
52
53## Audit Execution
54
55### Pre-Audit Preparation
56
571. Review ISMS documentation (policies, SoA, risk assessment)
582. Analyze previous audit reports and open findings
593. Prepare audit plan with interview schedule
604. Notify auditees of audit scope and timing
615. Prepare checklists for controls in scope
626. **Validation:** All documentation received and reviewed before opening meeting
63
64### Audit Conduct Steps
65
661. **Opening Meeting**
67 - Confirm audit scope and objectives
68 - Introduce audit team and methodology
69 - Agree on communication channels and logistics
70
712. **Evidence Collection**
72 - Interview control owners and operators
73 - Review documentation and records
74 - Observe processes in operation
75 - Inspect technical configurations
76
773. **Control Verification**
78 - Test control design (does it address the risk?)
79 - Test control operation (is it working as intended?)
80 - Sample transactions and records
81 - Document all evidence collected
82
834. **Closing Meeting**
84 - Present preliminary findings
85 - Clarify any factual inaccuracies
86 - Agree on finding classification
87 - Confirm corrective action timelines
88
895. **Validation:** All controls in scope assessed with documented evidence
90
91---
92
93## Control Assessment
94
95### Control Testing Approach
96
971. Identify control objective from ISO 27002
982. Determine testing method (inquiry, observation, inspection, re-performance)
993. Define sample size based on population and risk
1004. Execute test and document results
1015. Evaluate control effectiveness
1026. **Validation:** Evidence supports conclusion about control status
103
104For detailed technical verification procedures by Annex A control, see [security-control-testing.md](references/security-control-testing.md).
105
106---
107
108## Finding Management
109
110### Finding Classification
111
112| Severity | Definition | Response Time |
113|----------|------------|---------------|
114| Major Nonconformity | Control failure creating significant risk | 30 days |
115| Minor Nonconformity | Isolated deviation with limited impact | 90 days |
116| Observation | Improvement opportunity | Next audit cycle |
117
118### Finding Documentation Template
119
120```
121Finding ID: ISMS-[YEAR]-[NUMBER]
122Control Reference: A.X.X - [Control Name]
123Severity: [Major/Minor/Observation]
124
125Evidence:
126- [Specific evidence observed]
127- [Records reviewed]
128- [Interview statements]
129
130Risk Impact:
131- [Potential consequences if not addressed]
132
133Root Cause:
134- [Why the nonconformity occurred]
135
136Recommendation:
137- [Specific corrective action steps]
138```
139
140### Corrective Action Workflow
141
1421. Auditee acknowledges finding and severity
1432. Root cause analysis completed within 10 days
1443. Corrective action plan submitted with target dates
1454. Actions implemented by responsible parties
1465. Auditor verifies effectiveness of corrections
1476. Finding closed with evidence of resolution
1487. **Validation:** Root cause addressed, recurrence prevented
149
150---
151
152## Certification Support
153
154### Stage 1 Audit Preparation
155
156Ensure documentation is complete:
157- [ ] ISMS scope statement
158- [ ] Information security policy (management signed)
159- [ ] Statement of Applicability
160- [ ] Risk assessment methodology and results
161- [ ] Risk treatment plan
162- [ ] Internal audit results (past 12 months)
163- [ ] Management review minutes
164
165### Stage 2 Audit Preparation
166
167Verify operational readiness:
168- [ ] All Stage 1 findings addressed
169- [ ] ISMS operational for minimum 3 months
170- [ ] Evidence of control implementation
171- [ ] Security awareness training records
172- [ ] Incident response evidence (if applicable)
173- [ ] Access review documentation
174
175### Surveillance Audit Cycle
176
177| Period | Focus |
178|--------|-------|
179| Year 1, Q2 | High-risk controls, Stage 2 findings follow-up |
180| Year 1, Q4 | Continual improvement, control sample |
181| Year 2, Q2 | Full surveillance |
182| Year 2, Q4 | Re-certification preparation |
183
184**Validation:** No major nonconformities at surveillance audits.
185
186---
187
188## Tools
189
190### scripts/
191
192| Script | Purpose | Usage |
193|--------|---------|-------|
194| `isms_audit_scheduler.py` | Generate risk-based audit plans | `python scripts/isms_audit_scheduler.py --year 2025 --format markdown` |
195
196### Audit Planning Example
197
198```bash
199# Generate annual audit plan
200python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
201
202# With custom control risk ratings
203python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
204```
205
206---
207
208## References
209
210| File | Content |
211|------|---------|
212| [iso27001-audit-methodology.md](references/iso27001-audit-methodology.md) | Audit program structure, pre-audit phase, certification support |
213| [security-control-testing.md](references/security-control-testing.md) | Technical verification procedures for ISO 27002 controls |
214| [cloud-security-audit.md](references/cloud-security-audit.md) | Cloud provider assessment, configuration security, IAM review |
215
216---
217
218## Audit Performance Metrics
219
220| KPI | Target | Measurement |
221|-----|--------|-------------|
222| Audit plan completion | 100% | Audits completed vs. planned |
223| Finding closure rate | >90% within SLA | Closed on time vs. total |
224| Major nonconformities | 0 at certification | Count per certification cycle |
225| Audit effectiveness | Incidents prevented | Security improvements implemented |