Running an audit programme

Running an audit programme

Running an internal audit programme is a mandatory requirement within all management systems that seek to be certified by an external entity. However internal audits provide plenty of information on the conformity of the ISMS and should therefore being conducted even without the objective of certification.

One thing that often leads to confusion even among experienced auditors is the proper distinction between an audit and an audit program. ISO 27000 defines an audit as?

“ a systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are met."

Audits are conducted by audit teams, which consist of auditors and subject matter experts with a profound knowledge and experience in their field.?

An audit program is?

?"a set of one or more?audits?planned for a specific time frame and directed towards a specific purpose."


In other words an audit programme encompasses all the audits that are necessary to achieve a defined purpose with given restrictions like time or budget.

ISO 19011 provides guidance on auditing management systems, including the principles of auditing, managing an audit programme and conducting management system audits. With special regards to individual(s) managing the audit programme, auditors and audit teams. The following graph displays the process of managing an audit programme according to the standard PDCA cycle. Note how an audit programme can consist of multiple audits as depicted in step 5.5.

No alt text provided for this image
Michael Brooke

@Crayon supporting partners and their end clients to improve cyber security posture improvement

2 年

Thanks for writing these up Aron, really useful material.

回复

要查看或添加评论,请登录

Aron Lange的更多文章

  • 4 New and Free Resources by NIST

    4 New and Free Resources by NIST

    I haven't used my LinkedIn Newsletter in a while. But, due to popular request, I'm giving it another shot.

    1 条评论
  • The Top 5 Newsletters of 2023

    The Top 5 Newsletters of 2023

    In 2023, I sent out 25 newsletters about Governance, Risk and Compliance topics. Here are the most popular editions of…

  • Introducing LearnGRC

    Introducing LearnGRC

    Dear Readers, when I started this newsletter, I wanted to focus on demystifying the world of information security…

    16 条评论
  • My Journey to Becoming a Certified Information Security Manager (CISM)

    My Journey to Becoming a Certified Information Security Manager (CISM)

    Dear Community, I have some thrilling news to share with you! I have decided to embark on a journey towards becoming a…

    4 条评论
  • The All-New Resource Center

    The All-New Resource Center

    Dear Readers, I am thrilled to announce the release of Resource Center! As security professionals, we are always on the…

    15 条评论
  • Cybersecurity Made Easy: Free and Low-Cost Courses

    Cybersecurity Made Easy: Free and Low-Cost Courses

    In today's world, cybersecurity is becoming more and more critical. With the rise of cyberattacks, the need for…

    8 条评论
  • Free Resources for Security and GRC

    Free Resources for Security and GRC

    Here is my list of free resources that will help you to break into GRC and information security. By the way, this is…

    10 条评论
  • The new ISO 27002:2022

    The new ISO 27002:2022

    For the first time since 2013 a new revision of ISO 27002 has been published. In case you think thats too good to be…

    12 条评论
  • Security Controls

    Security Controls

    In this edition of InfoSec Insights we are going to talk about controls. You will learn what controls are used for and…

    2 条评论
  • ISO 27005 - Risk Management

    ISO 27005 - Risk Management

    ISO/IEC 27005 provides guidance on implementing a process-oriented risk management approach to assist in implementing…

    35 条评论

社区洞察

其他会员也浏览了