Preparing audit activities
The administration of the audit operations is covered in depth in the audit activities of ISO 19011. This methodical technique can assist in ensuring that your audits are efficient and reliable and strengthen the audit system. The individual steps in the process are detailed here:
- Performing the document review: After the initiation process, the required documents must be reviewed. This helps in determining the extent of the system documentation for the audit and to analyze any gap which decides the audit plan in the following step. These documents include but are not limited to the following:
- Information Security Management System (ISMS) scope and objectives
- Information Security (IS) policy
- ISMS risk register
- Statement of Applicability (SoA)
- Legal records
- Monitoring and measurement records
- Records of corrective actions
- Management reviews
The management system’s documented information must be analyzed in order to comprehend the auditee’...