Summary
As you can see, a variety of skills should be taken into consideration to have the right individual to carry out efficient audits of your organization’s information security management system (ISMS). Some of these skills are required while others are only desired. Even though it is conceivable for a person who lacks sufficient competence to conduct an audit of parts of ISMS, a professional auditor or audit team is your best bet to move your company closer to its goal of incorporating audits into its ongoing cycle of continuous improvement.
In the next chapter, we will see case studies based on audit planning, reporting NCs, and drafting the final audit report.