Day 9 of 22ISMS · ISO 27001· ~60 min

Plan an ISMS internal audit + build the checklist

Scenario

SwiftLend's ISMS is now 6 months old. Time for the first internal audit (Clause 9.2). External certification body arrives in 3 months. This internal audit MUST find real issues — a spotless report will make the certifier suspicious. Scope: audit 4 Annex A controls in depth — A.5.15 (Access control), A.5.23 (Cloud services), A.8.16 (Monitoring), A.8.32 (Change management).

Your role

You are the Internal Auditor.

Your task

Produce the audit programme: 1. Objective + scope + criteria (2 sentences each) 2. Sample size + selection rationale (privileged accounts / cloud subscriptions / monitoring alerts / changes) 3. Audit checklist — 3-5 test steps per control (12-20 test steps total) 4. Expected evidence per test 5. Documentation of independence (auditor doesn't audit own work)

Deliverable format: Audit programme document, ~800-1200 words

Toolkit

  • ISO 27001:2022 Clause 9.2 — Internal audit
  • Sample size: for access control, sample 15-25 of ~200 privileged accounts (never <10)
  • Test steps: (a) obtain evidence, (b) verify against criterion, (c) note exceptions
  • Independence: the person who granted access shouldn't audit access grants

Success criteria (what the AI grades against)

  • Sample sizes justified (statistical or risk-based)
  • Test steps are specific — not 'check access controls'
  • Expected evidence named per test (e.g. 'AWS IAM export CSV', 'change ticket #')
  • Independence explicitly addressed
  • At least one test looks for TIMELINESS (e.g. 'access revoked within 24h of offboarding')

Log in to submit your deliverable for AI review.

Log in / Register