Plan an ISMS internal audit + build the checklist
Scenario
SwiftLend's ISMS is now 6 months old. Time for the first internal audit (Clause 9.2). External certification body arrives in 3 months. This internal audit MUST find real issues — a spotless report will make the certifier suspicious. Scope: audit 4 Annex A controls in depth — A.5.15 (Access control), A.5.23 (Cloud services), A.8.16 (Monitoring), A.8.32 (Change management).
Your role
You are the Internal Auditor.
Your task
Produce the audit programme: 1. Objective + scope + criteria (2 sentences each) 2. Sample size + selection rationale (privileged accounts / cloud subscriptions / monitoring alerts / changes) 3. Audit checklist — 3-5 test steps per control (12-20 test steps total) 4. Expected evidence per test 5. Documentation of independence (auditor doesn't audit own work)
Deliverable format: Audit programme document, ~800-1200 words
Toolkit
- ISO 27001:2022 Clause 9.2 — Internal audit
- Sample size: for access control, sample 15-25 of ~200 privileged accounts (never <10)
- Test steps: (a) obtain evidence, (b) verify against criterion, (c) note exceptions
- Independence: the person who granted access shouldn't audit access grants
Success criteria (what the AI grades against)
- Sample sizes justified (statistical or risk-based)
- Test steps are specific — not 'check access controls'
- Expected evidence named per test (e.g. 'AWS IAM export CSV', 'change ticket #')
- Independence explicitly addressed
- At least one test looks for TIMELINESS (e.g. 'access revoked within 24h of offboarding')
Log in to submit your deliverable for AI review.
Log in / Register