The ISO 27001 internal audit is a prerequisite to Stage 1 of the certification process, where either your organization or a third-party firm will assess the effectiveness of your information security management system (ISMS) to meet clause 9.2 of the ISO 27001 standards.
This is the first installment in a two-part series on the ISO 27001 certification process. Through the rest of this series, we’ll outline requirements for stage 1 and stage 2 of the audit as well as what it means to obtain ISO 27001 certification.
“The internal audit is the biggest lift for organizations when preparing for ISO 27001 certification,” said Whitney Perez, director of quality and compliance at BARR Advisory. This process is beneficial for several reasons, including:
Let’s take a look at what to expect when you’re first starting your ISO 27001 certification during the internal audit.
Clause 9.2 of the ISO 27001 standard is one of the more complex requirements to achieve certification. This is due to the detailed requirements and possible need for outside assistance.
During the internal audit, it’s required that your ISMS not only conforms to your organization’s own requirements (9.2a), but that those requirements of this standard are effectively implemented and maintained (9.2b).
Here are the additional requirements for clause 9.2 of the internal audit according to the ISO 27001/IEC 27001 standards:
“While it’s recommended to conduct these internal audits on an annual basis, there’s no requirement to audit against all ISO clauses and Annex A controls at once,” said Perez. “You can make an audit plan that suits your needs. Your organization’s plan may span multiple years, testing controls on a rotational basis.”
If this is your first ISO 27001 audit, or your organization might need extra assistance, you can employ an independent third-party firm to help complete your internal audit. Consulting firms like BARR will help you create policies and complete your internal audit while maintaining independence.
Perez said, “While it’s not required, most organizations who use a third-party auditor for their internal audit experience a greater level of success within the certification process.”
Still not sure where to start? Not to worry. At BARR, we have a list of best-fit experts we can refer you to when it comes to completing your internal audit.
Once you’ve completed your internal audit and have developed and implemented the other ISO documentation and processes outlined in ISO 27001, you’re now geared up for Stage 1 and Stage 2 of the ISO 27001 certification process:
For more information, see our ISO 27001 Engagement Process.
Additionally, BARR is one of only nine firms in the nation who can help you obtain both an ISO 27001 certification and SOC 2 report upon project completion. Through our “test once, report many” approach, we save you time and resources to help you meet regulatory requirements and ensure customer trust.
Interested in connecting with a specialist from our ISO team? Contact us for a free consultation.