27007-4.1 | Auditing principles overview | 0 |
27007-4.2 | Integrity and ethical conduct | 0 |
27007-4.3 | Evidence-based approach | 1 |
27007-5.1 | Establishing the Audit Programme | 2 |
27007-5.2 | Audit Programme Objectives | 170 |
27007-5.3 | Audit Programme Risks | 0 |
27007-5.4 | Establishing the Programme Resources | 55 |
27007-5.5 | Implementing the Audit Programme | 2 |
27007-5.6 | Monitoring the Audit Programme | 2 |
27007-5.7 | Reviewing and Improving the Programme | 1 |
27007-6.1 | Initiating the Audit | 1 |
27007-6.2 | Preparing Audit Activities | 1 |
27007-6.3 | Conducting Audit Activities | 1 |
27007-6.4 | Preparing and Distributing the Audit Report | 1 |
27007-6.5 | Completing the Audit | 1 |
27007-6.6 | Audit Follow Up | 0 |
27007-7.1 | Determining Auditor Competence | 1 |
27007-7.2 | Auditor Evaluation Criteria | 1 |
27007-7.3 | Selection of Auditor Evaluation Method | 0 |
27007-7.4 | Conducting Auditor Evaluation | 1 |
27007-7.5 | Maintaining and Improving Auditor Competence | 1 |
27007-A.1 | Generic Competence | 0 |
27007-A.2 | Discipline Specific Competence | 0 |
27007-A.4 | Auditing context of the organization (Clause 4) | 0 |
27007-A.5 | Auditing leadership (Clause 5) | 0 |
27007-A.6 | Auditing planning (Clause 6) | 0 |
27007-A.7-10 | Auditing support through improvement (Clauses 7-10) | 0 |
27007-B.1 | Practical Guidance Examples | 0 |
1-3 | Scope, normative references, terms and definitions | 0 |
4 | Principles of auditing | 0 |
5 | Managing an audit programme | 0 |
5.1 | General: establishing the audit programme | 0 |
5.2 | Establishing audit programme objectives | 0 |
5.3 | Determining and evaluating audit programme risks and opportunities | 0 |
5.4 | Establishing audit programme | 0 |
5.4.1 | Roles and responsibilities of the individual(s) managing audit programme | 0 |
5.4.2 | Competence of individual(s) managing audit programme | 0 |
5.4.3 | Establishing extent of the audit programme | 0 |
5.4.4 | Determining audit programme resources | 0 |
5.5 | Implementing audit programme | 0 |
5.5.2 | Defining the objectives, scope and criteria for an individual audit | 0 |
5.5.3 | Selecting and determining audit methods | 0 |
5.5.4 | Selecting audit team members | 0 |
5.5.5 | Assigning responsibility for an individual audit to the audit team leader | 0 |
5.5.6 | Managing audit programme results | 0 |
5.5.7 | Managing and maintaining audit programme records | 0 |
5.6 | Monitoring audit programme | 0 |
5.7 | Reviewing and improving audit programme | 0 |
6 | Conducting an audit | 0 |
6.2 | Initiating audit | 0 |
6.2.2 | Establishing contact with auditee | 0 |
6.2.3 | Determining feasibility of audit | 0 |
6.3 | Preparing audit activities | 0 |
6.3.1 | Performing review of documented information | 0 |
6.3.2 | Audit planning | 0 |
6.3.3 | Assigning work to audit team | 0 |
6.3.4 | Preparing documented information for audit | 0 |
6.4 | Conducting audit activities | 0 |
6.4.10 | Conducting closing meeting | 0 |
6.4.2 | Assigning roles and responsibilities of guides and observers | 0 |
6.4.3 | Conducting opening meeting | 0 |
6.4.4 | Communicating during audit | 0 |
6.4.5 | Audit information availability and access | 0 |
6.4.6 | Reviewing documented information while conducting audit | 0 |
6.4.7 | Collecting and verifying information | 0 |
6.4.8 | Generating audit findings | 0 |
6.4.9 | Determining audit conclusions | 0 |
6.5 | Preparing and distributing audit report | 0 |
6.5.1 | Preparing audit report | 0 |
6.5.2 | Distributing audit report | 0 |
6.6 | Completing audit | 0 |
6.7 | Conducting audit follow-up | 0 |
7 | Competence and evaluation of auditors | 0 |
7.2 | Determining auditor competence | 0 |
7.2.2 | Personal behaviour | 0 |
7.2.3 | Knowledge and skills | 0 |
7.2.4 | Achieving auditor competence | 0 |
7.2.5 | Achieving audit team leader competence | 0 |
7.3 | Establishing auditor evaluation criteria | 0 |
7.4 | Selecting appropriate auditor evaluation method | 0 |
7.5 | Conducting auditor evaluation | 0 |
7.6 | Maintaining and improving auditor competence | 0 |
A | Annex A (informative): guidance for ISMS auditing practice | 0 |
A:10.1 | Annex A: auditing ISO/IEC 27001:2013, 10.1 Nonconformity and corrective action | 0 |
A:10.2 | Annex A: auditing ISO/IEC 27001:2013, 10.2 Continual improvement | 0 |
A:4.1 | Annex A: auditing ISO/IEC 27001:2013, 4.1 Understanding the organization and its context | 0 |
A:4.2 | Annex A: auditing ISO/IEC 27001:2013, 4.2 Understanding the needs and expectations of interested parties | 0 |
A:4.3 | Annex A: auditing ISO/IEC 27001:2013, 4.3 Determining the scope of the information security management system | 0 |
A:4.4 | Annex A: auditing ISO/IEC 27001:2013, 4.4 Information security management system | 0 |
A:5.1 | Annex A: auditing ISO/IEC 27001:2013, 5.1 Leadership and commitment | 0 |
A:5.2 | Annex A: auditing ISO/IEC 27001:2013, 5.2 Policy | 0 |
A:5.3 | Annex A: auditing ISO/IEC 27001:2013, 5.3 Organizational roles, responsibilities and authorities | 0 |
A:6.1.1 | Annex A: auditing ISO/IEC 27001:2013, 6.1.1 Actions to address risks and opportunities: general | 0 |
A:6.1.2 | Annex A: auditing ISO/IEC 27001:2013, 6.1.2 Information security risk assessment | 0 |
A:6.1.3 | Annex A: auditing ISO/IEC 27001:2013, 6.1.3 Information security risk treatment | 0 |
A:6.2 | Annex A: auditing ISO/IEC 27001:2013, 6.2 Information security objectives and planning to achieve them | 0 |
A:7.1 | Annex A: auditing ISO/IEC 27001:2013, 7.1 Resources | 0 |
A:7.2 | Annex A: auditing ISO/IEC 27001:2013, 7.2 Competence | 0 |
A:7.3 | Annex A: auditing ISO/IEC 27001:2013, 7.3 Awareness | 0 |
A:7.4 | Annex A: auditing ISO/IEC 27001:2013, 7.4 Communication | 0 |
A:7.5 | Annex A: auditing ISO/IEC 27001:2013, 7.5 Documented information | 0 |
A:8.1 | Annex A: auditing ISO/IEC 27001:2013, 8.1 Operational planning and control | 0 |
A:8.2 | Annex A: auditing ISO/IEC 27001:2013, 8.2 Information security risk assessment (operation) | 0 |
A:8.3 | Annex A: auditing ISO/IEC 27001:2013, 8.3 Information security risk treatment (operation) | 0 |
A:9.1 | Annex A: auditing ISO/IEC 27001:2013, 9.1 Monitoring, measurement, analysis and evaluation | 0 |
A:9.2 | Annex A: auditing ISO/IEC 27001:2013, 9.2 Internal audit | 0 |
A:9.3 | Annex A: auditing ISO/IEC 27001:2013, 9.3 Management review | 0 |