Phase 1
Audit programme and plan
We define objective, scope, criteria and schedule, taking into account the state of the processes, the results of previous audits and any changes in the organisation.
Information security
A management system that is not audited degrades quietly. We verify that what was defined is being applied, that the evidence exists, and that the controls mitigate the risks they claim to mitigate.
We carry out internal audits with expert auditors independent of the advisory team, and support and guide the handling of the findings identified. When the organisation decides to prepare its own internal audit staff, we deliver the training and knowledge transfer they need to perform effectively.
Phase 1
We define objective, scope, criteria and schedule, taking into account the state of the processes, the results of previous audits and any changes in the organisation.
Phase 2
Interviews, direct observation, record review and technical verification that the controls operate as required against the defined criteria.
Phase 3
We document non-conformities, observations and opportunities for improvement with objective evidence, classified by severity.
Phase 4
We support the root cause analysis, the definition of corrective actions and the verification of their effectiveness, recorded in SORT Redmine.
No. The internal audit is a requirement of the standard and preparation for the external one, but certification is issued by an accredited certification body, which is independent of us.
Yes, using auditors from the audit team, independent of the advisory team that worked on the implementation. That separation is what preserves the impartiality the standard requires.
Yes. Audits of critical third parties are increasingly requested, both because of contractual requirements and because of control A.5.22 of ISO/IEC 27001.
your business partner