Your organisation should aim to conduct internal audits on the mandatory clauses of the Standard, Annex A controls, other relevant controls, and your own organisational processes that support the implementation of your ISMS. The Standard promotes the use of a risk-based approach to auditing, i.e., the areas that are likely to suffer the greatest impact of a risk or is the most vulnerable should be prioritised. You should aim to have completed an audit on every element of your organisation at least once over a 3 year period.
related BLog
No items found.
"
Our consultant was very thorough and knowledgeable when delivering the ISO 27001 pre-stage-2 internal audit.
contact US
Let us help you
Let us help you in your compliance journey by completing the form and letting us know how we can best support you.

