ISO 27001 Lead Auditor · Domain 1
ISMS Foundations
About 15% of the exam
Clause by clause, what to ask for
- Clause 4
- scope statement, issues, party register
- Clause 5
- policy, roles, leadership evidence
- Clause 6
- criteria, assessment, SoA, objectives
- Clause 7
- competence, awareness, document control
- Clause 8
- assessment and treatment results
- Clause 9
- measures, audit records, review minutes
- Clause 10
- nonconformity and action records
Every clause names documented information the auditor can request by number before setting foot on site
Testing the SoA and the risk link
- Trace a risk forward to its control
- Trace a control back to a risk
- Check exclusion justifications actually hold
- Compare SoA status with operating evidence
- Look for controls applicable but dormant
- Check the SoA date against recent change
- Confirm the Annex A comparison happened
An implemented control with no risk behind it usually means the link is broken, not the control
Reading a risk assessment
- Criteria defined before the scoring
- Scores vary, not copied down
- Method stated and applied consistently
- Risk owners named for each entry
- Residual acceptance recorded in writing
- Dates not clustered before audits
Scope tests an auditor runs
- Compare scope wording to actual operations
- Check named sites still exist
- Follow information flows across boundaries
- Ask what happens at each interface
- Confirm central functions really serve sites
- Test exclusions against real activity
Mandatory documented information
- Scope, policy and security objectives
- Risk assessment and treatment processes
- The Statement of Applicability
- Competence evidence per role
- Operational planning and control confidence
- Assessment and treatment results
- Monitoring, audit and review results
- Nonconformities and actions taken
Evidence strength, weakest to strongest
- Verbal claim
- Policy document
- Documented procedure
- One record
- Sampled records over time
- Auditor observes operation
- Auditor directed reperformance
- Policy alone
- shows intent, never operation
- Single record
- one instance, not a pattern
- Sample
- supports a conclusion if representative
- Observation
- the auditor sees it happen
- Reperformance
- the auditor picks what is shown
When the auditee drives the screen, ask to choose the records yourself
The ISMS as one system
- Clauses interlock, findings ripple outward
- A scope error breaks risk coverage
- Weak competence surfaces during operation
- A missing review stalls improvement
- Report the systemic cause, not symptoms
Signals of a paper ISMS
- Risk assessments dated before each audit
- Identical scores across a whole category
- Staff cannot describe the policy
- Procedures contradict the stated policy
- Controls implemented days before stage 2
- Improvement log empty for a year
Standards an ISMS auditor cites
- ISO/IEC 27001
- the audit criteria itself
- ISO/IEC 27002
- control implementation guidance
- ISO/IEC 27005
- information security risk guidance
- ISO 19011
- guidance for auditing management systems
- ISO/IEC 27007
- audit guidance specific to ISMS
- ISO/IEC 27008
- assessing technical control implementation
- ISO/IEC 17021-1
- requirements on certification bodies
Terms auditors must not blur
- Conformity
- meeting a stated requirement
- Effectiveness
- achieving the planned result
- Compliance
- meeting law or contract
- Correction
- fixing the instance found
- Corrective action
- removing the underlying cause
- Risk
- uncertainty affecting the objectives
Rapid recall: record to clause
- Scope
- clause 4.3
- Policy
- clause 5.2
- SoA
- clause 6.1.3
- Objectives
- clause 6.2
- Competence
- clause 7.2
- Assessment results
- clause 8.2
- Audit results
- clause 9.2
- Review results
- clause 9.3
- Actions taken
- clause 10.2
Questions that open a clause
- Who owns this and since when
- Show me the last three instances
- What triggers this activity
- What happened the last time it failed
- Who checks that this happened
Reference strip: clauses, records, scope, evidence, warning signs
Clauses
- Four to ten are auditable
- Annex A sits inside 6.1.3
- Findings map to a clause
Records
- Scope, policy, objectives
- Risk process, results, SoA
- Audit, review, corrective action
Scope
- Boundaries, interfaces, dependencies
- Sites and services named
- Exclusions tested against reality
Evidence
- Verifiable, sufficient, appropriate
- Sampled across the whole period
- Source, time and place recorded
Warning signs
- Activity clustered before audits
- Uniform risk scores
- Controls with no operating records
Quick exam traps
- Trap: A signed policy is evidence that the control operates
- Trap: Annex A controls may be audited without reference to the risk assessment
- Trap: An ISMS auditor certifies the organization personally
- Trap: Effectiveness and conformity mean the same thing
- Trap: A control implemented last week can show operating effectiveness
- Trap: The auditee decides which records the auditor may sample
cybercertprep.com · original revision sheet written from the public body of knowledge