ISO 27001 Lead Auditor · Domain 2
Audit Principles and Auditor Competence
About 15% of the exam
The seven ISO 19011 principles
- Integrity
- the foundation of professionalism
- Fair presentation
- report truthfully and accurately
- Due professional care
- diligence matched to the consequences
- Confidentiality
- protect the information obtained
- Independence
- impartial and free of conflict
- Evidence based
- verifiable evidence supports every conclusion
- Risk based
- effort follows significance and risk
Integrity, fair presentation, due care, confidentiality, independence, evidence and risk: seven principles, every one of them examinable
First, second and third party
- First party
- internal audit of your own system
- Second party
- a customer audits its supplier
- Third party
- independent body, certification or regulation
- Criteria
- agreed before the audit starts
- Certification
- only a third party grants it
- Second party scope
- contract terms may exceed the standard
- Internal auditors
- employees or contracted specialists
A second party auditor reports against the agreed criteria, even when the finding sits outside ISO/IEC 27001 itself
Auditor competence
- Personal behavior plus knowledge and skills
- Education, work experience, audit experience
- Information security management principles understood
- Risk and control concepts understood
- Sector knowledge where the scope demands
- Maintained through continual professional development
- Evaluated, reevaluated and recorded
Personal behavior expected
- Ethical, open minded, diplomatic
- Observant, perceptive and versatile
- Tenacious yet able to decide
- Self reliant and acting independently
- Open to improvement and feedback
- Culturally aware and collaborative
Independence threats
- Auditing a system you helped build
- Consulting for the same client recently
- Financial or family interest present
- Pressure to reduce the finding count
- Long unbroken relationship with one auditee
- Gifts, hospitality or future job offers
Audit roles
- Audit client
- the party requesting the audit
- Auditee
- the organization being audited
- Team leader
- manages the team and decides
- Auditor
- collects and evaluates evidence
- Technical expert
- knowledge only, does not audit
- Guide
- arranges access, contacts and logistics
- Observer
- attends but takes no part
Risk based approach
- Deeper testing where significance is higher
- Prior findings pull attention back
- Change since the last audit matters
- Shrinking time means reprioritizing, not skipping
- Material reductions discussed with the client
Confidentiality duties
- Information used only for the audit
- Never disclosed to competitors or press
- Working papers protected and retained securely
- The duty outlives the engagement
- Personal data handled with equal care
Evidence based conclusions
- Verifiable records, observations and statements
- Record source, time and location
- A disputed finding must stay defensible
- Opinion alone is never evidence
- Samples chosen by the auditor
Handling pressure without losing the principle
- Notice the pressure
- Return to the criteria
- Recheck the evidence
- Consult the team leader
- Record the position
- Report objectively
- Consolidate findings only where evidence supports
- Late evidence evaluated, never waved through
- Disagreement recorded as an unresolved opinion
- Escalate through the audit client
- Never trade a finding for goodwill
Competence gaps in the moment
- Bring in a technical expert
- Ask a team member to verify
- Never bluff a technical conclusion
- Seek scheme guidance on interpretation
- Record what could not be verified
Rapid recall: principle to behavior
- Integrity
- no shortcuts and no favors
- Fair presentation
- report exactly what you found
- Due care
- judgment matched to consequence
- Confidentiality
- guard what you were shown
- Independence
- no stake in the outcome
- Evidence based
- conclusions you can defend later
- Risk based
- time spent where it matters
Reference strip: principles, parties, competence, roles, threats
Principles
- Integrity and fair presentation
- Due care and confidentiality
- Independence, evidence, risk
Parties
- First party is internal
- Second party is customer led
- Third party certifies
Competence
- Knowledge, skills, behavior
- Sector and discipline specific
- Evaluated and kept current
Roles
- Client requests, auditee hosts
- Team leader decides disputes
- Expert advises, guide assists
Threats
- Self review and recent consulting
- Pressure on finding counts
- Gifts and future employment
Quick exam traps
- Trap: A technical expert may raise findings like any auditor
- Trap: An internal auditor cannot audit anything outside their own department
- Trap: A second party audit can grant certification if the criteria match
- Trap: Reducing the number of findings on request is a matter of style
- Trap: The guide provided by the auditee may choose the sample
- Trap: Evidence given verbally by a manager is enough to close a concern
cybercertprep.com · original revision sheet written from the public body of knowledge