ISO 27001 Lead Auditor · Domain 3
Audit Program and Planning
About 18% of the exam
Program versus plan
- Audit program
- all audits across a period
- Program objectives
- set by management, risk informed
- Program risks
- resourcing, competence and coverage gaps
- Audit plan
- arrangements for one audit
- Plan contents
- objectives, scope, criteria, dates, roles
- Plan flexibility
- changed by agreement while auditing
- Program review
- improved using audit results
One program covers many audits over time; one plan covers a single audit and is agreed with the auditee before it starts
Objectives, scope, criteria
- Objectives
- what this audit must achieve
- Scope
- extent, sites, processes and period
- Criteria
- requirements the evidence is compared to
- Typical criteria
- the standard plus internal policies
- No criterion
- then there is no finding
Determining audit time
- Driven by effective number of personnel
- Scope complexity and number of sites
- Technology and regulatory context
- Part time staff counted proportionally
- Reductions justified, never assumed
- Scheme rules cap the reduction
Stage 1 and stage 2
- Application and scope review
- Stage 1
- Close the gaps
- Stage 2
- Closing meeting
- Certification decision
- Stage 1 purpose
- readiness, documentation, scope confirmation
- Stage 1 output
- areas of concern for stage 2
- Interval
- long enough to close gaps
- Stage 2 purpose
- evidence that the ISMS operates
- Stage 2 coverage
- all requirements of the standard
- Recertification
- stage 1 only after significant change
Stage 1 asks whether you are ready; stage 2 asks whether it actually works
Planning inputs the auditor demands
- Scope statement and the SoA
- Organization chart and process map
- Previous audit results and open findings
- Internal audit and management review records
- The exception or waiver register
- Sites, shifts and time zones
- Legal and contractual requirements register
- Changes since the last visit
Sampling plan
- Define the population before sampling
- Take the population from an independent source
- Cover the whole period, not one month
- Size reflects risk and population
- Record what was sampled and why
- An incomplete population invalidates the result
Multi site planning
- Central function verified before site sampling
- Sample sites across risk and geography
- Not every site can be visited
- Sample size grows with site count
- High risk sites visited more often
Remote auditing
- Agreed between body and organization
- Physical controls cannot be observed directly
- Site atmosphere and behavior stay invisible
- Connectivity and evidence integrity are risks
- Mix remote work with on site work
- Record the techniques actually used
Integrated management systems
- State which standards are in criteria
- Shared processes audited once, reported separately
- Time allowed for each standard
- Competence needed for every discipline
- Findings mapped to the right standard
Planning red flags
- Scope excludes a busy subsidiary
- No time allowed for supplier controls
- Sample list supplied only by the auditee
- Every audit crammed into one week
- Auditor lacks the sector knowledge needed
- Previous major finding never revisited
Working documents
- Checklists tied to the criteria
- Sampling plans with populations recorded
- Forms for recording evidence
- Never a script that blocks follow up
- Protected as confidential information
- Retained per certification body rules
Opening meeting agenda
- Introduce the team and roles
- Confirm objectives, scope and criteria
- Confirm the plan and timings
- Explain sampling and its limits
- Agree communication and escalation routes
- Confirm safety, access and confidentiality
- Set the closing meeting time
Adjusting a plan mid audit
- Unreachable objectives must be reported
- Discuss changes with the audit client
- Reallocate remaining time using risk
- Never drop coverage silently
- Record every change to the plan
- An extra day beats a shallow conclusion
When the objectives cannot be met in the time available, the answer is to say so, not to thin the sample quietly
Rapid recall: plan contents
- Objectives, scope and criteria
- Dates, locations and timings
- Team roles and technical experts
- Areas and processes to be audited
- Communication and reporting arrangements
- Logistics, access and confidentiality
Scheme documents behind the plan
- ISO 19011
- guidance for auditing management systems
- ISO/IEC 17021-1
- requirements for certification bodies
- ISO/IEC 27006
- ISMS certification body requirements
- ISO/IEC 27007
- how to audit an ISMS
- Scheme rules
- the body adds its own
Reference strip: program, plan, stages, sampling, time
Program
- Many audits over a period
- Objectives set by management
- Reviewed and improved yearly
Plan
- One audit, agreed in advance
- Objectives, scope, criteria stated
- Changes agreed and recorded
Stages
- Stage 1 tests readiness
- Stage 2 tests operation
- Gap between them for fixes
Sampling
- Population defined independently
- Spread across the whole period
- Auditor selects the items
Time
- Effective personnel drive duration
- Complexity and sites add days
- Reductions justified against scheme rules
Quick exam traps
- Trap: The audit program and the audit plan are two names for one document
- Trap: Every site in a multi site scope must be visited each year
- Trap: A fully remote audit can verify physical controls equally well
- Trap: Audit duration depends only on headcount
- Trap: The auditee may provide the population list used for sampling
- Trap: A stage 1 audit is always required before recertification
- Trap: Running short on time justifies dropping an area without telling anyone
cybercertprep.com · original revision sheet written from the public body of knowledge