A small company of 15 staff has one IT manager who configures and operates most controls. To satisfy clause 9.2's expectation of audit objectivity, which approach is most appropriate?
- A.Rely solely on the certification body's external audit instead of internal audit
- B.The IT manager audits their own controls since they know them best
- C.Skip auditing IT controls because independence is impossible in a small firm
- D.Have a different competent person, an employee from another function or an external auditor, audit the IT manager's area so auditors do not audit their own work
Why D is correct
Clause 9.2 requires the selection of auditors and conduct of audits to ensure objectivity and impartiality, and auditors should not audit their own work. Even in small organizations this can be met by using staff from other functions or an external resource.
Know someone studying for ISO 27001? Send them this one.