Skip to content
GitHubLinkedIn

ISMS internal audit (draft)

ISO 27001 expects periodic internal audits of the ISMS. This page provides a minimal audit structure and templates.

OwnerInformation Security Officer
Contactinfra@lef.tec.br
Version0.1
Last updated2025-12-24
Review cadenceAnnual (or on audit approach changes)

Assess whether the ISMS is:

  • implemented as planned (process compliance)
  • effective for the defined scope (risk and control coverage)
  • maintained through improvement actions
  • Scope follows ISMS scope (draft).
  • Criteria may include: ISO/IEC 27001 requirements, the SoA, and internal policies/procedures.

Audits should be performed by people who are sufficiently independent of the area being audited.

  1. Plan the audit (scope, criteria, schedule).
  2. Collect evidence (documents, records, interviews).
  3. Record findings (conformities, nonconformities, observations).
  4. Report results and agree corrective actions.
  5. Verify effectiveness and close findings.
FieldValue
Audit period
Scope
Criteria
Auditor(s)
Auditees
Output location