International Organization for Standardization (ISO)
ISO/IEC 27001 information security management
The international standard for an information security management system and its Annex A controls.
Who it applies to
Any organisation that holds or seeks certification, or that uses the standard as its control baseline alongside the Saudi frameworks.
What internal audit has to show
Internal audit of the management system is itself a requirement of the standard. Audit has to cover the clauses and the applicable Annex A controls on a planned cycle and evidence it.
What Oversight does with ISO 27001
- Loads the clauses and the statement of applicability into the audit universe against the owning functions.
- Drafts the internal audit program across the cycle so every applicable control is covered on schedule.
- Requests and tracks the evidence, records the examination and drafts nonconformities with the source attached.
- Keeps corrective actions visible to closure and reports status to management review.
Typical engagements
- ISMS internal audit
- Annex A control effectiveness review
- Supplier security review
See a ISO 27001 engagement drafted from your scope
Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.
Request a demo