International Organization for Standardization (ISO)

    ISO/IEC 27001 information security management

    The international standard for an information security management system and its Annex A controls.

    Who it applies to

    Any organisation that holds or seeks certification, or that uses the standard as its control baseline alongside the Saudi frameworks.

    What internal audit has to show

    Internal audit of the management system is itself a requirement of the standard. Audit has to cover the clauses and the applicable Annex A controls on a planned cycle and evidence it.

    What Oversight does with ISO 27001

    • Loads the clauses and the statement of applicability into the audit universe against the owning functions.
    • Drafts the internal audit program across the cycle so every applicable control is covered on schedule.
    • Requests and tracks the evidence, records the examination and drafts nonconformities with the source attached.
    • Keeps corrective actions visible to closure and reports status to management review.

    Typical engagements

    • ISMS internal audit
    • Annex A control effectiveness review
    • Supplier security review

    See a ISO 27001 engagement drafted from your scope

    Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.

    Request a demo