What are the pitfalls to avoid in conducting ISO 27001 audits?

Some pitfalls to avoid when organising and conducting an ISO 27001 audit include:

  • Not communicating the scope and criteria effectively enough for the audit and inadequate planning/confirmation with the departments/areas being audited.
  • Allowing auditees to assume control of the audit, potentially avoiding responses to the questions asked
  • Not collecting adequate objective evidence to support statements of conformance or nonconformance
  • Allowing subjectivity to influence audit findings and conclusions - i.e. not being objective
  • Being poorly prepared and not understanding the policies, clauses or controls that are being audited
  • Following audit trails that are inconsequential and compromise the ability to conduct the audit in the available timeframe.
No items found.
"
From beginning to end URM made achieving PCI compliance incredibly easy & worked with us to educate us on the requirements. They were always available for a call whenever we needed to discuss queries along the way & were always flexible to our internal deadlines. We would highly recommend URM from a consultancy & auditing perspective.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.