What problem does it solve?
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.
Core Features & Use Cases
- Audit Program Management: Plan and manage audit programs with risk-based schedules and Annex A mapping.
- Audit Execution: Conduct audits with evidence collection, testing guidance, and closing activities.
- Control Assessment: Test and evaluate control effectiveness with guidance linked to ISO 27002.
- Finding Management: Classify findings, document evidence, and manage corrective actions.
- Certification Support: Prepare for Stage 1/Stage 2 and surveillance audits, ensure continual improvement.
- Tools & References: Access to the ISMS audit scheduler script and reference materials for procedures.
Quick Start
Outline the ISMS scope and SoA, then generate a risk-based audit plan and draft Stage 1/Stage 2 documentation.