Independent review of your ISMS

Does your ISMS work as intended?

An internal audit ISO 27001 shows whether your ISMS is well described and is working. Kynexis Information Security objectively assesses how the management system is set up, what measures have actually been introduced and what evidence shows that they work over time.

Do you recognize this?
  • You're working towards a first ISO 27001 certification.
  • Phase 1, phase 2, surveillance or recertification is approaching.
  • You want to periodically independent tests or controls to work demonstrably.
  • Board or management wants certainty about the design, existence and functioning of ISMS.

What are the risks? If policies, implementation and evidence are not consistent, deviations are often detected only during the certification audit. This causes repair work under time pressure and gives management insufficient certainty about the actual functioning of ISMS.

Our promise of service

Security before an external auditor asks questions

The internal audit shall make available in good time any deviations, lack of evidence and administratively relevant points of improvement.

  • Objective audit findings
  • Assessment of evidence and effect
  • Priorities for follow-up

ISO 27001 internal audit

What is Internal Audit ISO 27001?

An internal audit ISO 27001 shows whether your ISMS is well described and is working. Kynexis Information Security objectively assesses how the management system is set up, what measures have actually been introduced and what evidence shows that they work over time.

FOR WHOMFor organisations with an ISMS
WHENPeriodic review or preparation for certification
RESULTA substantiated picture of deviations and operation

When does this service fit?

Periodic review or preparation for certification

This audit fits with organisations with an equipped ISMS that have to periodically check whether the management system is demonstrably satisfactory and functioning. The audit may be used before stage 1 or phase 2, in the case of surveillance or recertification and as part of the internal audit programme.

For organisations with an ISMSFor ISMs managersFor the board and executive management

Research area

The ISMS, the controls and the evidence examined in conjunction

We set the precise scope and audit criteria in advance. Depending on your organisation, the following parts can be examined.

Scope, context and governance

Demarcation, stakeholders, objectives, roles, responsibilities and board-level engagement.

Risk analysis and treatment

Methodology, topicality, criteria, ownership, treatment choices, residual risk and link between risk and measure.

Statement of Application

Coherence between risks, chosen controls, actual design and justification of exclusions.

Policies and procedures

Usability, awareness and connection of fixed agreements to the daily execution.

Controls and evidence

Access, vulnerabilities, logging, backup, incidents, suppliers, awareness and continuity, among others.

Monitoring and improvement

Controls, management information, audit findings, corrective measures, management review and improvement cycle.

Evidence of control

Design, existence and operation

These concepts make it visible whether a measure goes beyond a description on paper.

DESIGN

Is the measure properly designed?

The chosen method is consistent with risk, organisation and purpose.

IMPLEMENTATION

Has the measure actually been implemented?

Rolls, processes and technical or organisational facilities are provided.

OPERATION

Does the measure work demonstrably?

Sampling and evidence show that the measure was carried out during the relevant period.

Your result

A substantiated picture of deviations and operation

The report follows the agreed scope and gives management and ISMS-responsible direction for follow-up.

  • Audit plan with scope, criteria and approach
  • Management summary with conclusions and risks
  • Underlying anomalies and observations
  • Evidence assessment of design, existence and operation
  • Priorities before certification or subsequent audit
  • Final discussion with management and ISMS responsible
KYNEXISISO 27001 internal audit
3Deviations7Observations21Demonstrable
FocusOperation, evidence and board-level follow-upRisk-driven and enforceable

Choose based on your question

GAP analysis, audit readiness or internal audit?

The right shape depends on your starting point, the moment and the certainty you need.

GAP-ANALYSE

Where are we?

Gaps and roadmap at the beginning or at the restart of the route.

See this route →
AUDIT-READINESS

Are we ready for the external audit?

Last vulnerabilities shortly before certification.

How we work

This is how the internal audit is conducted

  1. 01

    Entry and Scope

    Capture purpose, audit criteria, parts, roles, planning and available evidence.

  2. 02

    Document Review

    Scope, risk analysis, SoA, policy, management review, previous audits and improvement register review.

  3. 03

    Interviews and samples

    With relevant roles practical examples and actual execution tests.

  4. 04

    Evidence and re-examination

    Findings underpin and verify facts and context before conclusions become final.

  5. 05

    Reporting and discussion

    Deviations, observations, risks and priorities management-oriented.

Choose based on your question

Which form of research suits your decision-making needs?

The routes differ in purpose, depth and the type of support you need.

Make your next step concreteHave your ISMS independently tested internally?

Discuss the audit objective, scope, evidence available and planning towards the external certification audit.

Schedule an audit intake

Frequently Asked Questions

Practical answers on ISO 27001 internal audit

Is an internal audit mandatory for ISO 27001?

ISO/IEC 27001 requires the organisation to conduct internal audits at scheduled intervals to assess whether the ISMS meets relevant requirements and own agreements and is effectively implemented and maintained.

Can Kynexis conduct the internal audit?

Yes, if sufficient objectivity and impartiality can be secured. If Kynexis Information Security was materially responsible for the establishment of the components to be audited, another auditor may be more appropriate for the formal internal audit.

What is the difference between a GAP analysis and internal audit?

A GAP analysis is mainly investigating what is missing from the desired standard position. An internal audit will assess whether the existing ISMS is demonstrably satisfactory and works in practice.

Can the audit be used as preparation for certification?

Yes. The audit may reveal gaps, missing evidence and deviations before phase 1, phase 2, surveillance or recertification.

Does Kynexis also audit technical controls?

When they fall within the agreed scope, relevant technical controls and evidence of their operation may be included. We determine the exact depth in advance.

How long does an internal audit take?

This depends on the scope, scope and complexity of ISMS. We will determine the required audit size after the intake.

Wouter Parent

An internal audit shall not be valid until it looks beyond the documents available. The core is to determine independently whether agreements are being made, proof is reliable and it really helps steer ISMS.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates