Internal ISMS Audit
Conducted a complete internal ISMS audit following ISO 19011 auditing guidelines to evaluate compliance with ISO/IEC 27001 controls and verify operational effectiveness before certification.
To better understand the audit lifecycle, I performed an end-to-end internal audit from planning through reporting. The engagement included audit planning, evidence collection, interviews, sampling, control testing, reporting, and corrective action tracking.
- Develop an audit program.
- Evaluate implemented security controls.
- Verify compliance through evidence.
- Record observations and nonconformities.
- Recommend corrective actions.
- ISO 19011
- ISO 27001
- Audit Checklists
- Evidence Register
- Microsoft Excel
Prepared audit plans, interviewed process owners, reviewed security documentation, sampled evidence, evaluated controls, classified findings, and drafted a formal audit report.
- Internal Audit Plan
- Audit Checklist
- Evidence Register
- Audit Report
- Corrective Action Register
The project improved my ability to gather objective evidence, evaluate controls consistently, and present findings using internationally recognized auditing practices.