4. Incidents, audits and improvement
Audits, and how to behave in one
Audits are where the ISMS is tested against reality. There are two kinds, and you may meet either.
Internal audits
ISO 27001 requires the organisation to audit its own ISMS at planned intervals. Internal audits are carried out by trained staff or contractors who are independent of the area they are auditing, and their purpose is to find problems before they matter: gaps between policy and practice, controls that have drifted, records that are missing. Findings from internal audits feed the improvement cycle. Treat internal auditors as allies doing exactly what the standard asks.
External audits
External audits are performed by the certification body. After the initial certification audit, surveillance audits happen regularly, with a full recertification audit completing the cycle, typically every three years. External auditors review documents and records, observe working practices, and interview staff at all levels. Serious findings, called major nonconformities, can lead to certification being suspended or withdrawn if not corrected, which is why audit periods get organisational attention.
If an auditor talks to you
Being interviewed is normal and not a test you can fail personally. The auditor wants to know whether the ISMS is real, and ordinary staff are the best evidence. Some straightforward rules:
- Answer honestly. Describe what actually happens, not what you think should happen
- Do not guess. If you do not know an answer, say so and say who you would ask or where you would look. That is a good answer, because knowing where to find the policy is exactly what is expected of you
- Keep answers to what you know first-hand, and do not speculate about other teams
- Never invent, backdate, or polish records for an audit. Fabricating evidence is far more serious than any gap it hides
A useful reframe: an auditor asking you how you report an incident is giving the organisation a chance to show its training works. If this course has done its job, you can answer that one already.
› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement
Putting it into practice