What is covered under ISO 27001 Clause 9.2?
Clause 9 of the management requirements for ISO 27001:2022 is performance evaluation. 9.2 says the organisation shall conduct internal audits at planned intervals to provide information on whether the information security management system (ISMS):
- Conforms to the organisation's own requirements for its information security management system; and meets the requirements of the ISO 27001 international standard;
- Whether the ISMS is effectively implemented and maintained
To achieve those goals the ISO auditor will look to see that the organisation has:
- Planned, implemented and maintained an audit programme
- Defined the audit criteria and scope for each audit
- Selected auditors who will be objective and impartial
- Ensured that audits are reported to relevant management
- Retained documented information as evidence