ISO 27001 Clause 7.2 Audit Checklist

Home / ISO 27001 / ISO 27001 Lead Auditor / ISO 27001 Clause 7.2 Audit Checklist

The ISO 27001 Clause 7.2 audit checklist is designed to help an ISO 27001 Lead Auditor conduct internal audits and external audits of ISO 27001 Clause 7.2 Competence.

The 10 point ISO 27001 audit plan sets out what to audit, the challenges faced and the audit techniques to adopt.

With over 30 years industry experience I will show you the audit checklist used by professional ISO 27001 Lead Auditors for ISO 27001 certification.

I am Stuart Barker, author of the Ultimate ISO 27001 Toolkit and this is the ISO 27001 Competence audit checklist.

Role Definition and Competence Requirements

Verify that roles impacting information security have clearly defined responsibilities and corresponding competence requirements.

Challenges

Ensuring job descriptions are up-to-date and accurately reflect the necessary skills. Mapping competence requirements to specific tasks can be complex.

Audit Techniques

Review job descriptions, organisational charts, competency frameworks, and interview personnel to understand their roles and required skills.

Training Needs Analysis

Check that a process exists to identify training needs related to information security.

Challenges

Accurately identifying skill gaps and predicting future training needs. Keeping training needs analysis up-to-date.

Audit Techniques

Review training needs analysis documentation, interview HR and departmental managers, and examine past training records.

Training Plans and Delivery

Confirm that training plans are in place to address identified needs and that training is delivered effectively.

Challenges

Delivering training in a way that is engaging and effective. Measuring the effectiveness of training.

Audit Techniques

Review training plans, training materials, attendance records, and evaluate training delivery methods (e.g., online, in-person).

Competence Evaluation

Ensure that the effectiveness of training and other actions taken to improve competence is evaluated.

Challenges

Designing effective evaluation methods. Measuring the impact of training on job performance.

Audit Techniques

Review post-training evaluations, on-the-job assessments, performance reviews, and interview staff about the impact of training.

Record Keeping

Verify that records of training, qualifications, and other evidence of competence are maintained.

Challenges

Maintaining accurate and up-to-date records. Ensuring records are easily accessible.

Audit Techniques

Examine training records, CVs, certifications, and other documentation demonstrating competence.

Awareness Training

Confirm that all personnel receive appropriate information security awareness training.

Challenges

Ensuring awareness training is relevant and engaging. Measuring the effectiveness of awareness training.

Audit Techniques

Review awareness training materials, attendance records, and conduct surveys to assess security awareness levels.

Specific Skills Training

Check that personnel with specific responsibilities (e.g., system administrators) receive specialised training.

Challenges

Keeping up with rapidly changing technologies and ensuring specialised training is available.

Audit Techniques

Review training records for specific roles, interview personnel in those roles, and examine relevant certifications.

On-the-Job Training/Mentoring

Verify that on-the-job training and mentoring are used where appropriate to develop competence.

Challenges

Providing effective on-the-job training and mentoring. Documenting on-the-job training activities.

Audit Techniques

Interview staff about mentoring and on-the-job training received, review mentoring plans, and observe staff performing tasks.

External Expertise

Confirm that the organisation uses external expertise where necessary to supplement internal competence.

Challenges

Selecting qualified external experts. Managing the work of external experts.

Audit Techniques

Review contracts with external providers, interview staff about the use of external expertise, and examine reports produced by external experts.

Continual Improvement of Competence Processes

Verify that the organisation seeks to continually improve its processes for managing competence.

Challenges

Identifying areas for improvement. Implementing changes effectively.

Audit Techniques

Review management review minutes, audit findings related to competence, and interview HR and departmental managers about improvement initiatives.

Further Reading

ISO 27001 Clause 7.2 Competence

How to conduct an ISO 27001 Internal Audit

ISO 27001 Clause 9.2 Internal Audit

ISO 27001 Toolkit Business Edition

ISO 27001 Toolkit

Do It Yourself ISO 27001

Share to...