The ISO 27001 Clause 7.2 audit checklist is designed to help an ISO 27001 Lead Auditor conduct internal audits and external audits of ISO 27001 Clause 7.2 Competence.
The 10 point ISO 27001 audit plan sets out what to audit, the challenges faced and the audit techniques to adopt.
With over 30 years industry experience I will show you the audit checklist used by professional ISO 27001 Lead Auditors for ISO 27001 certification.
I am Stuart Barker, author of the Ultimate ISO 27001 Toolkit and this is the ISO 27001 Competence audit checklist.
Role Definition and Competence Requirements
Verify that roles impacting information security have clearly defined responsibilities and corresponding competence requirements.
Challenges
Ensuring job descriptions are up-to-date and accurately reflect the necessary skills. Mapping competence requirements to specific tasks can be complex.
Audit Techniques
Review job descriptions, organisational charts, competency frameworks, and interview personnel to understand their roles and required skills.
Training Needs Analysis
Check that a process exists to identify training needs related to information security.
Challenges
Accurately identifying skill gaps and predicting future training needs. Keeping training needs analysis up-to-date.
Audit Techniques
Review training needs analysis documentation, interview HR and departmental managers, and examine past training records.
Training Plans and Delivery
Confirm that training plans are in place to address identified needs and that training is delivered effectively.
Challenges
Delivering training in a way that is engaging and effective. Measuring the effectiveness of training.
Audit Techniques
Review training plans, training materials, attendance records, and evaluate training delivery methods (e.g., online, in-person).
Competence Evaluation
Ensure that the effectiveness of training and other actions taken to improve competence is evaluated.
Challenges
Designing effective evaluation methods. Measuring the impact of training on job performance.
Audit Techniques
Review post-training evaluations, on-the-job assessments, performance reviews, and interview staff about the impact of training.
Record Keeping
Verify that records of training, qualifications, and other evidence of competence are maintained.
Challenges
Maintaining accurate and up-to-date records. Ensuring records are easily accessible.
Audit Techniques
Examine training records, CVs, certifications, and other documentation demonstrating competence.
Awareness Training
Confirm that all personnel receive appropriate information security awareness training.
Challenges
Ensuring awareness training is relevant and engaging. Measuring the effectiveness of awareness training.
Audit Techniques
Review awareness training materials, attendance records, and conduct surveys to assess security awareness levels.
Specific Skills Training
Check that personnel with specific responsibilities (e.g., system administrators) receive specialised training.
Challenges
Keeping up with rapidly changing technologies and ensuring specialised training is available.
Audit Techniques
Review training records for specific roles, interview personnel in those roles, and examine relevant certifications.
On-the-Job Training/Mentoring
Verify that on-the-job training and mentoring are used where appropriate to develop competence.
Challenges
Providing effective on-the-job training and mentoring. Documenting on-the-job training activities.
Audit Techniques
Interview staff about mentoring and on-the-job training received, review mentoring plans, and observe staff performing tasks.
External Expertise
Confirm that the organisation uses external expertise where necessary to supplement internal competence.
Challenges
Selecting qualified external experts. Managing the work of external experts.
Audit Techniques
Review contracts with external providers, interview staff about the use of external expertise, and examine reports produced by external experts.
Continual Improvement of Competence Processes
Verify that the organisation seeks to continually improve its processes for managing competence.
Challenges
Identifying areas for improvement. Implementing changes effectively.
Audit Techniques
Review management review minutes, audit findings related to competence, and interview HR and departmental managers about improvement initiatives.
Further Reading
ISO 27001 Clause 7.2 Competence