The ISO 27001 Clause 7.3 audit checklist is designed to help an ISO 27001 Lead Auditor conduct internal audits and external audits of ISO 27001 Clause 7.3 Awareness.
The 10 point ISO 27001 audit plan sets out what to audit, the challenges faced and the audit techniques to adopt.
With over 30 years industry experience I will show you the audit checklist used by professional ISO 27001 Lead Auditors for ISO 27001 certification.
I am Stuart Barker, author of the Ultimate ISO 27001 Toolkit and this is the ISO 27001 Awareness audit checklist.
Awareness Programme Content
Verify the content of the awareness programme covers all required topics (policy, contributions, responsibilities, breaches, legal/regulatory).
Challenges
Ensuring content is up-to-date and reflects current threats and best practices. Making content relevant to different audiences.
Audit Techniques
Review training materials, presentations, online modules, and other awareness resources.
Target Audience Identification
Confirm that different target audiences (e.g., new hires, specific departments) are identified and their specific awareness needs are considered.
Challenges
Identifying all relevant parties who need awareness training (e.g., contractors, temporary staff). Tailoring training to different roles and responsibilities.
Audit Techniques
Review training plans, audience lists, and interview HR and departmental managers.
Delivery Methods
Check that a variety of delivery methods are used to maximise engagement (e.g., online modules, in-person training, posters, newsletters).
Challenges
Finding the right mix of delivery methods to suit different audiences and learning styles. Making training interactive and engaging.
Audit Techniques
Review training materials, observe training sessions, and interview staff about their preferred learning methods.
Frequency of Training
Confirm that awareness training is provided regularly and at appropriate intervals (e.g., annual refresher training).
Challenges
Determining the optimal frequency of training. Balancing the need for regular training with the risk of “training fatigue.”
Audit Techniques
Review training schedules, attendance records, and interview staff about the frequency of training.
New Hire Training
Verify that new hires receive information security awareness training as part of their induction process.
Challenges
Ensuring new hire training is delivered promptly and effectively. Integrating security awareness into the broader onboarding process.
Audit Techniques
Review new hire training materials, induction procedures, and interview new employees.
Communication of Policy and Procedures
Check that the information security policy and related procedures are readily accessible to all personnel.
Challenges
Making policies and procedures easy to understand and navigate. Ensuring staff know where to find these documents.
Audit Techniques
Review how policies and procedures are communicated (e.g., intranet, hard copies), and interview staff about their accessibility.
Awareness Campaigns
Confirm that awareness campaigns are conducted to reinforce key messages and address specific threats.
Challenges
Designing effective awareness campaigns that capture attention and change behaviour. Measuring the impact of campaigns.
Audit Techniques
Review campaign materials (e.g., posters, emails), and interview staff about their awareness of recent campaigns.
Testing Effectiveness
Verify that the effectiveness of awareness training is tested (e.g., quizzes, surveys, simulated phishing exercises).
Challenges
Designing effective testing methods. Measuring the long-term impact of training on behaviour.
Audit Techniques
Review test results, survey data, and the results of simulated phishing attacks.
Record Keeping
Ensure that records of awareness training, including attendance and test results, are maintained.
Challenges
Maintaining accurate and up-to-date records. Ensuring records are easily accessible.
Audit Techniques
Examine training records, attendance sheets, and test scores.
Continual Improvement
Verify that the organisation seeks to continually improve its awareness programme based on feedback and evaluation results.
Challenges
Gathering and analysing feedback on the effectiveness of training. Implementing changes to improve the programme.
Audit Techniques
Review feedback from training participants, management review minutes, and interview HR and departmental managers about improvement initiatives.
Further Reading
ISO 27001 Clause 7.3 Awareness