ISO 27001 Clause 7.3 Audit Checklist

Home / ISO 27001 / ISO 27001 Lead Auditor / ISO 27001 Clause 7.3 Audit Checklist

The ISO 27001 Clause 7.3 audit checklist is designed to help an ISO 27001 Lead Auditor conduct internal audits and external audits of ISO 27001 Clause 7.3 Awareness.

The 10 point ISO 27001 audit plan sets out what to audit, the challenges faced and the audit techniques to adopt.

With over 30 years industry experience I will show you the audit checklist used by professional ISO 27001 Lead Auditors for ISO 27001 certification.

I am Stuart Barker, author of the Ultimate ISO 27001 Toolkit and this is the ISO 27001 Awareness audit checklist.

Awareness Programme Content

Verify the content of the awareness programme covers all required topics (policy, contributions, responsibilities, breaches, legal/regulatory).

Challenges

Ensuring content is up-to-date and reflects current threats and best practices. Making content relevant to different audiences.

Audit Techniques

Review training materials, presentations, online modules, and other awareness resources.

Target Audience Identification

Confirm that different target audiences (e.g., new hires, specific departments) are identified and their specific awareness needs are considered.

Challenges

Identifying all relevant parties who need awareness training (e.g., contractors, temporary staff). Tailoring training to different roles and responsibilities.

Audit Techniques

Review training plans, audience lists, and interview HR and departmental managers.

Delivery Methods

Check that a variety of delivery methods are used to maximise engagement (e.g., online modules, in-person training, posters, newsletters).

Challenges

Finding the right mix of delivery methods to suit different audiences and learning styles. Making training interactive and engaging.

Audit Techniques

Review training materials, observe training sessions, and interview staff about their preferred learning methods.

Frequency of Training

Confirm that awareness training is provided regularly and at appropriate intervals (e.g., annual refresher training).

Challenges

Determining the optimal frequency of training. Balancing the need for regular training with the risk of “training fatigue.”

Audit Techniques

Review training schedules, attendance records, and interview staff about the frequency of training.

New Hire Training

Verify that new hires receive information security awareness training as part of their induction process.

Challenges

Ensuring new hire training is delivered promptly and effectively. Integrating security awareness into the broader onboarding process.

Audit Techniques

Review new hire training materials, induction procedures, and interview new employees.

Communication of Policy and Procedures

Check that the information security policy and related procedures are readily accessible to all personnel.

Challenges

Making policies and procedures easy to understand and navigate. Ensuring staff know where to find these documents.

Audit Techniques

Review how policies and procedures are communicated (e.g., intranet, hard copies), and interview staff about their accessibility.

Awareness Campaigns

Confirm that awareness campaigns are conducted to reinforce key messages and address specific threats.

Challenges

Designing effective awareness campaigns that capture attention and change behaviour. Measuring the impact of campaigns.

Audit Techniques

Review campaign materials (e.g., posters, emails), and interview staff about their awareness of recent campaigns.

Testing Effectiveness

Verify that the effectiveness of awareness training is tested (e.g., quizzes, surveys, simulated phishing exercises).

Challenges

Designing effective testing methods. Measuring the long-term impact of training on behaviour.

Audit Techniques

Review test results, survey data, and the results of simulated phishing attacks.

Record Keeping

Ensure that records of awareness training, including attendance and test results, are maintained.

Challenges

Maintaining accurate and up-to-date records. Ensuring records are easily accessible.

Audit Techniques

Examine training records, attendance sheets, and test scores.

Continual Improvement

Verify that the organisation seeks to continually improve its awareness programme based on feedback and evaluation results.

Challenges

Gathering and analysing feedback on the effectiveness of training. Implementing changes to improve the programme.

Audit Techniques

Review feedback from training participants, management review minutes, and interview HR and departmental managers about improvement initiatives.

Further Reading

ISO 27001 Clause 7.3 Awareness

How to conduct an ISO 27001 Internal Audit

ISO 27001 Clause 9.2 Internal Audit

ISO 27001 Toolkit Business Edition

ISO 27001 Toolkit

Do It Yourself ISO 27001

Share to...