Internal Audit Procedure
Internal Audit Procedure
PROCEDURE
VERSION 1.1
REVISION HISTORY
Date of
Sr. No. Ver. Validity Description of change Reviewed By Approved By
Revision
1 18/03/12 1.0 One Year Initialization Nasser A. Ammar Dr. Mohammed A Alnuem
10
DISTRIBUTION LIST
TABLE OF CONTENTS
1. PURPOSE .................................................................................................. 4
2. SCOPE ...................................................................................................... 4
6. INVOCATION ............................................................................................ 5
9. OUTPUTS................................................................................................ 11
1. PURPOSE
To provide a formal, precise, complete and detailed plan on which the ISMS audit will be carried out.
The objective of the audit is to check over a specified regular audit period that all aspects of the
ISMS are functioning as intended and the compliance of the ISMS to the ISO 27001 standard is
maintained at an acceptable level.
2. SCOPE
This procedure applies to King Saud University (KSU) - eTransactions & Communication (ETC)
Deanship and all parties, its affiliated partners or subsidiaries, including data processing and process
control systems, that are in possession of or using information and/or facilities owned by KSU-ETC
Deanship.
This procedure applies to all staff/ users that are directly or indirectly employed by KSU-ETC
Deanship, subsidiaries or any entity conducting work on behalf of KSU that involves the use of
information assets owned by ETC Deanship.
Disciplinary action will be depending on the severity of the violation which will be determined by the
investigations. Actions such as termination or others as deemed appropriate by ETC Management
and Human Resources Department will be taken.
5. DOCUMENT OWNER
ISMS Manager
7. INVOCATION
This procedure shall be followed whenever there is:
Annual Audit Plan
8. PROCESS FLOWCHART
Internal Audit
Periodic Audit
Ad-Hoc Audit
START
Step 5
Step 2
No
ISMS Manager
Step 6
Approval?
Develop Action
Plan
Reference to
Start / End Start and end of the procedure Another related procedure Input/
another Input or output infomation
Output
procedure
9. PROCEDURE DETAILS
This section reflects the broad activities/steps to be carried out in the procedure.
The ISMS Audit Team prepares the Annual Audit Plan covering the type
of audits as well as the frequency and methods of audit. The annual
Actions audit plan takes into consideration the status and importance of the
processes and areas to be audited, the Risk Assessment report, as well
as the results of previous audits.
The ISMS Audit Team submits the plan to the ISMS Manager for
Actions approval. Upon approval of the annual audit plan, the ISMS Audit Team
communicates the plan to the interested parties (Audittees)
The ISMS Audit Team collects and studies previous audit findings and
possible outstanding issues. Additionally, the team prepares all relevant
documents that will be needed for the realization of the audit (e.g. ISMS
Audit Checklist). Checklists or work-programs are instrumental in aiding
an audit that is thorough, effective and uniform.
Periodic audit checklists / work-programs must be in-depth and based
Actions
on ISO 27001 (using the template ISMS Audit Checklist), following a
predefined path and checking for compliance with controls. Follow-up
audit checklists/ work-programs must be limited to include only the
relative audit findings. Ad-hoc audit checklists/ work-programs must
always be focused on the trigger event. Therefore ad-hoc audit
checklists must be created anew prior to each ad-hoc audit.
Based on the audit findings, the ISMS Audit Team prepares the audit
report. This is a report referring to non-compliance, unresolved issues,
high residual risks, etc. Any audit finding must be labeled according to
its priority level
Audit findings that are characterized as Priority 1 are major non-
conformities and must be planned for resolution in a period of 2 weeks
and a follow up audit must be scheduled at the end of that period. Note
that if considered critical, the resolution of certain audit findings may be
required ASAP
Actions
Audit findings that are characterized as Priority 2 are minor non-
conformities and must be planned for resolution in a period of 3
months and a follow up audit must be scheduled at the end of that
period
Audit findings that are characterized as Observation must be planned
for resolution in a period of 6 months and their progress must be
monitored in all of the following periodic audits until resolution
Audit findings and their corresponding non-conformance must be
communicated to the ISMS Manager at the end of each audit
Action Plan
Output
Follow up Audit
10. OUTPUTS
The following activity will be an output of the process.
ISMS Annual Audit Plan
ISMS Audit Report
Action Plan
11. RECORDS
The following are the list of all applicable records that are the evidence of implementation of the
Process.
The records are maintained in hard and soft copy.
ISMS Annual Audit Plan
ISMS Audit Check List
12. ANNEXURE