3.1 ISO 19011 Auditing Concepts and Types of Audits
Key Takeaways
- ISO 19011 defines seven core principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach.
- Internal audits (first-party) are for self-declaration; second-party audits evaluate external providers; third-party audits are for independent certification.
- The risk-based approach ensures audit resources are focused on matters significant to the audit objectives.
3.1 ISO 19011 Auditing Concepts and Types of Audits
Auditing is fundamentally a structured, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. For an Information Security Management System (ISMS) based on ISO/IEC 27001, the auditing process is governed by the guidelines laid out in ISO 19011:2018 (Guidelines for auditing management systems). Understanding these foundational concepts is critical for any CQI/IRCA ISMS Lead Auditor.
The Seven Principles of Auditing
ISO 19011 defines seven core principles of auditing. These principles are not merely theoretical; they are the prerequisites for providing audit conclusions that are relevant and sufficient, and for ensuring that auditors working independently from one another will reach similar conclusions in similar circumstances.
-
Integrity: The Foundation of Professionalism Auditors and individuals managing audit programs must perform their work ethically, with honesty and responsibility. Integrity requires auditors to only undertake audit activities if they are competent to do so, perform their work in an impartial manner, and remain fair and unbiased in all dealings. This means resisting any pressures that might influence their judgment. Integrity ensures that the audit process is trusted by all stakeholders.
-
Fair Presentation: The Obligation to Report Truthfully and Accurately Audit findings, audit conclusions, and audit reports should reflect truthfully and accurately the audit activities. Significant obstacles encountered during the audit and unresolved diverging opinions between the audit team and the auditee should be reported. The communication must be truthful, accurate, objective, timely, clear, and complete.
-
Due Professional Care: The Application of Diligence and Judgement Auditors should exercise due care in accordance with the importance of the task they perform and the confidence placed in them by the audit client and other interested parties. An important factor in carrying out their work with due professional care is having the ability to make reasoned judgments in all audit situations.
-
Confidentiality: Security of Information Auditors should exercise discretion in the use and protection of information acquired in the course of their duties. Audit information should not be used inappropriately for personal gain by the auditor or the audit client, or in a manner detrimental to the legitimate interests of the auditee. This concept includes the proper handling of sensitive or confidential information, which is especially critical in an ISMS audit where auditors are exposed to highly sensitive organizational data, risk assessments, and vulnerability reports.
-
Independence: The Basis for the Impartiality of the Audit Auditors should be independent of the activity being audited wherever practicable, and should in all cases act in a manner that is free from bias and conflict of interest. For internal audits, auditors should be independent of the operating managers of the function being audited. For external audits, auditors should maintain an objective state of mind throughout the audit process to ensure that findings and conclusions are based only on audit evidence.
-
Evidence-based Approach: The Rational Method for Reaching Reliable Audit Conclusions Audit evidence should be verifiable. It is in general based on samples of the information available, since an audit is conducted during a finite period of time and with finite resources. An appropriate use of sampling is closely related to the confidence that can be placed in the audit conclusions. The auditor must collect objective evidence through observation, interview, and review of records.
-
Risk-based Approach: An Audit Approach that Considers Risks and Opportunities The risk-based approach to auditing should substantively influence the planning, conducting, and reporting of audits in order to ensure that audits are focused on matters that are significant for the audit client, and for achieving the audit program objectives. This means allocating more time and resources to auditing areas of high risk (e.g., critical business processes, complex network architectures, or areas with previous nonconformities) and less time to low-risk areas.
Types of Audits
Audits are generally categorized into three types based on the relationship between the auditor and the auditee. These are known as first-party, second-party, and third-party audits.
First-Party Audits (Internal Audits)
First-party audits are conducted by, or on behalf of, the organization itself for management review and other internal purposes. They form the basis for an organization's self-declaration of conformity. In many cases, particularly in smaller organizations, independence can be demonstrated by the freedom from responsibility for the activity being audited. Internal audits are crucial for maintaining the ISMS and identifying opportunities for improvement before external audits occur.
Second-Party Audits (External Provider Audits)
Second-party audits are conducted by parties having an interest in the organization, such as customers, or by other persons on their behalf. These are external audits, typically performed to ensure that a supplier or contractor meets specific requirements defined in a contract. In the context of an ISMS, an organization might conduct a second-party audit on a cloud service provider or an outsourced IT support firm to verify that they maintain adequate information security controls that align with the organization's own ISMS requirements.
Third-Party Audits (Certification Audits)
Third-party audits are conducted by independent auditing organizations, such as regulators or those providing certification/registration of conformity to requirements (like ISO/IEC 27001). These auditing organizations must be completely independent from the auditee to ensure absolute objectivity. The outcome of a successful third-party ISMS audit is a formal certification stating that the organization's ISMS complies with the ISO/IEC 27001 standard. Third-party audits are further divided into Stage 1 (readiness review), Stage 2 (certification audit), Surveillance audits (annual health checks), and Recertification audits (typically every three years).
Integrating Concepts for Effective ISMS Auditing
The successful application of ISO 19011 principles to the different types of audits determines the overall effectiveness of the audit program. A Lead Auditor must balance these principles. For example, maintaining confidentiality while ensuring fair presentation of findings can be challenging when reporting on severe vulnerabilities. Similarly, applying a risk-based approach requires the auditor to have a deep understanding of the organization's context and risk assessment methodology to prioritize audit activities effectively. By adhering strictly to the evidence-based approach, the auditor ensures that all conclusions, regardless of the audit type, remain robust, defensible, and constructive for the organization's information security posture.
Which ISO 19011 principle ensures that an auditor allocates more time and resources to auditing critical business processes rather than low-risk areas?
An organization sends its own audit team to evaluate a cloud service provider's information security controls before signing a major contract. What type of audit is this?
According to the principle of fair presentation, what must an auditor do when they encounter unresolved diverging opinions with the auditee?