Runbook 02 — ISO/IEC 27001 Internal Audit, Nonconformity & Corrective Action Management
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook | 02 — ISO/IEC 27001 Internal Audit, Nonconformity & Corrective Action Management |
| Module | ISO/IEC 27001 |
| Difficulty | Advanced |
| Estimated Time | Multi-Day / Recurring Enterprise Workflow |
| Primary Role | GRC Analyst / ISMS Auditor |
| Supporting Roles | ISMS Manager, CISO, Control Owners, Risk Owners, Internal Audit, Business Owners |
| Primary Output | Internal Audit & Corrective Action Package |
| Runbook Type | ISO Assurance & Continual Improvement |
Purpose
Section titled “Purpose”This runbook provides a repeatable process for operating the internal audit, nonconformity, corrective action, retesting, and closure lifecycle of an ISO/IEC 27001 Information Security Management System.
The workflow covers:
Audit Program ↓Audit Planning ↓Scope & Criteria ↓Evidence Collection ↓Interviews ↓Walkthroughs ↓Sampling ↓Control Testing ↓Findings ↓Nonconformity ↓Correction ↓Root Cause ↓Corrective Action ↓Implementation ↓Retesting ↓Closure ↓Management Review ↓Continual ImprovementThe objective is not simply to identify failures.
The objective is to create a repeatable assurance process that helps management answer:
Is the ISMS operating as designed, are failures being identified early, and are root causes being corrected so the same problems do not continue to recur?
Runbook Outcomes
Section titled “Runbook Outcomes”A completed internal audit cycle should produce:
-
Approved audit program.
-
Defined audit scope and criteria.
-
Audit plan.
-
Evidence request list.
-
Interview schedule.
-
Audit working papers.
-
Control-testing records.
-
Audit findings.
-
Nonconformity records.
-
Root-cause analyses.
-
Corrective-action plans.
-
Remediation tracking.
-
Retest results.
-
Closure approvals.
-
Management-review inputs.
-
Continual-improvement actions.
Operational Workflow
Section titled “Operational Workflow”Annual Assurance Plan ↓Audit Selected ↓Planning ↓Fieldwork ↓Evidence ↓Testing ↓Findings ↓Corrective Actions ↓Retesting ↓Closure ↓Reporting ↓Management ReviewPhase 1 — Establish the Internal Audit Program
Section titled “Phase 1 — Establish the Internal Audit Program”Step 1 — Define the Audit Universe
Section titled “Step 1 — Define the Audit Universe”Identify all ISMS areas that may require assurance.
Examples include:
Clause 4 — Context
Clause 5 — Leadership
Clause 6 — Planning
Clause 7 — Support
Clause 8 — Operation
Clause 9 — Performance Evaluation
Clause 10 — Improvement
Annex A Controls
Risk Management
Supplier Security
IAM
Incident Response
Business Continuity
Secure Development
Logging & MonitoringThe audit universe should reflect the actual ISMS.
Step 2 — Review Risk Information
Section titled “Step 2 — Review Risk Information”Consider:
-
High residual risks.
-
Critical controls.
-
Previous findings.
-
Recent incidents.
-
Major changes.
-
Supplier risks.
-
Control failures.
Example:
High Residual Risk:Privileged account compromise
Audit Priority:IAM and privileged access controlsStep 3 — Review Previous Audit Results
Section titled “Step 3 — Review Previous Audit Results”Identify:
Repeat Findings
Overdue Findings
Areas Never Audited
Weak Corrective ActionsThese should influence the audit program.
Step 4 — Consider Significant Changes
Section titled “Step 4 — Consider Significant Changes”Examples:
New Cloud Provider
Acquisition
New Product
Major IAM Migration
New Regulation
Security IncidentA significant change may justify additional audit coverage.
Step 5 — Build Annual Audit Program
Section titled “Step 5 — Build Annual Audit Program”Example:
| Quarter | Audit |
|---|---|
| Q1 | ISMS Governance & Risk |
| Q2 | IAM & Access Control |
| Q3 | Supplier & Cloud Security |
| Q4 | Incident Response & Business Continuity |
The organization may use a different model based on scale and risk.
Step 6 — Obtain Audit Program Approval
Section titled “Step 6 — Obtain Audit Program Approval”Record:
Audit Program Owner
Approver
Period
Version
Approval DatePhase 2 — Establish Auditor Objectivity & Competence
Section titled “Phase 2 — Establish Auditor Objectivity & Competence”Step 7 — Assign Auditor
Section titled “Step 7 — Assign Auditor”Identify:
Lead Auditor
Supporting Auditors
Technical SpecialistsStep 8 — Check Independence
Section titled “Step 8 — Check Independence”Ask:
Does the auditor own the process?
Did the auditor design the control?
Does the auditor operate the control?
Could objectivity be impaired?Avoid inappropriate self-audit.
Step 9 — Confirm Competence
Section titled “Step 9 — Confirm Competence”Auditors should have appropriate knowledge of:
-
ISO/IEC 27001.
-
Audit methods.
-
Risk management.
-
Evidence assessment.
-
Relevant technology.
Step 10 — Use Specialists Where Required
Section titled “Step 10 — Use Specialists Where Required”Example:
Audit:Cloud Security
Auditor:GRC
Technical Specialist:Cloud Security ArchitectThe specialist supports technical understanding while audit judgment remains appropriately independent.
Phase 3 — Define Audit Objective, Scope & Criteria
Section titled “Phase 3 — Define Audit Objective, Scope & Criteria”Step 11 — Define Audit Objective
Section titled “Step 11 — Define Audit Objective”Example:
Determine whether privileged access management processes are appropriately designed, implemented, and operating in accordance with the ISMS, the Access Control Policy, and applicable ISO/IEC 27001 controls.
Step 12 — Define Audit Scope
Section titled “Step 12 — Define Audit Scope”Document:
Business Units
Systems
Processes
Controls
Locations
Audit PeriodExample:
Scope:Production AWS privileged access
Period:01 January – 30 June 2026Step 13 — Define Audit Criteria
Section titled “Step 13 — Define Audit Criteria”Possible criteria:
ISO/IEC 27001 Requirements
Statement of Applicability
Policies
Standards
Procedures
Contracts
Legal RequirementsStep 14 — Confirm Out-of-Scope Areas
Section titled “Step 14 — Confirm Out-of-Scope Areas”Document exclusions to avoid confusion during fieldwork.
Phase 4 — Prepare the Audit Plan
Section titled “Phase 4 — Prepare the Audit Plan”Step 15 — Create Audit Plan
Section titled “Step 15 — Create Audit Plan”Include:
Audit Objective
Scope
Criteria
Audit Team
Stakeholders
Timeline
Interviews
Processes
Controls
Evidence
SamplingStep 16 — Identify Process Owners
Section titled “Step 16 — Identify Process Owners”Example:
| Area | Owner |
|---|---|
| IAM | IAM Director |
| Vulnerability Management | Security Engineering |
| Supplier Security | GRC |
| Backup | IT Operations |
Step 17 — Build Audit Schedule
Section titled “Step 17 — Build Audit Schedule”Example:
Day 1Opening + Governance
Day 2Walkthroughs
Day 3Testing
Day 4Follow-Up Evidence
Day 5Findings ValidationStep 18 — Send Audit Notification
Section titled “Step 18 — Send Audit Notification”Include:
-
Audit objective.
-
Scope.
-
Schedule.
-
Required participants.
-
Evidence expectations.
Avoid surprises.
Phase 5 — Build Evidence Request List
Section titled “Phase 5 — Build Evidence Request List”Step 19 — Identify Required Evidence
Section titled “Step 19 — Identify Required Evidence”Examples:
Policies
Procedures
Risk Register
RTP
SoA
Access Reviews
System Reports
Tickets
Vendor Assessments
Training Reports
Incident RecordsStep 20 — Create Evidence Request Tracker
Section titled “Step 20 — Create Evidence Request Tracker”Use:
| Request ID | Evidence | Owner | Due | Status |
|---|
Step 21 — Validate Evidence Period
Section titled “Step 21 — Validate Evidence Period”Ensure the requested evidence covers the audit period.
Example:
Audit Period:Jan–Jun
Evidence:Only current July configurationThis may not prove historical operation.
Step 22 — Minimize Sensitive Data
Section titled “Step 22 — Minimize Sensitive Data”Request only what is needed.
Do not unnecessarily collect:
-
Passwords.
-
Private keys.
-
Full customer datasets.
-
Unredacted sensitive information.
Phase 6 — Conduct Opening Meeting
Section titled “Phase 6 — Conduct Opening Meeting”Step 23 — Confirm Audit Scope
Section titled “Step 23 — Confirm Audit Scope”Restate:
What is being audited?
What is not being audited?Step 24 — Confirm Timeline
Section titled “Step 24 — Confirm Timeline”Review:
-
Interviews.
-
Evidence deadlines.
-
Findings validation.
-
Closing meeting.
Step 25 — Confirm Communication Channel
Section titled “Step 25 — Confirm Communication Channel”Define who coordinates questions.
Example:
Central Coordinator:GRC AnalystStep 26 — Confirm Escalation Process
Section titled “Step 26 — Confirm Escalation Process”Material issues discovered during fieldwork may need rapid escalation.
Phase 7 — Perform Process Walkthroughs
Section titled “Phase 7 — Perform Process Walkthroughs”Step 27 — Select Process
Section titled “Step 27 — Select Process”Example:
Privileged Access ManagementStep 28 — Ask Process Owner to Demonstrate Workflow
Section titled “Step 28 — Ask Process Owner to Demonstrate Workflow”Follow:
Request ↓Approval ↓Provisioning ↓Use ↓Monitoring ↓Review ↓RemovalStep 29 — Validate Actual Practice
Section titled “Step 29 — Validate Actual Practice”Compare:
Documented ProcedurevsActual OperationDifferences may indicate control weakness.
Step 30 — Record Walkthrough Notes
Section titled “Step 30 — Record Walkthrough Notes”Include:
-
Owner.
-
Process.
-
Systems.
-
Inputs.
-
Outputs.
-
Evidence.
-
Exceptions.
Phase 8 — Evaluate Control Design
Section titled “Phase 8 — Evaluate Control Design”Step 31 — Identify Control Objective
Section titled “Step 31 — Identify Control Objective”Example:
Objective:Prevent inappropriate privileged access.Step 32 — Review Control Statement
Section titled “Step 32 — Review Control Statement”Example:
Privileged production access is reviewed quarterly and access without a valid business requirement is removed.
Step 33 — Evaluate Design
Section titled “Step 33 — Evaluate Design”Ask:
Does the control address the risk?
Is the scope sufficient?
Is the frequency appropriate?
Is responsibility defined?
Does it produce evidence?
Can exceptions be identified?Step 34 — Record Design Conclusion
Section titled “Step 34 — Record Design Conclusion”Use:
Effective Design
Partially Effective Design
Ineffective DesignDocument rationale.
Phase 9 — Identify Population
Section titled “Phase 9 — Identify Population”Step 35 — Determine Full Population
Section titled “Step 35 — Determine Full Population”Example:
Control:New User Access Approval
Population:725 requestsStep 36 — Validate Completeness
Section titled “Step 36 — Validate Completeness”Ask:
-
Where did the population come from?
-
Is every system included?
-
Are cancelled transactions included?
-
Are privileged accounts included?
An incomplete population undermines sampling.
Step 37 — Document Population Source
Section titled “Step 37 — Document Population Source”Example:
Source:Identity platform export
Generated:05 July 2026Phase 10 — Select Audit Samples
Section titled “Phase 10 — Select Audit Samples”Step 38 — Determine Sampling Method
Section titled “Step 38 — Determine Sampling Method”Possible methods:
Random
Systematic
Judgmental
Risk BasedStep 39 — Consider Control Frequency
Section titled “Step 39 — Consider Control Frequency”Example:
Quarterly ControlPopulation = 4
Approach:Test all 4Step 40 — Consider Risk
Section titled “Step 40 — Consider Risk”High-risk controls may justify deeper testing.
Step 41 — Document Sample Selection
Section titled “Step 41 — Document Sample Selection”Record:
Population
Sample Size
Sampling Method
Sample IDs
RationalePhase 11 — Test Operating Effectiveness
Section titled “Phase 11 — Test Operating Effectiveness”Step 42 — Define Test Procedure
Section titled “Step 42 — Define Test Procedure”Example:
For each selected access review:
Verify review population.
Verify reviewer.
Verify completion date.
Inspect access decisions.
Verify removals.Step 43 — Inspect Evidence
Section titled “Step 43 — Inspect Evidence”Record each sample result.
Example:
| Sample | Approval | Timely | Removal | Result |
|---|---|---|---|---|
| Q1 | Yes | Yes | Yes | Pass |
| Q2 | Missing | No | N/A | Fail |
| Q3 | Yes | Yes | Yes | Pass |
Step 44 — Document Exceptions
Section titled “Step 44 — Document Exceptions”Do not immediately label every exception a nonconformity.
First determine:
-
Cause.
-
Frequency.
-
Scope.
-
Risk.
-
Requirement.
Step 45 — Conclude Operating Effectiveness
Section titled “Step 45 — Conclude Operating Effectiveness”Example:
Design:Effective
Operating:Partially EffectivePhase 12 — Test Automated Controls
Section titled “Phase 12 — Test Automated Controls”Step 46 — Inspect Configuration
Section titled “Step 46 — Inspect Configuration”Example:
Control:Cloud policy blocks public storage.Review:
-
Rule configuration.
-
Scope.
-
Enforcement status.
Step 47 — Review Access to Modify Control
Section titled “Step 47 — Review Access to Modify Control”Ask:
Who can change the rule?If unrestricted, control reliability may be weak.
Step 48 — Review Change History
Section titled “Step 48 — Review Change History”Check whether configuration changed during the audit period.
Step 49 — Review Exceptions
Section titled “Step 49 — Review Exceptions”Identify:
Bypasses
Disabled Rules
Excluded Accounts
Emergency ChangesPhase 13 — Test Manual Controls
Section titled “Phase 13 — Test Manual Controls”Step 50 — Review Control Performer
Section titled “Step 50 — Review Control Performer”Confirm the correct person performed the activity.
Step 51 — Review Frequency
Section titled “Step 51 — Review Frequency”Example:
Required:Monthly
Actual:3 times in 6 monthsThis indicates inconsistency.
Step 52 — Review Evidence Quality
Section titled “Step 52 — Review Evidence Quality”Manual evidence should demonstrate actual performance, not just a blank template.
Phase 14 — Test Hybrid Controls
Section titled “Phase 14 — Test Hybrid Controls”Step 53 — Test Automation
Section titled “Step 53 — Test Automation”Example:
Vulnerability scanner runs weekly.Verify configuration and coverage.
Step 54 — Test Manual Review
Section titled “Step 54 — Test Manual Review”Confirm security personnel actually review results.
Step 55 — Test Remediation Workflow
Section titled “Step 55 — Test Remediation Workflow”Trace:
Finding ↓Ticket ↓Owner ↓Remediation ↓RescanPhase 15 — Audit ISMS Clauses
Section titled “Phase 15 — Audit ISMS Clauses”Step 56 — Clause 4
Section titled “Step 56 — Clause 4”Review:
Context
Interested Parties
Requirements
ScopeCheck for significant changes.
Step 57 — Clause 5
Section titled “Step 57 — Clause 5”Review:
Leadership
Policy
Roles
AuthoritiesInterview leadership where appropriate.
Step 58 — Clause 6
Section titled “Step 58 — Clause 6”Review:
Risk Methodology
Risk Register
RTP
ObjectivesStep 59 — Clause 7
Section titled “Step 59 — Clause 7”Review:
Resources
Competence
Awareness
Communication
Document ControlStep 60 — Clause 8
Section titled “Step 60 — Clause 8”Review whether planned processes actually operate.
Step 61 — Clause 9
Section titled “Step 61 — Clause 9”Review:
Metrics
Internal Audit
Management ReviewStep 62 — Clause 10
Section titled “Step 62 — Clause 10”Review:
Nonconformities
Corrective Actions
Continual ImprovementPhase 16 — Audit Annex A / SoA Controls
Section titled “Phase 16 — Audit Annex A / SoA Controls”Step 63 — Select SoA Controls
Section titled “Step 63 — Select SoA Controls”Use risk-based sampling.
Step 64 — Verify Applicability
Section titled “Step 64 — Verify Applicability”Ask:
Why is this control applicable?Step 65 — Verify Implementation Status
Section titled “Step 65 — Verify Implementation Status”If SoA says:
Implementedevidence should support that conclusion.
Step 66 — Verify Ownership
Section titled “Step 66 — Verify Ownership”Interview control owner.
Step 67 — Verify Evidence
Section titled “Step 67 — Verify Evidence”Follow the control through actual operation.
Phase 17 — Identify Audit Findings
Section titled “Phase 17 — Identify Audit Findings”Step 68 — Determine Requirement
Section titled “Step 68 — Determine Requirement”Every nonconformity needs a requirement.
Example:
Requirement:Access reviews occur quarterly.Step 69 — Determine Condition
Section titled “Step 69 — Determine Condition”Observed:
Q2 review was not performed.Step 70 — Identify Evidence
Section titled “Step 70 — Identify Evidence”Example:
No Q2 review record.
IAM owner confirmed review was missed.Step 71 — Describe Risk
Section titled “Step 71 — Describe Risk”Example:
Inappropriate privileged access may remain undetected for an extended period.
Step 72 — Draft Finding
Section titled “Step 72 — Draft Finding”Recommended structure:
The Access Control Standard requires quarterly privileged access reviews. The audit found that the Q2 2026 review was not performed for 18 production systems. As a result, inappropriate privileged access may not have been identified and removed in a timely manner.
Phase 18 — Classify Findings
Section titled “Phase 18 — Classify Findings”Step 73 — Determine Nonconformity
Section titled “Step 73 — Determine Nonconformity”A nonconformity exists when a requirement is not fulfilled.
Step 74 — Determine Severity Using Approved Methodology
Section titled “Step 74 — Determine Severity Using Approved Methodology”Possible categories may include:
Major
Minor
Observation
Opportunity for ImprovementClassification should follow the audit program and relevant certification approach.
Step 75 — Consider Systemic Nature
Section titled “Step 75 — Consider Systemic Nature”Ask:
Is this isolated?
Repeated?
Systemic?
Does it affect a core ISMS process?
Does it create significant risk?Phase 19 — Validate Findings
Section titled “Phase 19 — Validate Findings”Step 76 — Review With Process Owner
Section titled “Step 76 — Review With Process Owner”Confirm facts.
Step 77 — Review Evidence
Section titled “Step 77 — Review Evidence”Resolve factual errors.
Step 78 — Avoid Negotiating Facts Away
Section titled “Step 78 — Avoid Negotiating Facts Away”If the requirement was not met, changing wording should not hide the issue.
Step 79 — Finalize Finding
Section titled “Step 79 — Finalize Finding”Record:
Finding ID
Requirement
Condition
Evidence
Risk
ClassificationPhase 20 — Conduct Closing Meeting
Section titled “Phase 20 — Conduct Closing Meeting”Step 80 — Present Overall Conclusion
Section titled “Step 80 — Present Overall Conclusion”Example:
ISMS generally effective,with improvement required inprivileged access and supplier reassessment.Step 81 — Present Significant Findings
Section titled “Step 81 — Present Significant Findings”Focus on:
-
Major risks.
-
Systemic issues.
-
Recurring failures.
Step 82 — Explain Next Steps
Section titled “Step 82 — Explain Next Steps”Discuss:
Management Response
Root Cause
Corrective Action
Target Date
RetestingPhase 21 — Issue Audit Report
Section titled “Phase 21 — Issue Audit Report”Step 83 — Prepare Executive Summary
Section titled “Step 83 — Prepare Executive Summary”Include:
-
Scope.
-
Overall conclusion.
-
Significant findings.
-
Certification-readiness impact.
Step 84 — Include Detailed Findings
Section titled “Step 84 — Include Detailed Findings”For each:
Criteria
Condition
Evidence
Risk
Classification
OwnerStep 85 — Issue Final Report
Section titled “Step 85 — Issue Final Report”Distribute according to governance.
Potential recipients:
CISO
ISMS Manager
Risk Owners
Control Owners
ManagementPhase 22 — Record Nonconformity
Section titled “Phase 22 — Record Nonconformity”Step 86 — Create Corrective Action Record
Section titled “Step 86 — Create Corrective Action Record”Use:
Finding ID
Requirement
Nonconformity
Owner
Correction
Root Cause
Corrective Action
Target
Evidence
RetestStep 87 — Assign Owner
Section titled “Step 87 — Assign Owner”Choose someone with authority to resolve the underlying issue.
Phase 23 — Perform Immediate Correction
Section titled “Phase 23 — Perform Immediate Correction”Step 88 — Correct Immediate Failure
Section titled “Step 88 — Correct Immediate Failure”Example:
Finding:
Five terminated users retain accounts.Correction:
Disable five accounts.This addresses immediate exposure.
Step 89 — Preserve Evidence
Section titled “Step 89 — Preserve Evidence”Record correction completion.
Phase 24 — Perform Root Cause Analysis
Section titled “Phase 24 — Perform Root Cause Analysis”Step 90 — Ask Why the Failure Occurred
Section titled “Step 90 — Ask Why the Failure Occurred”Do not stop at:
Employee forgot.Step 91 — Consider Common Causes
Section titled “Step 91 — Consider Common Causes”Unclear Ownership
Manual Process
Missing Automation
Poor Training
Technology Failure
Resource Constraint
Weak Governance
Process Design FailureStep 92 — Use Five Whys
Section titled “Step 92 — Use Five Whys”Example:
Problem:Vendor reassessment overdue.
Why?No reminder.
Why?Spreadsheet manually maintained.
Why?No workflow automation.
Why?TPRM process was designed without lifecycle tooling.
Root Cause:Inadequate reassessment tracking design.Step 93 — Document Root Cause
Section titled “Step 93 — Document Root Cause”Root cause should be specific and actionable.
Phase 25 — Develop Corrective Action
Section titled “Phase 25 — Develop Corrective Action”Step 94 — Define Action Addressing Root Cause
Section titled “Step 94 — Define Action Addressing Root Cause”Weak:
Remind team to complete reviews.Better:
Implement automated vendor reassessment scheduling, reminder, escalation, and overdue reporting.
Step 95 — Assign Corrective Action Owner
Section titled “Step 95 — Assign Corrective Action Owner”Example:
Owner:TPRM ManagerStep 96 — Set Target Date
Section titled “Step 96 — Set Target Date”Consider finding severity and risk.
Step 97 — Define Closure Evidence
Section titled “Step 97 — Define Closure Evidence”Example:
Workflow Configuration
Test Results
Completed Reassessments
Overdue DashboardPhase 26 — Review Corrective Action Quality
Section titled “Phase 26 — Review Corrective Action Quality”Step 98 — Confirm Action Addresses Root Cause
Section titled “Step 98 — Confirm Action Addresses Root Cause”Ask:
Will this prevent recurrence?Step 99 — Confirm Scope
Section titled “Step 99 — Confirm Scope”If issue affected 18 systems, do not remediate only one.
Step 100 — Confirm Sustainability
Section titled “Step 100 — Confirm Sustainability”Avoid solutions requiring constant manual heroics.
Phase 27 — Track Corrective Actions
Section titled “Phase 27 — Track Corrective Actions”Step 101 — Maintain Corrective Action Register
Section titled “Step 101 — Maintain Corrective Action Register”Use:
| ID | Action | Owner | Target | Status |
|---|
Step 102 — Use Standard Status
Section titled “Step 102 — Use Standard Status”Open
Planned
In Progress
Blocked
Ready for Retest
ClosedStep 103 — Monitor High-Risk Findings
Section titled “Step 103 — Monitor High-Risk Findings”Review more frequently.
Step 104 — Escalate Overdue Actions
Section titled “Step 104 — Escalate Overdue Actions”Example:
Minor→ Owner
High-Risk Finding→ CISO
Major / Certification Blocking→ Executive ManagementPhase 28 — Handle Blocked Remediation
Section titled “Phase 28 — Handle Blocked Remediation”Step 105 — Identify Blocker
Section titled “Step 105 — Identify Blocker”Examples:
Budget
Vendor Dependency
Legacy System
Staffing
Technology LimitationStep 106 — Evaluate Temporary Risk
Section titled “Step 106 — Evaluate Temporary Risk”Determine whether residual risk has increased.
Step 107 — Apply Compensating Controls
Section titled “Step 107 — Apply Compensating Controls”Where appropriate.
Step 108 — Escalate Risk Acceptance
Section titled “Step 108 — Escalate Risk Acceptance”If delay creates unacceptable exposure.
Phase 29 — Prepare for Retest
Section titled “Phase 29 — Prepare for Retest”Step 109 — Confirm Management Says Action Is Complete
Section titled “Step 109 — Confirm Management Says Action Is Complete”Do not close yet.
Step 110 — Collect Closure Evidence
Section titled “Step 110 — Collect Closure Evidence”Example:
New Process
Configuration
Training
Reports
Completed SamplesStep 111 — Define Retest Scope
Section titled “Step 111 — Define Retest Scope”Retesting should address the original issue and root cause.
Phase 30 — Perform Retesting
Section titled “Phase 30 — Perform Retesting”Step 112 — Validate Correction
Section titled “Step 112 — Validate Correction”Confirm immediate issue remains resolved.
Step 113 — Validate Corrective Action
Section titled “Step 113 — Validate Corrective Action”Example:
Original:Quarterly reviews missed
New Process:Automated workflowTest latest review cycle.
Step 114 — Test Operating Evidence
Section titled “Step 114 — Test Operating Evidence”Verify:
Complete Population
Timely Review
Appropriate Approval
Remediation
EscalationStep 115 — Determine Effectiveness
Section titled “Step 115 — Determine Effectiveness”Use:
Effective
Partially Effective
IneffectivePhase 31 — Close or Reopen Finding
Section titled “Phase 31 — Close or Reopen Finding”Step 116 — Close Finding
Section titled “Step 116 — Close Finding”Only when:
-
Correction complete.
-
Corrective action implemented.
-
Evidence sufficient.
-
Root cause addressed.
-
Retest successful.
Step 117 — Record Closure
Section titled “Step 117 — Record Closure”Include:
Closure Date
Retest Result
Reviewer
EvidenceStep 118 — Reopen if Failed
Section titled “Step 118 — Reopen if Failed”If retest fails:
Finding Remains Open ↓Further Root Cause Review ↓New Corrective ActionPhase 32 — Identify Recurring Findings
Section titled “Phase 32 — Identify Recurring Findings”Step 119 — Review Finding History
Section titled “Step 119 — Review Finding History”Look for repeated themes:
Access Reviews
Vendor Assessments
Document Control
Training
Backup TestingStep 120 — Escalate Recurring Failure
Section titled “Step 120 — Escalate Recurring Failure”Repeat findings may indicate:
-
Poor governance.
-
Inadequate root-cause analysis.
-
Weak accountability.
-
Insufficient resources.
Phase 33 — Update the Risk Register
Section titled “Phase 33 — Update the Risk Register”Step 121 — Determine Whether Finding Changes Risk
Section titled “Step 121 — Determine Whether Finding Changes Risk”Example:
Backup recovery control fails ↓Availability Risk IncreasesStep 122 — Update Risk Rating
Section titled “Step 122 — Update Risk Rating”If necessary.
Step 123 — Update Risk Treatment
Section titled “Step 123 — Update Risk Treatment”Add or modify treatment actions.
This connects assurance back to risk management.
Phase 34 — Update the Statement of Applicability
Section titled “Phase 34 — Update the Statement of Applicability”Step 124 — Review Affected Control
Section titled “Step 124 — Review Affected Control”If SoA says:
Implementedbut internal audit finds systemic failure, status may need review.
Step 125 — Update Control Status
Section titled “Step 125 — Update Control Status”Possible:
Implemented→Partially ImplementedStep 126 — Link Finding
Section titled “Step 126 — Link Finding”Reference corrective action where appropriate.
Phase 35 — Update Control Library
Section titled “Phase 35 — Update Control Library”Step 127 — Improve Control Statement
Section titled “Step 127 — Improve Control Statement”Audit may reveal a vague control.
Example:
Old:Access reviewed regularly.Improved:
Privileged production access is reviewed quarterly by designated application owners, and inappropriate access is removed within five business days.
Step 128 — Update Frequency or Evidence
Section titled “Step 128 — Update Frequency or Evidence”Where necessary.
Phase 36 — Feed Audit Results Into Management Review
Section titled “Phase 36 — Feed Audit Results Into Management Review”Step 129 — Prepare Audit Summary
Section titled “Step 129 — Prepare Audit Summary”Report:
Audit Completed
Overall Conclusion
Major Findings
Minor Findings
Repeat Findings
Overdue Corrective Actions
Certification ImpactStep 130 — Highlight Management Decisions Required
Section titled “Step 130 — Highlight Management Decisions Required”Examples:
Additional Resource
Control Investment
Risk Acceptance
System Replacement
Process RedesignStep 131 — Record Management Actions
Section titled “Step 131 — Record Management Actions”Track owners and dates.
Phase 37 — Monitor Audit Metrics
Section titled “Phase 37 — Monitor Audit Metrics”Step 132 — Track Finding Metrics
Section titled “Step 132 — Track Finding Metrics”Useful metrics:
Open Findings
Overdue Findings
Major Findings
Repeat Findings
Average Closure Time
Retest Failure RateStep 133 — Track Audit Completion
Section titled “Step 133 — Track Audit Completion”Example:
Planned Audits:6
Completed:5
Completion:83%Step 134 — Track Corrective Action Aging
Section titled “Step 134 — Track Corrective Action Aging”Example:
| Finding | Age |
|---|---|
| F-001 | 15 Days |
| F-002 | 85 Days |
| F-003 | 210 Days |
Older high-risk findings require attention.
Phase 38 — Establish KRIs
Section titled “Phase 38 — Establish KRIs”Potential KRIs:
High Findings Overdue
Repeat Nonconformities
Failed Retests
Controls With No Evidence
Audits Not Completed as PlannedThese show assurance-program health.
Phase 39 — Prepare for Certification Audit
Section titled “Phase 39 — Prepare for Certification Audit”Step 135 — Review Internal Audit Coverage
Section titled “Step 135 — Review Internal Audit Coverage”Confirm relevant ISMS areas have been audited.
Step 136 — Review Major Nonconformities
Section titled “Step 136 — Review Major Nonconformities”Certification-blocking issues should be addressed.
Step 137 — Review Corrective Action Evidence
Section titled “Step 137 — Review Corrective Action Evidence”Organize:
Finding ↓Root Cause ↓Action ↓Evidence ↓Retest ↓ClosureStep 138 — Prepare Auditor Walkthrough
Section titled “Step 138 — Prepare Auditor Walkthrough”Be ready to demonstrate internal assurance is functioning.
Phase 40 — Manage External Audit Findings
Section titled “Phase 40 — Manage External Audit Findings”The same core corrective-action workflow can be applied to certification findings.
Step 139 — Record External Finding
Section titled “Step 139 — Record External Finding”Maintain source:
Internal Audit
Stage 1
Stage 2
Surveillance
RecertificationStep 140 — Prioritize According to Classification
Section titled “Step 140 — Prioritize According to Classification”External certification timelines may influence deadlines.
Step 141 — Submit Corrective Action Evidence
Section titled “Step 141 — Submit Corrective Action Evidence”Follow certification-body requirements.
Step 142 — Retain Closure Record
Section titled “Step 142 — Retain Closure Record”Keep for future surveillance.
Internal Audit Operational Checklist
Section titled “Internal Audit Operational Checklist”Planning
Section titled “Planning”-
Audit universe defined.
-
Risks reviewed.
-
Previous findings reviewed.
-
Changes reviewed.
-
Annual audit program approved.
-
Auditor independence considered.
-
Auditor competence confirmed.
Audit Setup
Section titled “Audit Setup”-
Objective defined.
-
Scope defined.
-
Criteria defined.
-
Audit period defined.
-
Process owners identified.
-
Audit plan prepared.
-
Evidence request list issued.
-
Opening meeting completed.
Fieldwork
Section titled “Fieldwork”-
Walkthroughs performed.
-
Control design assessed.
-
Populations validated.
-
Samples selected.
-
Automated controls tested.
-
Manual controls tested.
-
Hybrid controls tested.
-
Clause requirements tested.
-
SoA controls tested.
-
Evidence retained.
Findings
Section titled “Findings”-
Requirement identified.
-
Condition documented.
-
Evidence documented.
-
Risk described.
-
Classification assigned.
-
Finding validated.
-
Closing meeting completed.
-
Audit report issued.
Corrective Action
Section titled “Corrective Action”-
Immediate correction completed.
-
Root cause identified.
-
Corrective action defined.
-
Owner assigned.
-
Target date assigned.
-
Closure evidence defined.
-
Progress monitored.
-
Overdue items escalated.
Retesting
Section titled “Retesting”-
Closure evidence obtained.
-
Retest performed.
-
Root cause remediation validated.
-
Effectiveness determined.
-
Finding closed or reopened.
Continuous Improvement
Section titled “Continuous Improvement”-
Risk register updated where required.
-
RTP updated where required.
-
SoA updated where required.
-
Control library updated.
-
Management review input prepared.
-
Repeat findings analyzed.
-
Metrics reported.
Quick Reference — Finding Lifecycle
Section titled “Quick Reference — Finding Lifecycle”Audit Exception ↓Requirement Not Met? │ ├── No → Observation / No Finding │ └── Yes ↓Nonconformity ↓Immediate Risk? │ ├── Yes → Correction │ └── No ↓Root Cause Analysis ↓Corrective Action ↓Implementation ↓Retest ↓Effective? │ ├── Yes → Close │ └── No → Reopen / Further ActionQuick Reference — Audit Evidence Decision Tree
Section titled “Quick Reference — Audit Evidence Decision Tree”Control Claim ↓Evidence Available? │ ├── No → Potential Exception │ └── Yes ↓Correct Period? │ ├── No → Insufficient Evidence │ └── Yes ↓Complete Population? │ ├── No → Validate Population │ └── Yes ↓Sample / Test ↓Exceptions? │ ├── No → Effective │ └── Yes → Evaluate Severity & Systemic ImpactAudit Working Paper Template
Section titled “Audit Working Paper Template”Use:
Audit Area:
Requirement:
Control ID:
Control Objective:
Control Owner:
Control Frequency:
Audit Period:
Population:
Sample:
Test Procedure:
Evidence Reviewed:
Exceptions:
Design Conclusion:
Operating Conclusion:
Finding Reference:
Auditor:
Review Date:Nonconformity Record Template
Section titled “Nonconformity Record Template”Finding ID:
Source:
Requirement:
Condition:
Evidence:
Risk / Impact:
Classification:
Process Owner:
Control Owner:
Correction:
Root Cause:
Corrective Action:
Action Owner:
Target Date:
Closure Evidence:
Retest Date:
Retest Result:
Closure Date:Corrective Action Quality Test
Section titled “Corrective Action Quality Test”Before approving corrective action, ask:
Does it fix the immediate issue?
Does it address root cause?
Does it cover the full affected population?
Is it sustainable?
Is an owner assigned?
Is there a deadline?
Can effectiveness be tested?
Will evidence be available?If several answers are “No”, the corrective action should be improved.
Common Audit Failures
Section titled “Common Audit Failures”Failure 1 — Auditing Documents Only
Section titled “Failure 1 — Auditing Documents Only”Policy Exists→ PassThis does not test implementation.
Failure 2 — No Population Validation
Section titled “Failure 2 — No Population Validation”A beautiful sample from an incomplete population provides weak assurance.
Failure 3 — Inquiry Accepted as Evidence
Section titled “Failure 3 — Inquiry Accepted as Evidence”Statements should be corroborated.
Failure 4 — Auditor Audits Own Work
Section titled “Failure 4 — Auditor Audits Own Work”Objectivity is weakened.
Failure 5 — Findings Are Vague
Section titled “Failure 5 — Findings Are Vague”Example:
Security needs improvement.Not actionable.
Failure 6 — Every Exception Called Major
Section titled “Failure 6 — Every Exception Called Major”Classification loses credibility.
Failure 7 — Findings Downgraded to Avoid Problems
Section titled “Failure 7 — Findings Downgraded to Avoid Problems”Assurance should remain objective.
Failure 8 — Root Cause Is “Human Error”
Section titled “Failure 8 — Root Cause Is “Human Error””This usually stops analysis too early.
Failure 9 — Findings Closed on Screenshot Alone
Section titled “Failure 9 — Findings Closed on Screenshot Alone”The underlying process may still fail.
Failure 10 — Audit Results Do Not Update Risk
Section titled “Failure 10 — Audit Results Do Not Update Risk”Assurance remains disconnected from governance.
Example End-to-End Case
Section titled “Example End-to-End Case”Original Control
Section titled “Original Control”Control:Critical vendors reassessed annually.Audit Test
Section titled “Audit Test”Population:
40 Critical VendorsEvidence:
35 Current
5 OverdueFinding
Section titled “Finding”Five of forty critical vendors were not reassessed within the required annual period, resulting in reduced assurance that material changes in vendor security posture are identified in a timely manner.
Correction
Section titled “Correction”Complete 5 assessments.Root Cause
Section titled “Root Cause”Manual spreadsheet trackingwithout automated reminders or escalation.Corrective Action
Section titled “Corrective Action”Implement automated reassessmentscheduling, reminders, and escalation.Retest
Section titled “Retest”Three months later:
Critical Vendors:42
Current:42
Overdue:0Result
Section titled “Result”Corrective Action:Effective
Finding:ClosedThis is what a complete assurance lifecycle looks like.
Runbook Deliverables
Section titled “Runbook Deliverables”A completed assurance package should contain:
01 — Annual Internal Audit Program
02 — Audit Plan
03 — Audit Evidence Request List
04 — Interview Schedule
05 — Audit Working Papers
06 — Control Testing Worksheets
07 — Audit Findings Register
08 — Internal Audit Report
09 — Nonconformity Register
10 — Root Cause Analysis Records
11 — Corrective Action Register
12 — Remediation Evidence
13 — Retest Records
14 — Finding Closure Register
15 — Audit Metrics Dashboard
16 — Management Review Audit SummaryRunbook Success Criteria
Section titled “Runbook Success Criteria”The internal audit and corrective-action program is operating effectively when:
Audits occur as planned
Auditors remain objective
Evidence is tested
Populations are validated
Controls are assessed for design and operation
Findings are clearly written
Root causes are identified
Corrective actions address recurrence
Remediation is tracked
Retesting occurs before closure
Repeat findings decrease
Risk and SoA records reflect audit results
Management receives meaningful assurancePractical Assurance Mindset
Section titled “Practical Assurance Mindset”A weak audit asks:
Do you have the document?
A better audit asks:
Is the process implemented?
A mature audit asks:
Is the process appropriately designed, operating consistently, producing reliable evidence, reducing the intended risk, and improving when failures occur?
That is the mindset of effective ISO/IEC 27001 assurance.
Runbook Complete
Section titled “Runbook Complete”With this runbook, you have completed the operational assurance lifecycle:
Audit ↓Evidence ↓Finding ↓Root Cause ↓Corrective Action ↓Retest ↓Management Review ↓ImprovementTogether with Runbook 01 — ISO/IEC 27001 Implementation & Certification Readiness, you now have both sides of the ISO operating model:
Implementation +Assurance =Sustainable ISMSModule Complete — ISO/IEC 27001
Section titled “Module Complete — ISO/IEC 27001”You have now completed the ISO/IEC 27001 module covering:
01 — Introduction to ISO/IEC 27001
02 — ISMS Fundamentals
03 — ISO Clauses Explained
04 — Context of the Organization
05 — Leadership & Governance
06 — Risk Assessment
07 — Risk Treatment Plan
08 — Statement of Applicability
09 — Annex A Controls Overview
10 — Certification Processand the practical activities:
Lab 01Build an ISO/IEC 27001 ISMS
Lab 02Build an ISO/IEC 27001 Statement of Applicability & Control Mapping
Runbook 01ISO/IEC 27001 Implementation & Certification Readiness
Runbook 02ISO/IEC 27001 Internal Audit, Nonconformity & Corrective Action ManagementYou now have the practical foundation required to move beyond general ISO/IEC 27001 implementation into more specialized security and compliance standards.
What’s Next?
Section titled “What’s Next?”➡️ Next Module — ISO Cloud Security Standards
The recommended next step is to extend the ISO/IEC 27001 foundation into cloud-specific assurance.
The next module can cover:
ISO/IEC 27017Cloud Security Controls ↓ISO/IEC 27018Protection of PII in Public Clouds ↓Cloud Shared Responsibility ↓Cloud Supplier Assurance ↓Cloud Control Mapping ↓Cloud Compliance Evidence ↓Cloud Audit & Certification ReadinessThis allows learners to understand how the ISO/IEC 27001 ISMS foundation is extended into AWS, Azure, SaaS, and enterprise cloud environments.