8

Audit Principles, Concepts, and Planning

The International Organization for Standardization (ISO) defines an audit as follows:

A systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. (ISO 19011:2018 – Guidelines for Auditing Management Systems)

In July 2018, in response to the demand for guidelines on integrated management system audits, the International Organization for Standardization published ISO 19011:2018, titled Guidelines for Auditing Management Systems.

It is a meta-standard that details the audit principles, planning, and execution processes for several types of management system audits including information ...

Get Mastering Information Security Compliance Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.