Your situation

Internal audits: independent review of your ISMS

Your company has to carry out internal audits – but you lack the time, the experience or a neutral outside view? We support you with specific observations, realistic recommendations and a solid basis for certification.

Free of charge and without obligation.

  • ISO 27001 Lead Auditors on the team
  • BSI-certified for IS consulting and IS audit
Hands writing notes next to a compass and navigation instruments on a map
Internal audits: your ISMS independently reviewed, results properly documented.

Your situation

You need to carry out internal audits but lack the time, the experience or the necessary independence?

ISO/IEC 27001, BSI IT-Grundschutz, VDA ISA / TISAX®, BAIT, MaRisk, DORA or KRITIS (critical infrastructure) evidence under Section 8a BSIG require regular internal audits. Even without a formal obligation, BaFin, the KBA, internal audit departments or clients require them as part of their compliance rules.

Internal audits must be carried out by people who are both independent and competent. In-house, this is often difficult to achieve – anyone who helped shape the ISMS can hardly audit it independently. Other organisations want to replace their previous auditor or prepare for the external audit with audit training.

This is where we come in: our certified auditors audit in line with the standard and focus on your real processes rather than an ideal model. Our aim is not to find faults but to create transparency. If no audit is mandatory and you would like a well-founded position check, the Cyber Security Check (BSI/ISACA guideline) is an alternative.

Audit scope

The standards we use for internal audits

Depending on the context, we audit against established standards, regulatory requirements or your own "best practice".

Additionally on request

  • Secure software development, e.g. based on OWASP SAMM
  • Compliance with internal technical requirements and policies, e.g. based on CIS Benchmarks
  • Audit against your company-specific best practice

Services & results

How your internal audit works – from planning to the agreed report

You get transparency about your ISMS (information security management system) and a solid basis for certification: internal audits to ISO/IEC 27001, BSI IT-Grundschutz, VDA ISA / TISAX®, BAIT, MaRisk, DORA or for KRITIS evidence, carried out by certified auditors. The audit plan is risk-based, and your documents are reviewed in advance so that the audit goes straight to the key topics.

Our approach is based on ISO/IEC 27006, ISO/IEC 27007 and the BSI guideline for IS audits. Instead of a rigid questionnaire, we use a structured question framework that adapts specifically to your ISMS during the audit and that we regularly align with the state of the art.

Audit planning

We draw up an individual, risk-based audit plan that fits your audit programme. Coordination starts early – at least four weeks before the start.

Your audit plan

A risk-based audit plan aligned with your audit programme.

Document review before the audit date

We review relevant documents for completeness, plausibility and practicability before the audit date. This way, we go straight to the key topics in the audit instead of reading policies together. This saves time and allows a deeper look at your actual ISMS.

Conducting the audit

Experienced, independent and certified auditors conduct interviews, visual inspections and sampling – clearly, critically and solution-oriented. You receive daily summaries.

At the end, there is a closing meeting with all relevant participants, with a wider group on request, such as senior management.

Report with two-stage quality assurance

The audit report contains clear findings, traceable samples and identified potential for improvement. A competent person not involved in the audit reviews it for content, after which it is copy-edited. This ensures that findings are documented correctly, consistently and comprehensibly.

Your audit report

Findings you can use internally – for improvements, management decisions and the external audit.

Agreeing the results

You receive the report for review. If needed, we clarify open points in an additional closing meeting and adjust the report where necessary.

Our expertise

At secuvera, internal audits are carried out by trained and certified auditors, for example with the ISO 27001 Lead Auditor qualification. Our company also employs IS auditors and auditors for ISO 27001 on the basis of IT-Grundschutz; since December 2011, secuvera has been a BSI-certified IT security service provider for IS audit (IS-Revision).

Our audit methodology is based on ISO/IEC 27006, ISO/IEC 27007 and the BSI guideline for IS audits. We develop the question framework iteratively and regularly adapt it to the state of the art.

Every report goes through two-stage quality assurance: a technical review by a person not involved in the audit, followed by copy-editing.

Getting started

Agree the audit programme and the processes to be audited

Audit programme and scope

We discuss the standard, audit programme, organisational scope and date. Existing audit reports and ISMS documents help to set the focus.

Selecting the right topics

On request, we also audit secure software development or compliance with internal technical requirements and policies. Depending on the context, we use OWASP SAMM, CIS Benchmarks or your company-specific requirements.

Plan an internal audit
Dividers fixing a position on the world map
An audit programme that really covers your processes.

Defining audit criteria and independence

Audit criteria, roles and scope are agreed in advance. An internal audit does not replace certification or recognition by an authority.

Questions about conducting internal audits

Can an external service provider carry out our internal audit?

Yes. secuvera carries out internal audits with trained and certified auditors, for example with the ISO 27001 Lead Auditor qualification. The audit assignment and independence are clarified in advance. The audit remains part of your internal audit programme.

When should we provide the documents for the internal audit?

Under the approach described, coordination starts at least four weeks before the start. Relevant documents are reviewed before the audit date. Which documents are needed depends on the audit criteria and the area under review.

Is only the documentation audited, or also the implementation?

Interviews, visual inspections and sampling examine the actual processes. The preparatory document review provides targeted questions for this. Feedback during the audit and a closing meeting put the findings into context with the participants.

We want to replace our current internal auditor. Does that make sense?

This is one of the typical reasons why organisations come to us. A new perspective often reveals topics that no longer stand out in the usual routine. The requirements of your audit programme remain in place.

Can you prepare us for an external certification audit?

Yes. We offer audit training or an independent pre-audit for this. This way, your responsible staff know the procedure and the open points before the certification body audits.

How can we support you with internal audits?