Skip to content

Audit Policy And Procedure

Contents

Objectives [3](#objectives)

Scope [3](#scope)

Requirements [3](#requirements)

Information Security Continuity [3](#information-security-continuity)

Internal Audit Procedure [4](#internal-audit-procedure)

Internal Audit Team Members [4](#internal-audit-team-members)

• Responsibilities [4](#responsibilities)

Corrective Actions [10](#corrective-actions)

External Audit [10](#external-audit)

Control mapping [10](#control-mapping)

Mapping to ISO Control (s) [10](#mapping-to-iso-control-s)

Exceptions [11](#exceptions)

Review [11](#review)

Version History

Version Number

Date

Description

Created By

Approved By

0.1

23/Jan/2024

Initial Copy

[Name] [Name]

0.2

18/Jun/2024

Approved

[Name] [Name]

[Name]

0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Objectives

The purpose of this document is to define a formal process for audit of Information Security Management System (ISMS). The objective is to conduct audits at planned intervals to provide information on whether the information security management system: Conforms to the organization’s own requirements for its information security management system; and is effectively implemented and maintained.

Scope

The document applies to tecciance to align with defined tecciance Information security requirements.

Requirements

Information Security Continuity

  • The information security and its implementation (i.e., control objectives, controls, policies, processes, procedures, and relevant metrics) shall be reviewed independently at planned intervals, or when significant changes to the security implementation occur.

  • The Internal Audit Team shall prepare an Internal Audit plan and schedule for tecciance, taking into consideration the status and importance of the processes and areas to be audited, as well as the results of the previous audits (if any). The audit criteria, scope, frequency and methods shall be defined as part of the plan.

  • Internal audit shall be conducted on an annual basis.

  • The CTO shall review and approve the Audit Plan and Schedule.

  • On approval of the Audit Plan, appraise Information Security Team of the audit schedule, the Internal Audit Team shall circulate the finalized audit plan to the respective personnel for their area of work to be audited.

  • Internal Audit Team shall be familiar with ISO 27001 standard, SOC2 requirements (as required) and any other applicable standards / regulations of tecciance, standard operating procedures, Information Security policies and procedures. The Internal Audit Team shall be trained in conducting Internal Audits. Internal Audit Team shall conduct the audit work objectively and impartially and shall not audit own area of operations.

  • Based on the audit plan, selected auditors shall prepare an audit checklist, pertaining to the area to which the audit needs to be conducted.

  • The Internal Audit Team shall prepare the Internal Audit Report template to record the audit findings.

  • Audit findings shall be recorded in the Internal Audit Report along with the details of the samples reviewed and the category of findings. The Internal Audit process (detailed further below in this document) provides guidance for identifying the category of findings:

  • The Internal Audit Team shall review and circulate the audit report to the respective auditee(s) department for their responses in-terms of corrective actions, responsibility and stipulated time for addressing the category of findings identified as part of the report.

  • The Internal Audit team shall finalize the audit report in terms of completeness, coverage of all applicable processes including the focus areas, effectiveness and the depth of the audit and submit the finalized Internal Audit Report to the CTO.

  • The IS Team shall follow up for Corrective Action and closure of audit observations / nonconformities / Opportunity for Improvement and review the implementation performed by the respective individual as per the timelines given to auditees.

  • The IS Team shall update the closure status of audit findings through the Management Review Meeting.

Internal Audit Procedure

Internal Audits shall be planned annually to validate the implementation of ISMS objectives and controls. Results of internal audits are input to management review, especially those for which a management decision is required.

Internal Audit Team Members

• Responsibilities

  • The CTO or a delegate is responsible for ensuring governance & compliance with Information security practices, policies and Procedures.

  • The CTO or a delegate nominates a lead auditor who shall be responsible to publish the

Internal Audit Plan o Audit Findings are reported periodically to the management.

  • Audit findings are followed up on the Action Plans and Closure with respective Business Heads.

• Responsibilities of Business/Control owners

  • Business/ Control Owners are responsible for maintaining and managing the controls relevant to their domain.

  • Progress on Action Plans within the Target Dates are to be periodically reported to the ISMS Audit Team for tracking it to Closure.

Auditors Criteria

• Auditor Qualifying Criteria

  • Lead Auditor to be a Certified ISO 27001 Lead Auditor.

  • The qualifying lead auditor shall not have any governance responsibilities on the scoped audit function.

  • The lead auditor shall be independent and remain impartial to the auditee and process throughout the Audit.

  • Internal Auditors to have a fair understanding of ISMS standards, applicable procedures, or other documents.

• Audit Principle

An auditor shall be able to:

  • Apply audit principles, procedures, and techniques. o Remain impartial to the auditee and process throughout the Audit.

  • Plan and organize the work effectively.

  • Conduct the audit within the agreed time schedule. o Prioritize and focus on matters of significance.

  • Collect information through effective interviewing, listening, observing, and reviewing documents, records, and data.

  • Understand the appropriateness and consequences of using sampling techniques for auditing.

  • Verify the accuracy of collected information.

  • Confirm the sufficiency and appropriateness of audit evidence to support audit findings and conclusions.

  • Use work documents to record audit activities.

  • Prepare audit reports of suitable quality and professionalism. o Maintain the confidentiality and security of information, and o Communicate effectively.

• Organization/business context

Knowledge and skills in this area shall cover aspects such as: o Organization size, structure, functions and relationships o General business processes and related terminology, and

o Applicable laws, regulations, and other obligations: to enable the auditor to work within, and be aware of, various obligations towards information security, privacy, governance, and other requirements that apply to the organization being audited. Knowledge and skills in this area shall cover relevant:

  • Local, regional, and national codes, laws, and regulations.

  • Contracts and agreements.

  • International treaties and conventions; and

  • Other compliance requirements such as applicable standards.

• Specific Knowledge and Skills of ISMS Auditors

  • Information security management system auditors shall have knowledge and skills in Information security-related methods and techniques to enable the auditor to examine information security management systems and to generate appropriate audit findings and conclusions. Knowledge and skills in this area shall cover. ▪ ISO27001:2022 Standard & ISO27002:2022 Controls ▪ Information security terminology and concepts.

  • Information security management principles and their application ▪ Information security management tools and their application.

  • Processes and products, including services: to enable the auditor to comprehend the technological context in which the audit is being conducted. Knowledge and skills in this area shall cover:

  • Industry-specific terminology.

  • Technical characteristics of processes and products, including services, and industry-specific processes and practices.

Audit Criteria

The following criteria to be considered for internal audit.

  • ISO 27001 controls as per the alignment to Organization Policies defined.

  • Business requirements.

  • Business processes affecting the existing business requirements.

  • Regulatory or legal requirements.

  • Risk Assessment Reports.

  • Contractual obligations.

  • Audit is conducted on sampling basis.

Internal Audit Team

Process

  • The Lead Internal Auditor is an independent auditor who has not implemented or has governance roles for tecciance’s ISMS program.

  • The Lead Internal Auditor prepares the audit plan covering the frequency and methods of the audit.

  • The audit plan takes into consideration the status and importance of the processes and areas to be audited, the Risk Assessment report, as well as the results of previous audits.

  • Internal Audit plan is reported to the management. After seeking approval on the Audit Plan, respective Business/ Control/Policy owners are communicated with the Audit plan.

  • A checklist shall be created to ensure continuity and depth in the audit.

  • The ISMS Audit Team performs the audit. During the audit, ISMS Audit Team tries to find adequate evidence to ascertain that:

  • The information security policy is still an accurate reflection of the business requirements.

  • An appropriate risk assessment methodology is being used.

  • The documented procedures are being followed (i.e., within the scope of the ISMS) and are meeting their desired objectives.

  • Technical controls are in place, are correctly configured and working as intended.

  • The residual risks have been assessed correctly and are still acceptable to the management of the company.

  • The agreed actions from previous audits and reviews have been implemented.

  • The ISMS is compliant with ISO 27001

a) Non-Conformity (NC)

A NC is raised whenever there is evidence of the non-conformity of the policy or any of its elements, which in the judgment of the auditor shall severely compromise the security of the organization and therefore may result in loss of Confidentiality, integrity and/or availability. A NC shall be raised in the absence of “intent, implementation and/or effectiveness” as specified in the requirements of the ISO/IEC 27001 specification.

• Major Nonconformity

The definition of a MAJOR nonconformity: Total breakdown of system, control, or procedure, Absence of a standard (ISO 27001) requirement, Several minors related to the same clause, A nonconformity that experience and judgment indicate shall likely result in ISMS failure or materially reduce its ability to assure controlled processes and products.

• Minor Nonconformity

The definition of a MINOR nonconformity: Failure to conform to a requirement which (based on judgment and experience) is not likely to result in ISMS failure, A single observed lapse or isolated incident, Minimal risk of nonconforming product or service or security.

b) Observation

An observation is a situation other than NC where a potential NC may arise in future or shall affect the compliance to the policy.

c) Opportunity for improvement (OFI)

Opportunity for improvement (OFI) is a situation where additional effectiveness on the process already implemented is expected with a modified approach.

Category of findings Description Resolution Time

Major non-

conformity (Major NC)

A systematic failure or significant deficiency - either as a single incident or a combination of several similar incidents - in part of the Information Security Management System (ISMS), or the lack of implementation of such a part, governed by applicable ISO 27001:2022 standard and/or

Information Security Policies of the organization.

14 days (Unless with exception approval from internal stakeholders)

Minor non-

conformity (Minor NC)

An isolated or sporadic lapse in the content or implementation of procedures or records which could reasonably lead to a systematic failure or significant deficiency of the Information Security Management System (ISMS) if not corrected.

30 days

Observation

An area of concern, a process, document, or activity that is currently conforming but may, if not improved, result in a nonconforming system, product or service.

3 months

Opportunity for

Improvement

Opportunity for Improvement is a positive finding. It can be an improvement compared to the previous audit, or processes that perform better than expected, e.g., best practice.

NA

Corrective Actions

The auditor shall:

  • Identify nonconformities of the implementation and/or operation of the ISMS.

  • Review the corrective action taken.

  • Ensure that corrective action is implemented.

  • Present the report to the top management team.

External Audit

  • External Audit is conducted by an External Auditor.

  • The qualifying lead auditor shall be independent and remain impartial to the auditee and process throughout the Audit.

  • An auditor shall be able to apply audit principles, procedures, and techniques and conduct the audit effectively.

Control mapping

Mapping to ISO Control (s)

ISO 27001:2022 Control Control Objective
Clause 9.2

Internal Audit

A.5.35

Independent review of information security

A.5.36

Compliance with policies, rules, and standards for information security

A.8.34

Protection of information systems during audit testing

Exceptions

Any exceptions to this Policy and Procedure shall be reviewed and approved by the CTO or a delegate prior to acceptance.

Review

This Policy and Procedure shall be reviewed and approved by the CTO or a deligateonce a year or at the time of any major change in existing environment affecting policy, whichever is earlier.