Compliance and internal audit

These categories are relatively self-explanatory: they deal with legal and technical compliance. The organisation should be aware of, and comply with, its legal obligations. Technical testing should report on the degree to which IT equipment, systems and software are as they should be. The schedule can include checks to confirm that only the right, approved equipment is connected to the network, that systems and software are as required (the approved mix and number for the licences held), and can include penetration testing to confirm the resilience of the technical measures in place.

Get An Introduction to Information Security and ISO27001: A Pocket Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.