ISO 28002:2011
Annex A: Checking and corrective action – ISO 28002:2011

ISO 28002:2011 A.6.6: A.6.6 Internal audit

The organization audits its resilience policy internally at planned intervals and when management decides, to find out whether management objectives, controls, processes and procedures conform to this standard and applicable legal requirements, to its risk management requirements, are effectively implemented and maintained, and perform as expected. The audit programme reflects the status and importance of the areas audited and earlier results; criteria, scope, frequency and methods are set; auditors are chosen and audits run so the process is objective and impartial, and nobody audits their own work. A documented procedure says who plans and runs audits and how, and how results are reported and records kept (see A.6.5). Management of the audited area makes sure actions to remove nonconformities and their causes are taken without undue delay, and follow-up verifies the actions and reports the result. Annex B adds that auditors may be internal or external, must be competent and impartial, and that combined audits with security, safety or environmental audits need a clearly defined purpose and scope for each.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 9.2.1 General: internal audits
  • 9.2.2 Internal audit programme

ISO 22301:2019 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Checking and corrective action – ISO 28002:2011

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.