Loading...
Loading...
Compare original and translation side by side
| Risk Level | Audit Frequency | Examples |
|---|---|---|
| Critical | Quarterly | Privileged access, vulnerability management, logging |
| High | Semi-annual | Access control, incident response, encryption |
| Medium | Annual | Policies, awareness training, physical security |
| Low | Annual | Documentation, asset inventory |
| 风险等级 | 审计频率 | 示例 |
|---|---|---|
| 关键 | 季度 | 特权访问、漏洞管理、日志记录 |
| 高 | 半年 | 访问控制、事件响应、加密 |
| 中 | 年度 | 政策、意识培训、物理安全 |
| 低 | 年度 | 文档、资产清单 |
| Method | Use Case | Example |
|---|---|---|
| Inquiry | Process understanding | Interview Security Manager about incident response |
| Observation | Operational verification | Watch visitor sign-in process |
| Inspection | Documentation review | Check access approval records |
| Re-performance | Control testing | Attempt login with weak password |
| 方法 | 使用场景 | 示例 |
|---|---|---|
| 询问 | 流程理解 | 访谈安全经理了解事件响应流程 |
| 观察 | 运行验证 | 查看访客登记流程 |
| 检查 | 文档审阅 | 检查访问审批记录 |
| 重新执行 | 控制测试 | 尝试使用弱密码登录 |
| Severity | Definition | Response Time |
|---|---|---|
| Major Nonconformity | Control failure creating significant risk | 30 days |
| Minor Nonconformity | Isolated deviation with limited impact | 90 days |
| Observation | Improvement opportunity | Next audit cycle |
| 严重程度 | 定义 | 响应时间 |
|---|---|---|
| 重大不符合项 | 控制措施失效,带来重大风险 | 30天 |
| 轻微不符合项 | 孤立偏差,影响有限 | 90天 |
| 观察项 | 改进机会 | 下一审计周期 |
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]| Period | Focus |
|---|---|
| Year 1, Q2 | High-risk controls, Stage 2 findings follow-up |
| Year 1, Q4 | Continual improvement, control sample |
| Year 2, Q2 | Full surveillance |
| Year 2, Q4 | Re-certification preparation |
| 周期 | 重点 |
|---|---|
| 第1年第2季度 | 高风险控制措施、第二阶段问题跟进 |
| 第1年第4季度 | 持续改进、控制措施抽样 |
| 第2年第2季度 | 全面监督审计 |
| 第2年第4季度 | 重新认证准备 |
| Script | Purpose | Usage |
|---|---|---|
| Generate risk-based audit plans | |
| 脚本 | 用途 | 使用方法 |
|---|---|---|
| 生成基于风险的审计计划 | |
undefinedundefined
---
---| File | Content |
|---|---|
| iso27001-audit-methodology.md | Audit program structure, pre-audit phase, certification support |
| security-control-testing.md | Technical verification procedures for ISO 27002 controls |
| cloud-security-audit.md | Cloud provider assessment, configuration security, IAM review |
| 文件 | 内容 |
|---|---|
| iso27001-audit-methodology.md | 审计计划结构、审计前阶段、认证支持 |
| security-control-testing.md | ISO 27002控制措施的技术验证流程 |
| cloud-security-audit.md | 云服务商评估、配置安全、IAM审阅 |
| KPI | Target | Measurement |
|---|---|---|
| Audit plan completion | 100% | Audits completed vs. planned |
| Finding closure rate | >90% within SLA | Closed on time vs. total |
| Major nonconformities | 0 at certification | Count per certification cycle |
| Audit effectiveness | Incidents prevented | Security improvements implemented |
| KPI | 目标 | 衡量方式 |
|---|---|---|
| 审计计划完成率 | 100% | 已完成审计数 vs 计划审计数 |
| 问题闭环率 | SLA内>90% | 按时闭环数 vs 总数 |
| 重大不符合项数 | 认证时为0 | 每认证周期的数量 |
| 审计有效性 | 预防事件发生 | 已实施的安全改进措施 |
| Framework | ISMS Audit Relevance |
|---|---|
| GDPR | A.5.34 Privacy, A.8.10 Information deletion |
| HIPAA | Access controls, audit logging, encryption |
| PCI DSS | Network security, access control, monitoring |
| SOC 2 | Trust Services Criteria mapped to ISO 27002 |
| 框架 | ISMS审计相关性 |
|---|---|
| GDPR | A.5.34隐私、A.8.10信息删除 |
| HIPAA | 访问控制、审计日志、加密 |
| PCI DSS | 网络安全、访问控制、监控 |
| SOC 2 | 映射至ISO 27002的信任服务准则 |