The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page

Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > ISO 19011 - Quality and Environmental Management Systems Auditing > Internal Auditing
Forum Username

Elsmar Cove Forum Visitor Notice(s)


Elsmar Cove Forum Sidebar
Custom Search
Monitor the Elsmar Forum
Monitor New Forum Posts
Follow Marc & Elsmar
Elsmar Cove Forum RSS Feed  Marc Smith's Google+ Page  Marc Smith's Linked In Page   Marc Smith's Elsmar Cove YouTube Page  Marc Smith's Facebook Page
Elsmar Cove Groups
Elsmar Cove Google+ Group  Elsmar Cove LinkedIn Group  Elsmar Cove Facebook Group
Sponsor Links







Donate and $ Contributor Forum Access
Sponsored Links
Courtesy Quick Links

Links that Elsmar Cove visitors will find useful in your quest for knowledge:


Howard's
International Quality Services

Atul's
Symphony Technologies

Marcelo Antunes'
SQR Consulting

Bob Doering's
Correct SPC - Precision Machining


NIST's Engineering Statistics Handbook

IRCA - International Register of Certified Auditors

SAE - Society of Automotive Engineers

Quality Digest Portal

IEST - Institute of Environmental Sciences and Technology

ASQ - American Society for Quality


Related Topic Tags
audits and auditing, internal audits, iso 27001 - information security management system (isms)
Reply
 
Thread Tools Search this Thread Rate Thread Content Display Modes
  #1  
Old 27th January 2011, 09:22 AM
S. Thompson's Avatar
S. Thompson S. Thompson is offline
Registered Visitor

 
Registration Date: Aug 2003
Location: England West Midlands
Age: 50
 
Posts: 40
Thanks Given to Others: 4
Thanked 4 Times in 2 Posts
Karma Power: 44
Karma: 30
S. Thompson has less than 100 Karma points so far.
Please Help! Internal Audits to ISO 27001 (Information Security)

Hi there,

We are currently going through our 2nd surveillance to 27001 (Information Security) The auditor is here at the moment with our Chief Informaiton Security Officer.

My collegue has within the last few minutes told me that the auditor will raise a non conformance against him as he has been perfoming internal audits. My collegue does not agree with this (as I don't) The auditor has citied that he can not be impartial as he works for the company and owns the system. (my collegue has just completed a full audit training programme)

He said it would be acceptable that I audit the 27001 system we have in place although my collegue argued that I would not have the specialised knowledge to do this. Failing this, then an external company.

I have been performing internal audits at the company for 15 years to 9001 and for 3 years to 14001 and have not had one non conformance re this previously.

I would appreciate your information on this please?

Many Thanks
__________________
[

Sponsored Links
  #2  
Old 27th January 2011, 09:36 AM
Marc's Avatar
Marc Marc is online now
Your Elsmar Cove Host

 
Registration Date: Jan 1996
Location: West Chester - Southern Ohio - USA
Age: 62
 
Posts: 22,812
Thanks Given to Others: 7,457
Thanked 4,543 Times in 2,894 Posts
Blog Entries: 4
Karma Power: 400
Karma: 28830
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Re: Internal Audits to ISO 27001 (Information Security)

The rule is you can not audit your own work. It is not that you can not audit the work of someone who works under/for you.

This is the reason for many discussions of "Who Audits the Auditor?"
__________________
A Search is a terrible thing to waste!
One Test is Worth 1000 Expert Opinions - The plural of anecdote is not data - Correlation does not imply Causation
We can't solve problems by using the same kind of thinking we used when we created them. - Unknown
Sponsored Links

  #3  
Old 3rd February 2011, 09:38 AM
S. Thompson's Avatar
S. Thompson S. Thompson is offline
Registered Visitor

 
Registration Date: Aug 2003
Location: England West Midlands
Age: 50
 
Posts: 40
Thanks Given to Others: 4
Thanked 4 Times in 2 Posts
Karma Power: 44
Karma: 30
S. Thompson has less than 100 Karma points so far.
Re: Internal Audits to ISO 27001 (Information Security)

I understand this - that you cannot audit your own work - that is why another auditor audits areas of 9001 & 14001 that I am responsible for such as document control, internal audits etc. This auditor has said that because the Information Security Manager owns the IMS he cannot audit it. I class the management systems as being 'owned' by the company not one person.

Any comments greatly appreciated.
__________________
[
  #4  
Old 3rd February 2011, 09:47 AM
Colin's Avatar
Colin Colin is offline
Appreciated Information Resource

 
Registration Date: Oct 2006
Location: UK - North West
 
Posts: 1,293
Thanks Given to Others: 340
Thanked 861 Times in 524 Posts
Karma Power: 169
Karma: 6686
Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.
Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.
Re: Internal Audits to ISO 27001 (Information Security)

Perhaps the argument could be that the IMS manager doesn't own the IMS, the departmental managers own their bit and the IMS manager manages the system. The IMS manager is not responsible for purchasing for example but is responsible for ensuring that there are appropriate systems in place to provide control over the information used in the department.
__________________
If you think training is expensive, try ignorance
Reply

Lower Navigation Bar
Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > ISO 19011 - Quality and Environmental Management Systems Auditing > Internal Auditing

Do you find this discussion thread helpful and informational?


Bookmarks


Visitors Currently Viewing this Thread: 1 (0 Registered Visitors (Members) and 1 Unregistered Guest Visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Forum Search
Display Modes Rate Thread Content
Rate Thread Content:

Forum Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Discussion Threads
Discussion Thread Title Thread Starter Forum Replies Last Post or Poll Vote
ISO 27001:2005 Information Security Management System - Revision Status PE-2011 ISO/IEC 27000 - Information Security Management Systems (ISMS) 5 10th May 2011 07:40 AM
ISO 27001 compliant Information Security Log chris02 ISO/IEC 27000 - Information Security Management Systems (ISMS) 8 7th April 2011 09:17 PM
Statement of Applicability per ISO 27001:2005 Information Security - Seeking Example intrestedparty Other ISO and International Standards and European Regulations 5 13th May 2009 06:45 AM
ISO 27001 Information Security - How to write documentation and where to start zillah Other ISO and International Standards and European Regulations 30 11th May 2009 06:57 AM



The time now is 06:28 PM. All times are GMT -4.
Your time zone can be changed in your UserCP --> Options.


   


Marc Timothy Smith - Elsmar.com
8466 LeSourdsville-West Chester Road, Olde West Chester, Ohio 45069-1929
513 341-6272