Information Systems Audit
What is Information Systems Audit?
An examination of an organization's information systems, technology infrastructure, and IT controls to evaluate security, reliability, and compliance.
Frameworks that govern information systems audit
What the standards actually require on information systems audit
Requirements naming information systems audit across 3 standards, quoted from the control text.
Requirement defined in ISO 27017:2015, clause 12.7 (Information systems audit considerations). See licensed source for normative text.
iso-27017-2015::12.7 · Information systems audit considerations →Requirement defined in ISO 27018:2019, clause 12.7 (Information systems audit considerations ISO/IEC 27018:2019). See licensed source for normative text.
iso-27018-2019::12.7 · Information systems audit considerations ISO/IEC 27018:2019 →Information systems audit controls apply as the base guidance requires, so audit activity on operational systems is planned and agreed to minimise disruption, read as covering systems that process personal data.
iso-27701-2019::6.9.7 · Information systems audit considerations →Questions people ask about information systems audit
What is Information Systems Audit?
Why is Information Systems Audit important for compliance?
Which compliance frameworks address Information Systems Audit?
Where can I learn more about Information Systems Audit?
See how Information Systems Audit applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.