Skip to content

Information Systems Audit

What is Information Systems Audit?

An examination of an organization's information systems, technology infrastructure, and IT controls to evaluate security, reliability, and compliance.

Audit and Assurance

What the standards actually require on information systems audit

Requirements naming information systems audit across 3 standards, quoted from the control text.

Requirement defined in ISO 27017:2015, clause 12.7 (Information systems audit considerations). See licensed source for normative text.

iso-27017-2015::12.7 · Information systems audit considerations

Requirement defined in ISO 27018:2019, clause 12.7 (Information systems audit considerations ISO/IEC 27018:2019). See licensed source for normative text.

iso-27018-2019::12.7 · Information systems audit considerations ISO/IEC 27018:2019

Information systems audit controls apply as the base guidance requires, so audit activity on operational systems is planned and agreed to minimise disruption, read as covering systems that process personal data.

iso-27701-2019::6.9.7 · Information systems audit considerations

Questions people ask about information systems audit

What is Information Systems Audit?
An examination of an organization's information systems, technology infrastructure, and IT controls to evaluate security, reliability, and compliance.
Why is Information Systems Audit important for compliance?
Information Systems Audit is a key concept in Audit and Assurance. Understanding information systems audit helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Information Systems Audit?
Information Systems Audit appears in the requirement text of ISO 27017:2015, ISO 27018:2019, ISO 27701:2019. Across these standards we have identified 3 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Information Systems Audit?
Explore our compliance framework pages to see how information systems audit applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Information Systems Audit applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.