ISO 27001
Gaining your ISO 27001 Certification
External audit stage 1: Review of documentation

External audit stage 1: Review of documentation

The ISO 27001 audit is conducted in two stages: Documentation review and certification audit.

In the Audit Stage 1, documentation review, the ISMS (Information Security Management System) controls are reviewed as per their design and structure. It assesses the documentation that supports the ISO 27001 controls and safeguards in place.

In the documentation review audit, you get reviewed on:

Information security policies
Risk assessment reports
Security procedures and controls
Incident response plans
Training records and compliance documentation

Once the stage 1 review is done, the auditor provides feedback to the business on any gaps or weaknesses in the documentation. Only after the team addresses these gaps does the organization move forward to Stage 2, the formal certification audit.

The Sprinto advantage

From automating compliance checklists to monitoring security controls in real-time and more, Sprinto does the heavy lifting for you to get you compliant. ISO 27001 isn’t a one-time exercise. It requires constant monitoring and improvement to ensure you stay compliant. Sprinto doesn’t just help you pass the audit it helps you stay continuously compliant and add more compliances to your kitty with very little additional lift.
hub-iso-dark
Sprinto: Your ally for all things compliance, risk, governance
support-team