ISO 27001 Lead Auditor Study Guide
Domain 3: Fundamental Audit Concepts and Principles
1. MAIN AUDIT CONCEPTS AND TERMINOLOGY (ISO 19011)
Key Definitions
Audit: Systematic, independent, and documented process for obtaining objective evidence and
evaluating it objectively to determine the extent to which audit criteria are fulfilled.
Audit Criteria: Set of requirements used as a reference against which objective evidence is
compared (e.g., ISO 27001 requirements, organizational policies).
Audit Evidence: Records, statements of fact, or other information that is relevant to the audit
criteria and verifiable.
Audit Findings: Results of the evaluation of collected audit evidence against audit criteria. Can
be conformities, nonconformities, observations, or opportunities for improvement.
Audit Conclusion: Outcome of an audit provided by the audit team after consideration of audit
objectives and all audit findings.
Auditee: Organization being audited.
Auditor: Person who conducts an audit with demonstrated competence.
Audit Client: Organization or person requesting an audit (may be the auditee or a regulatory
body).
Audit Team: One or more auditors conducting an audit, supported if needed by technical
experts.
Competence: Ability to apply knowledge and skills to achieve intended results.
Conformity: Fulfillment of a requirement.
Nonconformity: Non-fulfillment of a requirement (may be classified as major or minor).
Objective Evidence: Data supporting the existence or verity of something (can be qualitative or
quantitative).
2. AUDIT PRINCIPLES (ISO 19011)
The Seven Fundamental Principles
1. Integrity
Foundation of professionalism
Auditors demonstrate honesty, diligence, and responsibility
Comply with legal and professional requirements
Are impartial and truthful in all professional dealings
Application: Auditors must resist pressure from auditees to overlook findings, must report what
they observe accurately, and must maintain professional standards even when inconvenient.
2. Fair Presentation
Obligation to report truthfully and accurately
Audit findings, conclusions, and reports reflect audit activities accurately
Significant obstacles encountered during audit are reported
Reports are complete, accurate, objective, and timely
Application: Present both positive and negative findings objectively; don't exaggerate or
minimize issues; communicate clearly what was audited and what was not.
3. Due Professional Care
Application of diligence and judgment in auditing
Exercise care appropriate to the importance of task and confidence placed by audit
client and stakeholders
Have ability to make reasoned judgments in all audit situations
Consider audit scope, complexity, and sampling methodology
Application: Be thorough but efficient; don't rush through audits; consider the significance of
findings in context; know when to investigate further.
4. Confidentiality
Security and discretion with information
Auditors exercise discretion in the use and protection of information acquired during
audit
Information not used inappropriately for personal gain or to harm legitimate interests
Includes protection of information sources
Application: Don't discuss audit findings with unauthorized parties; protect proprietary
information; secure audit records properly; respect sensitive information.
5. Independence
Basis for impartiality and objectivity of audit conclusions
Auditors are independent of activity being audited
Act objectively throughout the audit process
Free from bias and conflict of interest
Application: Auditors should not audit their own work, areas they recently managed, or where
personal relationships could compromise objectivity. Declare conflicts of interest.
6. Evidence-Based Approach
Rational method for reaching reliable and reproducible audit conclusions
Audit evidence is verifiable
Based on samples of available information
Appropriate use of sampling directly related to confidence in audit conclusions
Application: Base findings on what you can verify; use appropriate sampling techniques; ensure
evidence is sufficient, relevant, and reliable; document sources of evidence.
7. Risk-Based Approach
Audit approach that considers risks and opportunities
Focuses audit effort on matters that are significant to the audit client
Audit planning and execution considers organizational risk
Affects audit scope, sampling, and time allocation
Application: Allocate more time to high-risk areas; consider likelihood and impact when
prioritizing audit activities; understand the organization's risk profile.
3. AUDIT TYPES: FIRST, SECOND, AND THIRD PARTY
First Party Audit (Internal Audit)
Conducted by: The organization itself (or on its behalf)
Purpose: Self-assessment, continual improvement, management review input
Independence: Auditors independent from audited area but employed by organization
Frequency: As determined by organization's internal audit program
Example: Company's internal audit team auditing IT department's ISMS controls
Key Characteristics:
Less formal than external audits
Can be more detailed and extensive
Results typically confidential to organization
Primary focus on improvement rather than certification
Second Party Audit (Supplier/Customer Audit)
Conducted by: Customers or parties with interest in the organization (e.g., supply chain
partner)
Purpose: Verify supplier compliance with contractual or regulatory requirements
Independence: External to auditee but not independent certification body
Example: Bank auditing cloud service provider's information security practices
Key Characteristics:
Protects customer's interests
May focus on specific contractual requirements
Can be required by contract or regulation
Results shared between customer and supplier
Third Party Audit (Certification/Registration Audit)
Conducted by: Independent, accredited certification bodies
Purpose: Certification, registration, compliance verification
Independence: Completely independent from auditee
Authority: Certification body accredited by national accreditation body
Example: PECB-accredited auditor conducting ISO 27001 certification audit
Key Characteristics:
Most formal and rigorous
Results in certificate if successful
Regular surveillance and recertification required
Findings can impact organizational reputation
Must follow accreditation body requirements
Comparison Table
Aspect First Party Second Party Third Party
Auditor Internal Customer/Partner Independent CB
Impartiality Lower Medium Highest
Formality Lower Medium Highest
Cost Lower Medium Highest
Credibility Internal only Customer confidence Market recognition
4. PECB CODE OF ETHICS & PROFESSIONAL RESPONSIBILITY
Core Ethical Obligations
Professionalism
Maintain technical competence through continuous professional development
Perform work with due care, diligence, and professional behavior
Avoid activities that discredit the profession
Not misrepresent qualifications or experience
Situations That Discredit Professionalism:
Accepting bribes or gifts that could influence judgment
Falsifying audit evidence or findings
Auditing own work or areas of recent responsibility
Claiming competence in areas where not qualified
Discussing confidential information publicly
Misrepresenting certification status
Plagiarizing others' work
Confidentiality Obligations
Protect information obtained during audits
Not disclose information without proper authorization
Secure audit documentation appropriately
Respect proprietary and sensitive information
Independence and Objectivity
Avoid conflicts of interest
Disclose any circumstances that could compromise impartiality
Decline assignments where independence cannot be maintained
Make decisions based on evidence, not personal bias
Ethical Issues and Obligations
To Audit Client:
Provide competent, professional service
Complete work within agreed scope and timeframe
Report findings accurately and completely
Declare any conflicts of interest
Maintain confidentiality unless legal obligation requires disclosure
To Auditee:
Conduct audit with minimal disruption
Respect auditee's operations and personnel
Provide clear explanations of requirements
Be fair and objective in evaluations
Protect confidential business information
To Law Enforcement and Regulatory Authorities:
Comply with applicable laws and regulations
Report certain findings when legally required (e.g., fraud, illegal activities)
Cooperate with investigations when legally obligated
Understand mandatory reporting requirements in jurisdiction
Legal Implications of Irregularities
When Auditor Discovers Illegal Activities:
1. Document: Record the evidence carefully
2. Report: Inform audit team leader and client immediately
3. Escalate: Follow organizational and legal reporting procedures
4. Compliance: Understand jurisdiction-specific reporting requirements
5. Confidentiality: Balance ethical duty to report with confidentiality obligations
Examples Requiring Action:
Fraud or embezzlement
Data breaches affecting personal information (GDPR, etc.)
Violations of industry-specific regulations
Criminal activities
Serious safety violations
Auditor Should:
Know reporting obligations before starting audit
Consult with legal counsel when uncertain
Document the irregularity thoroughly
Follow certification body and legal guidelines
Not conduct criminal investigations (not auditor's role)
5. EVIDENCE-BASED APPROACH IN ISMS AUDITS
Fundamental Concepts
Audit Evidence: Information that can be verified and is relevant to audit criteria. Foundation for
all audit findings and conclusions.
Characteristics of Good Audit Evidence:
Sufficient: Adequate quantity to support findings
Reliable: Dependable and from credible sources
Relevant: Directly related to audit criteria and objectives
Verifiable: Can be confirmed through examination or testing
Evidence Collection Process
1. Plan: Determine what evidence is needed based on audit scope and criteria
2. Collect: Use multiple methods (interviews, observation, document review, testing)
3. Verify: Confirm accuracy and authenticity
4. Evaluate: Compare against audit criteria
5. Document: Record evidence clearly and systematically
6. Analyze: Form findings based on evidence patterns
Sources of Evidence
Documents and records
Interviews with personnel
Observation of activities and conditions
Results of tests and measurements
Data from information systems
Physical evidence from facilities
6. TYPES OF AUDIT EVIDENCE
1. Physical Evidence
Definition: Tangible items that can be physically examined
Characteristics: Directly observable, concrete, highly reliable
Examples:
o Security badges and access control devices
o Locked cabinets and safes
o Server room environmental controls
o Surveillance cameras
o Shredded documents
o Hardware inventory
Strengths: Objective, difficult to dispute
Limitations: May not show how things are actually used in practice
2. Documentary Evidence
Definition: Written or electronic information recorded in documents
Characteristics: Can be verified, reproduced, and retained
Examples:
o Policies and procedures
o Risk assessments
o Audit logs
o Incident reports
o Training records
o Contracts and agreements
o Configuration documentation
Strengths: Provides permanent record, can show historical patterns
Limitations: May not reflect actual practice; can be outdated or fabricated
3. Verbal Evidence (Testimonial)
Definition: Information obtained through interviews and discussions
Characteristics: Subjective, requires corroboration
Examples:
o Staff interviews about security procedures
o Management explanations of processes
o User testimony about system access
o Descriptions of incident response actions
Strengths: Provides context, reveals understanding and awareness
Limitations: Subject to bias, memory errors, and misunderstanding; must be
corroborated
4. Analytical Evidence
Definition: Results from analysis of data or information
Characteristics: Derived through systematic examination
Examples:
o Trend analysis of security incidents
o Statistical analysis of access logs
o Comparison of actual vs. expected results
o Cost-benefit analysis of controls
o Performance metrics analysis
Strengths: Can reveal patterns and relationships not otherwise visible
Limitations: Quality depends on underlying data and analysis methods
5. Technical Evidence
Definition: Results from technical testing and examination
Characteristics: Objective, based on technical methods
Examples:
o Vulnerability scan results
o Penetration test findings
o Network traffic analysis
o System configuration reviews
o Backup restoration tests
o Encryption verification
Strengths: Highly objective and measurable
Limitations: Requires technical expertise to collect and interpret
6. Mathematical Evidence
Definition: Evidence based on numerical calculations and measurements
Characteristics: Quantitative, verifiable through recalculation
Examples:
o Calculations of recovery time objectives (RTO)
o Percentage of staff completing security training
o Number of incidents per period
o System uptime percentages
o Compliance rates with security requirements
Strengths: Precise, objective, comparable over time
Limitations: Numbers alone may not provide full context
7. Confirmative Evidence
Definition: Evidence that confirms or validates other evidence
Characteristics: Corroborates findings from other sources
Examples:
o Cross-referencing different data sources
o Verifying interview statements with documentation
o Confirming observations through testing
o Third-party validation of claims
o Independent verification of controls
Strengths: Increases reliability of conclusions
Limitations: Time-consuming to obtain
Evidence Hierarchy (Reliability)
Most Reliable → Least Reliable
1. Physical evidence obtained directly by auditor
2. Technical evidence from objective testing
3. Mathematical calculations verified by auditor
4. Documentary evidence from original sources
5. Confirmative evidence from multiple sources
6. Analytical evidence with sound methodology
7. Verbal evidence (requires corroboration)
7. DETERMINING EVIDENCE REQUIREMENTS
Factors Influencing Type and Amount of Evidence
1. Audit Objectives
Certification audit requires more comprehensive evidence than surveillance
Investigative audits need more detailed evidence
Scope determines breadth of evidence needed
2. Risk Level
High-risk areas require more extensive evidence
Critical controls need stronger verification
More evidence needed where consequences of failure are severe
3. Complexity
Complex processes require multiple evidence types
Technical systems need technical and documentary evidence
Simple procedures may need less evidence
4. Previous Audit Results
Areas with previous nonconformities need more scrutiny
Good track record may allow reduced sampling (but still verify)
New implementations require thorough evidence
5. Materiality
Significant processes require more evidence
Core ISMS elements need thorough verification
Supporting processes may need less evidence
6. Confidence Level Required
Certification decisions need high confidence
Surveillance may accept moderate confidence
Internal audits can vary based on purpose
Evidence Sufficiency Guidelines
Sufficient evidence exists when:
Multiple sources corroborate findings
Sample size is appropriate for population and risk
Evidence covers all aspects of audit criteria
Patterns are clear and consistent
Auditor has confidence in conclusions
Indicators of Insufficient Evidence:
Single source only
Conflicting information not resolved
Gaps in evidence trail
Unable to verify key claims
Uncertainty about conclusions
Sampling Principles
When to Sample:
Large populations of similar items
Time or resource constraints
Risk-based approach indicates sampling appropriate
Sample Size Considerations:
Higher risk = larger sample
Greater variability = larger sample
Higher confidence required = larger sample
Previous good results = may allow smaller sample
Sampling Methods:
Random: Every item has equal chance of selection
Systematic: Select every nth item
Stratified: Divide population into groups, sample from each
Judgmental: Select based on auditor's professional judgment
8. APPLICABLE LAWS AND REGULATIONS
Categories of Applicable Laws
1. Data Protection and Privacy
GDPR (EU General Data Protection Regulation)
CCPA (California Consumer Privacy Act)
National data protection laws
Sector-specific privacy requirements
Auditor Considerations:
Verify lawful basis for processing
Check data subject rights implementation
Verify breach notification procedures
Review data transfer mechanisms
2. Industry-Specific Regulations
Healthcare: HIPAA (US), NHS regulations (UK)
Financial: PCI-DSS, SOX, PSD2, banking regulations
Telecommunications: CALEA, communications regulations
Government: FISMA, FedRAMP, national security requirements
3. Labor and Employment Laws
Employee monitoring requirements
Workplace privacy rights
Acceptable use policies
Employee data protection
4. Intellectual Property
Copyright protection for software and content
Patent considerations
Trade secret protection
Licensing compliance
5. Contract Law
Service level agreements
Non-disclosure agreements
Supplier contracts
Customer contracts
Auditor's Responsibilities
Must:
Know relevant laws in auditee's jurisdiction(s)
Verify auditee has identified applicable legal requirements
Check if auditee monitors regulatory changes
Confirm compliance mechanisms exist
Report significant legal violations appropriately
Should Not:
Provide legal advice (not auditor's role)
Make definitive legal interpretations
Replace legal compliance audits
Assume responsibility for auditee's legal compliance
9. BIG DATA IN AUDITS
What is Big Data in Auditing?
Definition: Use of large, complex data sets and advanced analytics to support audit objectives.
Characteristics (The 5 Vs):
Volume: Large quantities of data
Velocity: High-speed data generation and processing
Variety: Multiple data types and sources
Veracity: Data quality and trustworthiness
Value: Meaningful insights extracted from data
Applications in ISMS Audits
1. Log Analysis
Analyze millions of access log entries
Identify unusual access patterns
Detect anomalies in user behavior
Verify access control effectiveness
2. Trend Analysis
Long-term security incident trends
Performance metrics over time
Compliance rate changes
Control effectiveness patterns
3. Risk Assessment
Aggregate risk data from multiple sources
Predictive analytics for potential threats
Correlation of risk indicators
Real-time risk monitoring
4. Continuous Monitoring
Real-time compliance verification
Automated control testing
Exception identification
Automated reporting
Benefits for Auditors
Increased Coverage: Analyze entire populations vs. samples
Better Insights: Identify patterns not visible in small samples
Efficiency: Automated data analysis saves time
Objectivity: Reduces reliance on subjective judgment
Continuous Audit: Enable ongoing verification between audits
Challenges and Considerations
Data Quality:
Garbage in, garbage out principle
Need to verify data accuracy and completeness
Understand data sources and collection methods
Technical Competence:
Auditors need data analytics skills
Understanding of tools and techniques
Ability to interpret results correctly
Privacy and Ethics:
Large-scale data analysis may raise privacy concerns
Must comply with data protection regulations
Ethical use of employee monitoring data
Over-reliance:
Data analysis supplements, not replaces, professional judgment
Still need to verify critical findings through traditional methods
Cannot replace observation and interviews entirely
Tools and Techniques
Common Audit Data Analytics Tools:
CAAT (Computer-Assisted Audit Techniques)
ACL, IDEA, Power BI, Tableau
SQL queries and database analytics
SIEM (Security Information and Event Management) systems
Log analysis tools
10. AUDITING OUTSOURCED OPERATIONS
Importance in ISMS Context
Organizations increasingly outsource IT and security functions:
Cloud services
Managed security services
Data center operations
Application development
Support services
ISO 27001 Requirement: Organization maintains responsibility for outsourced processes
affecting ISMS.
Key Principles
1. Retained Responsibility
Organization cannot outsource responsibility
Must ensure supplier meets ISMS requirements
Accountable for supplier's failures
Must maintain oversight and control
2. Due Diligence
Supplier selection process
Security requirements in contracts
Regular supplier assessment
Right to audit clauses
Auditing Approach
Pre-Audit Planning
Review:
Contracts and service level agreements
Supplier's security certifications (e.g., ISO 27001)
Agreed security controls
Interface between organization and supplier
Incident management procedures
Determine:
What processes are outsourced
What controls are supplier's responsibility
Organization's monitoring mechanisms
Previous supplier audit results
During the Audit
Audit the Organization's Controls:
Supplier selection and due diligence process
Contract terms regarding security requirements
Monitoring of supplier performance
Review of supplier audit reports
Incident management with supplier
Exit strategy and data recovery plans
Options for Auditing Supplier:
1. Direct Audit: Audit supplier's facilities (requires contractual right)
2. Third-Party Reports: Review supplier's ISO 27001 certification or SOC 2 reports
3. Questionnaires: Supplier self-assessment reviewed by auditor
4. Site Visits: Observe supplier operations if accessible
Challenges
Access Limitations:
May not have physical access to supplier facilities
Confidentiality restrictions
Shared infrastructure (especially cloud)
Multi-tenant environments
Solutions:
Rely on third-party certifications
Review independent audit reports (SOC 2 Type II)
Focus on organization's oversight mechanisms
Verify monitoring and reporting arrangements
Evidence to Collect
Documentary:
Contracts with security requirements
SLAs and performance metrics
Supplier security policies
Incident reports and resolutions
Supplier audit reports or certifications
Analytical:
Supplier performance trends
Incident frequency and resolution times
Compliance rates
Cost vs. benefit analysis
Verbal:
Interviews with supplier relationship managers
Discussions with technical contacts
Understanding of escalation procedures
Confirmative:
Verification of supplier claims
Cross-check between different evidence sources
Validation of monitoring data
Critical Control Areas
Must Verify:
Data protection and confidentiality
Access control to organization's data
Backup and recovery procedures
Incident notification and response
Right to audit provisions
Termination and data return procedures
Supplier's own information security management
Supply chain security (sub-contractors)
Special Considerations: Cloud Services
Shared Responsibility Model:
IaaS: Customer responsible for OS up
PaaS: Customer responsible for applications/data
SaaS: Vendor responsible for most security
Must Audit:
Understanding of shared responsibilities
Configuration of cloud security controls
Data location and sovereignty
Encryption in transit and at rest
Identity and access management
Logging and monitoring capabilities
EXAM PREPARATION TIPS
Key Areas to Master
1. Memorize the 7 audit principles and be able to apply them to scenarios
2. Distinguish clearly between 1st, 2nd, and 3rd party audits - know examples
3. Understand evidence types and which are most reliable
4. Know PECB Code of Ethics and identify ethical violations
5. Apply risk-based thinking to audit planning scenarios
6. Understand auditor's role with legal issues - report but don't investigate
Common Exam Question Types
Scenario-Based:
"An auditor discovers X situation. What should they do?"
"Which type of evidence would be most appropriate for verifying Y?"
"Is this a first, second, or third-party audit?"
Principle Application:
"Which audit principle is being violated in this scenario?"
"How would you apply due professional care in this situation?"
Ethics Questions:
"The auditee offers the auditor a gift. What should the auditor do?"
"Should the auditor report this irregularity to authorities?"
Study Strategies
1. Create flashcards for definitions and principles
2. Practice scenario analysis - apply principles to real situations
3. Compare and contrast: Evidence types, audit types, ethical considerations
4. Focus on "why" not just "what" - understand reasoning
5. Review case studies and past scenarios if available
Quick Reference Mnemonics
Seven Audit Principles: "I Failed Due Care, In Every Respect"
Integrity
Fair presentation
Due professional care
Confidentiality
Independence
Evidence-based approach
Risk-based approach
Evidence Types: "Please Don't Visit The Awkward Math Class"
Physical
Documentary
Verbal
Technical
Analytical
Mathematical
Confirmative
PRACTICE QUESTIONS
Question 1
You are auditing an organization and discover that an employee has been accessing customer
data without authorization. The employee has been terminated, but management hasn't
reported the breach to authorities. What should you do?
Answer: Document the finding, include it in the audit report as a nonconformity (failure to
comply with breach notification requirements), and inform management of their legal
obligations. As an auditor, you should not report directly to authorities (unless legally obligated
in your jurisdiction), but you must document management's failure to comply with legal
requirements. This could be a significant finding affecting certification.
Question 2
During an audit, you need to verify that employees are following the password policy. What
types of evidence would be most appropriate?
Answer:
Technical evidence: Review system configuration to verify password complexity
requirements are enforced
Documentary evidence: Review password policy documentation
Analytical evidence: Analyze password change logs and frequency
Verbal evidence: Interview IT staff about policy enforcement (requires corroboration)
Confirmative evidence: Cross-check multiple sources
Avoid: Asking employees to reveal their passwords (violates confidentiality and security)
Question 3
A supplier offers to take you on a weekend trip while you're conducting a second-party audit of
their facility. What should you do?
Answer: Politely decline. Accepting would violate the principles of independence and integrity,
creating a conflict of interest that could compromise audit objectivity. Even the perception of
bias can discredit the audit. Document the offer and report it to your audit team leader or
management.
FINAL CHECKLIST FOR EXAM READINESS
[ ] Can explain all 7 audit principles with examples
[ ] Can differentiate 1st, 2nd, and 3rd party audits
[ ] Know all 7 types of evidence and their reliability
[ ] Understand evidence sufficiency and sampling
[ ] Can identify ethical violations and appropriate responses
[ ] Know auditor's responsibilities with legal issues
[ ] Understand risk-based approach to auditing
[ ] Can apply principles to practical scenarios
[ ] Understand outsourcing audit considerations
[ ] Know role of big data in modern auditing
[ ] Familiar with key ISO 19011 terminology
[ ] Can make appropriate professional judgments in scenarios
Good luck with your certification exam!
ISO 27001 Lead Auditor Study Guide - Domain 3
Fundamental Audit Concepts and Principles
I'll create a comprehensive study guide covering all the competencies and knowledge
statements for Domain 3.
I've created a comprehensive study guide that covers all aspects of Domain 3 for your ISO 27001
Lead Auditor certification. The guide includes:
Key Features:
1. Complete Coverage - All 9 knowledge statements and 9 competencies addressed
2. Detailed Definitions - Key terminology from ISO 19011 explained clearly
3. Practical Examples - Real-world scenarios to illustrate concepts
4. Comparison Tables - Easy reference for audit types and evidence comparison
5. Exam Tips - Study strategies and common question types
6. Practice Questions - Sample scenarios with detailed answers
7. Memory Aids - Mnemonics for the 7 principles and 7 evidence types
8. Quick Checklist - Final review before the exam
How to Use This Guide:
First Pass: Read through thoroughly to understand all concepts
Second Pass: Focus on areas you find challenging (likely principles application and
evidence types)
Practice: Work through scenarios - apply principles to different situations
Memorize: Use the mnemonics for the 7 principles and 7 evidence types
Review: Use the checklist to ensure you've mastered everything
The exam will heavily test your ability to apply these concepts to real-world scenarios, rather
than just memorizing definitions. Pay special attention to the ethics sections and practice
making judgments about what an auditor should do in various situations.
Would you like me to create additional practice scenarios or expand on any particular section?