workflow
ISO 27001 Stage 1 ISMS Documentation Review
Certification-body Stage 1 review of the ISMS against ISO/IEC 27001:2022 clauses 4–10: context and leadership, planning and support, operation, and performance evaluation with improvement - walking each clause group against the governing documents and the operating processes that carry it, and concluding Stage 2 readiness with dual sign-off. Stage 1 documentation and readiness review for ISO/IEC 27001:2022 clauses 4–10, conducted under the engagement methodology. It informs Stage 2 planning and does not issue a certification decision. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- domains
- audit
- standards
- iso-27001
- sourceTemplateId
- workflow-library:audit-iso27001-stage1-documentation-review
- releaseId
- sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775
- canonicalUrl
- https://workflow-library.com/all/?w=audit-iso27001-stage1-documentation-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-21
- UC-AUDIT-22
- UC-AUDIT-23
- UC-AUDIT-25
- UC-CONFIG-02
- UC-GOV-02
- UC-GOV-06
- UC-GOV-11
- UC-GOV-12
- UC-GOV-14
- UC-GOV-15
- UC-GOV-16
- UC-HR-06
- UC-RISK-03
- UC-RISK-06
- UC-RISK-09
- UC-RISK-14
- UC-RISK-15
- UC-TRAIN-01
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- independence
- competence
- evidence
- recency
- reliance rationale
- nodeIds
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775
Connections
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-14 — Track deficiencies to closure with remediation action plans
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-HR-06 — Embed security and competence in HR practices
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-09 — Select, plan, and implement risk treatments
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-02 — Understand organizational context and stakeholder expectations
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-12 — Align strategy and business objectives with mission and risk
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-11 — Allocate adequate resources and budget for security
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-15 — Operate a management-approved information security program
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-TRAIN-01 — Deliver security awareness training to all personnel
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-22 — Review risk strategy and performance with leadership
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-06 — Define security roles, responsibilities, and authorities
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-25 — Maintain quality records and information for internal control
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-15 — Continually improve the risk management program
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-16 — Select and tailor a risk-based control baseline
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-06 — Perform periodic enterprise risk assessments