workflow

ISO 27001 Stage 2 Annex A Controls Audit

Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
audit
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
domains
  • audit
standards
  • iso-27001
sourceTemplateId
workflow-library:audit-iso27001-stage2-controls-audit
releaseId
sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae
canonicalUrl
https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-ACCESS-02
    • UC-ACCESS-03
    • UC-ACCESS-04
    • UC-ACCESS-05
    • UC-ACCESS-06
    • UC-ACCESS-08
    • UC-ACCESS-09
    • UC-ACCESS-18
    • UC-ASSET-01
    • UC-ASSET-03
    • UC-ASSET-04
    • UC-ASSET-06
    • UC-ASSET-07
    • UC-ASSET-08
    • UC-AUDIT-23
    • UC-AUDIT-24
    • UC-AUDIT-25
    • UC-BCDR-01
    • UC-BCDR-03
    • UC-BCDR-04
    • UC-CONFIG-01
    • UC-CONFIG-02
    • UC-CONFIG-03
    • UC-CONFIG-05
    • UC-CRYPTO-02
    • UC-DATA-09
    • UC-DATA-11
    • UC-DATA-12
    • UC-DATA-13
    • UC-GOV-03
    • UC-GOV-06
    • UC-GOV-07
    • UC-GOV-08
    • UC-GOV-14
    • UC-GOV-22
    • UC-GOV-23
    • UC-HR-01
    • UC-HR-02
    • UC-HR-03
    • UC-HR-04
    • UC-HR-05
    • UC-HR-07
    • UC-IR-01
    • UC-IR-03
    • UC-IR-04
    • UC-IR-06
    • UC-IR-07
    • UC-IR-10
    • UC-LOG-01
    • UC-LOG-02
    • UC-LOG-04
    • UC-LOG-08
    • UC-NET-01
    • UC-NET-13
    • UC-PHYS-01
    • UC-PHYS-02
    • UC-PHYS-03
    • UC-PHYS-04
    • UC-PHYS-05
    • UC-PHYS-06
    • UC-PHYS-08
    • UC-PHYS-09
    • UC-RISK-02
    • UC-RISK-17
    • UC-SDLC-01
    • UC-SDLC-03
    • UC-SDLC-04
    • UC-SDLC-05
    • UC-SDLC-10
    • UC-SDLC-14
    • UC-TPRM-01
    • UC-TPRM-04
    • UC-TPRM-07
    • UC-TPRM-08
    • UC-TRAIN-01
    • UC-VULN-03
    • UC-VULN-04
    • UC-VULN-05
    roleIntegrity
    activityCount
    5
    ermPhases
    • assess
    • report
    lineRoles
    • third
    serviceModes
    • assurance
    warnings
    • code
      reliance-basis-incomplete
      title
      Reliance basis is incomplete
      message
      Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
      missing
      • competence
      • recency
      nodeIds
      • approve-annex-a-conclusion
      • assess-organizational-controls
      • assess-people-controls
      • assess-physical-controls
      • assess-technological-controls

    Source

    No record-specific source URL is provided.

    Download workflow template · Release: sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae

    Connections