{"description":"Certification-body Stage 1 review of the ISMS against ISO/IEC 27001:2022 clauses 4–10: context and leadership, planning and support, operation, and performance evaluation with improvement - walking each clause group against the governing documents and the operating processes that carry it, and concluding Stage 2 readiness with dual sign-off. Stage 1 documentation and readiness review for ISO/IEC 27001:2022 clauses 4–10, conducted under the engagement methodology. It informs Stage 2 planning and does not issue a certification decision. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-AUDIT-21","UC-AUDIT-22","UC-AUDIT-23","UC-AUDIT-25","UC-CONFIG-02","UC-GOV-02","UC-GOV-06","UC-GOV-11","UC-GOV-12","UC-GOV-14","UC-GOV-15","UC-GOV-16","UC-HR-06","UC-RISK-03","UC-RISK-06","UC-RISK-09","UC-RISK-14","UC-RISK-15","UC-TRAIN-01"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage1-documentation-review","contentDigest":"sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Stage 1 documentation and readiness review for ISO/IEC 27001:2022 clauses 4–10, conducted under the engagement methodology. It informs Stage 2 planning and does not issue a certification decision.","slug":"audit-iso27001-stage1-documentation-review","source":"coworkcanvas-gallery","standards":["iso-27001"],"teams":["internal-audit"]},"name":"ISO 27001 Stage 1 ISMS Documentation Review","nodes":[{"data":{"controls":["UC-AUDIT-21","UC-AUDIT-22","UC-AUDIT-23","UC-RISK-14","UC-RISK-15","UC-GOV-02","UC-GOV-06","UC-GOV-11","UC-GOV-14","UC-GOV-15","UC-RISK-03","UC-RISK-06","UC-RISK-09","UC-GOV-12","UC-GOV-16","UC-HR-06","UC-TRAIN-01","UC-AUDIT-25","UC-CONFIG-02"],"description":"Evaluate ISMS clauses 4–10 documentation and Stage 2 readiness and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.","instructions":"**Objective**\nEvaluate ISMS clauses 4–10 documentation and Stage 2 readiness and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned qualified assessor evaluates each observation; the lead assessor reviews conclusions. Any certification decision remains with the authorized certification body.\n\n- The ISMS Scope Document, the Information Security Policy, and the Board & Governance Policy at their current approved versions with effective dates\n- The linked ISMS governance process with its recent run records in AssureSwarm\n- The interested-parties analysis and the internal/external issues register\n- Organization charts and role definitions for the security function, including any outsourced security leadership arrangement\n\nThe Risk Management Policy, the Information Security Objectives, and the Human Resources Security Policy at current approved versions\n- The linked planning and support processes with recent run records: enterprise risk assessment, policy lifecycle, workforce security, and awareness training\n- The current risk register, treatment plan, and Statement of Applicability\n- Competence records: role-based training assignments and completion evidence\n\nThe Change Management Policy, the Risk Treatment Process, and the Configuration Management Policy at current approved versions\n- The linked operating processes and their recent run records in AssureSwarm\n- The most recent periodic risk assessment output and the treatment plan's implementation status\n- The change record for the platform: merge-request-driven changes in the source-control platform landing on the application hosting service via CI\n\nThe Internal Audit Program, Management Review Procedure, Nonconformity & Corrective Action Procedure, and Continual Improvement Process at current approved versions\n- The linked evaluation and improvement processes with run records: internal audit with management review, compliance evidence and external assurance, and continuous control operation\n- The latest internal audit reports, the management review minutes, and the corrective action log\n- Clause observations recorded across the preceding Stage 1 review activities\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Review ISMS Context & Leadership (Clauses 4–5)”, “Review Planning & Support (Clauses 6–7)”, “Review Operational Planning & Control (Clause 8)”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Review ISMS Context & Leadership (Clauses 4–5): Determine whether the ISMS foundations required by clauses 4 and 5 are documented and coherent: the organization's context and interested parties are analyzed (4.1–4.2), the ISMS scope is determined and available as documented information (4.3), leadership demonstrates commitment (5.1), an information security policy is established and communicated (5.2), and roles, responsibilities, and authorities are assigned (5.3). The linked governance process operates these requirements day to day; this review checks the documents against the standard and against each other.\n\n2. Verify the scope statement bounds the scoped service, its people, and its cloud, identity, and development-platform interfaces, and that exclusions are justified rather than silent.\n3. Trace clause 4.1–4.2 evidence: the context analysis names the issues and interested parties, and their requirements flow visibly into the scope and the risk work reviewed later in this Stage.\n4. Assess clause 5.1 commitment through artifacts, not assertions - resourcing decisions, management review participation, and objective-setting signed by leadership.\n5. Confirm the policy satisfies 5.2: appropriate to purpose, containing objectives or a framework for them, communicated with acknowledgment records.\n6. Verify 5.3 assignments are specific persons or roles with authorities that match the organization chart, and note every mismatch as a Stage 1 observation with clause reference.\n\n7. Assessment scope for Review Planning & Support (Clauses 6–7): Determine whether planning and support meet clauses 6 and 7: risk assessment and risk treatment processes are defined with criteria (6.1.1–6.1.3), the Statement of Applicability derives from treatment decisions, information security objectives are established and planned (6.2), changes are planned (6.3), and the supporting machinery exists - resources and competence (7.1–7.2), awareness (7.3), communication (7.4), and documented information under control (7.5). The linked processes carry these clauses in daily operation; this review tests the documented method behind them.\n\n8. Verify the risk method defines acceptance criteria, produces consistent and comparable results, and names risk owners - then trace two register entries from identification through treatment decision to their SoA lines.\n9. Confirm the SoA states inclusion or exclusion with justification for every Annex A control and reconciles with the treatment plan the Stage 2 assessors will test against.\n10. Check the objectives are measurable, communicated, and carried by a named owner with a plan (what, resources, who, when, how evaluated).\n11. Assess 7.2 and 7.3 through the HR-security provisions and the awareness process: competence is determined per role, and the workforce can be shown to know the policy and their part in it.\n12. Test 7.5 document control by sampling the linked documents themselves - version, approval, availability, and protection from unintended edits.\n\n13. Assessment scope for Review Operational Planning & Control (Clause 8): Determine whether clause 8 is satisfied in the documentation and visible in operation: processes needed to meet security requirements are planned and controlled with criteria (8.1), planned changes are controlled and unintended-change consequences reviewed, externally provided processes are controlled, risk assessments are performed at planned intervals (8.2), and the risk treatment plan is implemented with results retained as documented information (8.3). The linked processes - the operated risk cycle and continuous control operation with evidence monitoring - are where clause 8 lives between audits.\n\n14. Verify 8.1 planning: operating criteria exist for the security-relevant processes, and the run records show the criteria applied - not merely published.\n15. Trace change control from the documented method to practice by sampling one production change end to end and checking outsourced or externally provided elements are identified and controlled.\n16. Confirm 8.2 cadence: risk assessments happened at the planned intervals and on significant change, with results retained.\n17. Confirm 8.3 implementation: sampled treatment actions show completion evidence or a live, dated plan, and deviations fed back into the register.\n18. Assess whether evidence retention across these runs would sustain Stage 2 sampling - thin operational evidence at Stage 1 is the classic predictor of Stage 2 nonconformity, so call it now.\n\n19. Assessment scope for Review Performance Evaluation & Improvement (Clauses 9–10): Determine whether the ISMS evaluates and improves itself per clauses 9 and 10: monitoring, measurement, analysis, and evaluation are defined and performed (9.1), an internal audit programme operates with objective auditors (9.2), management reviews happen at planned intervals with the required inputs and outputs (9.3), nonconformities trigger correction and root-cause corrective action (10.1–10.2 as operated), and the system continually improves. Then consolidate all Stage 1 clause observations into the readiness conclusion for Stage 2.\n\n20. Verify 9.1 defines what is monitored, by whom, when, and how results are evaluated, and trace two measurements from the metrics catalog to evaluated results.\n21. Assess 9.2 for coverage and objectivity - examine how auditor independence is preserved for the staffing and sourcing model and whether the programme reached all ISMS areas on schedule.\n22. Check 9.3 minutes against the standard's required inputs and outputs, and that decisions became tracked actions.\n23. Sample the corrective action log for root-cause analysis, effectiveness checks, and closure discipline under the nonconformity procedure.\n24. Consolidate every clause observation from the context and leadership review, the planning and support review, and the operational control review into the Stage 1 report, classify findings, and present the Stage 2 readiness conclusion for sign-off by the lead assessor and independent engagement reviewer; an unresolved objection returns the work to the relevant review activity.\n\n**Record in AssureSwarm**\nRecord clause-by-clause observations on this activity with document references and versions cited. Anything that would obstruct Stage 2 - an unavailable document, an unassigned authority - is flagged as a Stage 1 finding on the certification audit.\n\nRecord clause-by-clause observations with the sampled register entries and SoA lines cited. Method defects that would undermine Stage 2 sampling are flagged as Stage 1 findings.\n\nRecord clause 8 observations with the sampled change and treatment actions cited by record. Retention or cadence gaps are flagged as Stage 1 findings with clause references.\n\nRecord clause 9–10 observations and attach the consolidated Stage 1 report with the readiness conclusion and the finding register. Both approvals are captured with date and capacity.\n\n**Exit criteria**\nClauses 4.1 through 5.3 each carry a documented conformity observation or finding, and the scope statement is agreed as the basis for Stage 2 planning. Clauses 6.1 through 7.5 each carry a documented conformity observation or finding, and the SoA version to be tested at Stage 2 is fixed and referenced. Clauses 8.1 through 8.3 each carry a documented conformity observation or finding, and the operational evidence base is judged sufficient to plan Stage 2 sampling. Clauses 9.1 through 10.2 each carry a documented observation or finding, the consolidated Stage 1 report is attached, the lead assessor and independent engagement reviewer have signed, and the Stage 2 plan has a confirmed basis.","kind":"task","label":"Review Performance Evaluation & Improvement (Clauses 9–10)","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-4"}],"sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review"}
