ISO 2700119 August 2026
Information security audit planning with laptop and evidence documents

What happened?

ISO/IEC DIS 27007 is progressing as draft guidance for auditing information security management systems. The standard supports audit practice around ISO/IEC 27001 by helping organisations structure audit programmes, auditor competence, and audit evidence expectations.

Why it matters

ISO 27001 certification depends on an operating internal audit programme, not just a certificate-stage audit. As ISMS audit guidance is refreshed, organisations should check whether their internal audits test real security governance, risk treatment, control operation, and management review evidence.

Practical checks

  • Review whether internal audit plans cover scope, risks, controls, locations, systems, and outsourced processes.
  • Check auditor competence for technical controls, cloud services, supplier risk, and privacy-related controls.
  • Make sure audit findings are linked to corrective actions, owners, deadlines, and management review inputs.
  • Keep audit evidence current between surveillance audits so audit activity is not compressed into one audit week.

Strong internal audits make ISO 27001 more useful. They help management see whether the ISMS is actually working and whether control weaknesses are being corrected before certification or customer audits find them.