Training module
Auditing Information Security Controls
Evaluate control applicability, implementation evidence and common failure patterns across ISO/IEC 27001 Annex A control themes
Does your audit move beyond control-checklist auditing to traceable assurance about how security actually operates?
Annex A audits fail when controls are treated as static statements rather than working mechanisms with clear applicability, ownership, and evidence. This module equips auditors to challenge the Statement of Applicability, follow high-leverage audit trails, and recognise systemic ISMS weaknesses.
Overview
What this module is about
Many organisations can describe their Annex A controls but struggle to demonstrate why each control applies, how it is implemented, and whether it consistently operates across sites, teams, and suppliers. The result is an audit pattern of “policy evidence” without operational proof, and repeated findings that are symptoms of deeper system weaknesses.
This standard-specific auditing module focuses on Annex A control applicability and rationale (via the Statement of Applicability), evidence expectations by control theme, and typical systemic ISMS failures. It assumes information security fundamentals are already covered elsewhere and does not re-teach generic audit craft; it applies audit judgement to ISO/IEC 27001’s control set for internal auditors and third-party auditors (e.g., certification bodies or independent assurance providers).
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
aim to audit whether Annex A controls operate in practice, not just on paper.
want to test control applicability and rationale via the Statement of Applicability.
follow control claims end-to-end across policy, process, configuration, and records.
strengthen evidence-based judgement across different control themes.
seek audit findings that highlight systemic weaknesses, not checklist gaps.
It may not be the best fit if you…
primarily want to design, implement, or improve security controls.
expect control theory or technical implementation guidance.
prefer audits limited to documentation or policy consistency checks.
avoid challenging formally correct but weak control claims.
Agenda
What is taught
7 parts01Annex A in an audit context
Clarifies how Annex A controls are used to test assurance and operation, not as a checklist for document presence.
02Control applicability and rationale
Tests the credibility of SoA inclusion, exclusion, and tailoring decisions, and how weak rationales surface as evidence gaps.
03Evidence expectations by control theme (ISO/IEC 27001:2022)
Covers organisational controls (governance, ownership, routines), people controls (competence, JML, behavioural enforcement), and technological controls (configuration, access, logging, change), with focus on high-leverage audit signals.
04Physical controls in real environments
Assesses site realities, shared spaces, visitor handling, and asset movement, including where physical and technical controls interact or fail.
05Tracing one control end-to-end
Follows a single control claim through policy, process, configuration, and records, including interfaces with IT, HR, Facilities, suppliers, and shared platforms.
06Paper control sets and drift patterns
Identifies declared controls without operational ownership, fragmented implementation across sites or tools, and risk-treatment drift where SoA and reality diverge over time.
07Case-based audit simulation
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Challenge Annex A control applicability decisions using consistent tests for rationale quality and scope fit
02
Distinguish control statement, implementation, and operation evidence, and identify which is missing
03
Identify expected evidence types by Annex A control theme
Build practical, traceable audit trails from control intent to operational proof across functions and suppliers
Recognise recurring systemic ISMS failure patterns behind repeated control weaknesses
Apply Annex A auditing judgement in both internal audits and third-party assurance contexts without reverting to checklist auditing
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Auditing Information Security Controls is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-IS-A-02
- Discipline
- Information Security
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.