Audit and Compliance Management Procedure
Audit plan, security KPIs, statement of applicability and Board reporting
1. Purpose and Scope
This procedure ensures systematic assessment of ISMS effectiveness, compliance with NIS2 requirements, and identification of areas requiring improvement. Audit results are reported to the Board and form the basis for continual improvement.
2. Annual ISMS Audit Plan
Requirement – internal audit minimum once a year (NIS2)
| Audit type | Scope | Frequency | Executor | Deadline |
|---|---|---|---|---|
| Internal ISMS audit | Compliance with DOC-001 to DOC-021, NIS2 requirements | ▸ once a yearmin. 1×/year – NIS2 | ▸ [Internal auditor / external audit firm] | ▸ [e.g. Q4 each year] |
| ISMS management review | Audit results, KPIs, risks, incidents | ▸ once a yearmin. 1×/year – ISO 27001 | ▸ Board + CISO | ▸ [e.g. Q1 after annual report] |
| Supervisory authority audit | Per scope indicated by authority | On authority request | ▸ Supervisory authority | On request |
| GDPR compliance review | Record of processing activities, breaches | ▸ once a year | ▸ DPO / external advisor | ▸ |
3. Security KPIs
The organisation measures and reports to the Board the following security performance indicators:
| KPI | Description | Target | Measurement frequency |
|---|---|---|---|
| Number of P1/P2 incidents | Serious and high-severity cybersecurity incidents | ▸ Decreasing trendyear on year | Monthly |
| MTTR (Mean Time To Respond) | Average response time for P1 incidents | ▸ [< 2h]per DOC-005 | After each incident |
| Critical patch compliance rate | % critical vulnerabilities patched within SLA (72h) | ▸ [100%]min. 95% | Monthly |
| MFA coverage – privileged accounts | % admin accounts with active MFA | ▸ 100% | Monthly |
| Phishing simulation result (click rate) | % employees clicking phishing link | ▸ [< 5%]target <10% | After each campaign |
| Board training coverage | % Board members who completed training this year | ▸ 100% | Annually |
| Employee training coverage | % employees with current training | ▸ [> 95%]min. 90% | Quarterly |
| Backup recovery time (DRP test) | Whether critical system recovery meets RTO | ▸ RTO met (per DOC-011) | After each DRP test |
| Number of open critical risks (R≥17) | Risks without treatment plan | ▸ 0 | Monthly |
| Key systems uptime | Availability of key services (SLA) | ▸ [> 99.5%]per NIS2/sector requirements | Monthly |
4. Security Report for the Board
CISO prepares regular Security Reports for the Board:
Requirement – Board reporting minimum once a year (quarterly recommended)
| Frequency | Report content | Recipients |
|---|---|---|
| ▸ [quarterly]min. 1×/year | KPIs, incident count, open risk status, ISMS implementation progress, threat landscape changes | ▸ Board / CEO |
| Annually | Full ISMS review, audit results, plan for next year, security budget | ▸ Board + Supervisory Board (if applicable) |
5. Statement of Applicability (SoA)
The organisation maintains a Statement of Applicability confirming which security controls are implemented, to what extent, and the justification for any exclusions.
⚠ Critical – SoA required for ISO 27001-certified organisations and recommended for NIS2
| Control area (ISO 27001:2022 / NIS2) | Implementation status | Document | Exclusion justification (if N/A) |
|---|---|---|---|
| Information security policy (A.5.1) | ▸ [Implemented / Planned / N/A] | DOC-001 | ▸ |
| Risk management (A.5.3) | ▸ | DOC-002, DOC-003 | ▸ |
| Incident management (A.5.24–26) | ▸ | DOC-005, DOC-006, DOC-007 | ▸ |
| Access control (A.5.15–18, A.8.2–5) | ▸ | DOC-008 | ▸ |
| Cryptography (A.8.24) | ▸ | DOC-009 | ▸ |
| Information classification (A.5.9–14) | ▸ | DOC-010 | ▸ |
| Business continuity (A.5.29–30) | ▸ | DOC-011, DOC-012 | ▸ |
| Supply chain security (A.5.19–23) | ▸ | DOC-015 | ▸ |
| HR security (A.6.1–5) | ▸ | DOC-016, DOC-017 | ▸ |
| Physical security (A.7.1–14) | ▸ | DOC-018 | ▸ |
| Network security (A.8.20–23) | ▸ | DOC-019 | ▸ |
| Change and vulnerability management (A.8.8, 8.32) | ▸ | DOC-013, DOC-014 | ▸ |
6. Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ | ▸ | ▸ Initial release | ▸ Board |
DOC-021 Audit and Compliance Procedure | v1.0 | NIS2/ISMS