DOC-021 ← Document Portal

Audit and Compliance Management Procedure

Audit plan, security KPIs, statement of applicability and Board reporting
Document Number
DOC-021
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO / Internal Auditor
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2)(f) NIS2; ISO/IEC 27001:2022 cl. 9.1, 9.2; GDPR Art. 32
Related Documents
All ISMS documents (DOC-001 – DOC-020)

1. Purpose and Scope

This procedure ensures systematic assessment of ISMS effectiveness, compliance with NIS2 requirements, and identification of areas requiring improvement. Audit results are reported to the Board and form the basis for continual improvement.

2. Annual ISMS Audit Plan

Requirement – internal audit minimum once a year (NIS2)
Audit typeScopeFrequencyExecutorDeadline
Internal ISMS audit Compliance with DOC-001 to DOC-021, NIS2 requirements ▸ once a yearmin. 1×/year – NIS2 ▸ [Internal auditor / external audit firm] ▸ [e.g. Q4 each year]
ISMS management review Audit results, KPIs, risks, incidents ▸ once a yearmin. 1×/year – ISO 27001 ▸ Board + CISO ▸ [e.g. Q1 after annual report]
Supervisory authority audit Per scope indicated by authority On authority request ▸ Supervisory authority On request
GDPR compliance review Record of processing activities, breaches ▸ once a year ▸ DPO / external advisor

3. Security KPIs

The organisation measures and reports to the Board the following security performance indicators:

KPIDescriptionTargetMeasurement frequency
Number of P1/P2 incidents Serious and high-severity cybersecurity incidents ▸ Decreasing trendyear on year Monthly
MTTR (Mean Time To Respond) Average response time for P1 incidents ▸ [< 2h]per DOC-005 After each incident
Critical patch compliance rate % critical vulnerabilities patched within SLA (72h) ▸ [100%]min. 95% Monthly
MFA coverage – privileged accounts % admin accounts with active MFA ▸ 100% Monthly
Phishing simulation result (click rate) % employees clicking phishing link ▸ [< 5%]target <10% After each campaign
Board training coverage % Board members who completed training this year ▸ 100% Annually
Employee training coverage % employees with current training ▸ [> 95%]min. 90% Quarterly
Backup recovery time (DRP test) Whether critical system recovery meets RTO ▸ RTO met (per DOC-011) After each DRP test
Number of open critical risks (R≥17) Risks without treatment plan ▸ 0 Monthly
Key systems uptime Availability of key services (SLA) ▸ [> 99.5%]per NIS2/sector requirements Monthly

4. Security Report for the Board

CISO prepares regular Security Reports for the Board:

Requirement – Board reporting minimum once a year (quarterly recommended)
FrequencyReport contentRecipients
▸ [quarterly]min. 1×/year KPIs, incident count, open risk status, ISMS implementation progress, threat landscape changes ▸ Board / CEO
Annually Full ISMS review, audit results, plan for next year, security budget ▸ Board + Supervisory Board (if applicable)

5. Statement of Applicability (SoA)

The organisation maintains a Statement of Applicability confirming which security controls are implemented, to what extent, and the justification for any exclusions.

⚠ Critical – SoA required for ISO 27001-certified organisations and recommended for NIS2
Control area (ISO 27001:2022 / NIS2)Implementation statusDocumentExclusion justification (if N/A)
Information security policy (A.5.1)▸ [Implemented / Planned / N/A]DOC-001
Risk management (A.5.3)DOC-002, DOC-003
Incident management (A.5.24–26)DOC-005, DOC-006, DOC-007
Access control (A.5.15–18, A.8.2–5)DOC-008
Cryptography (A.8.24)DOC-009
Information classification (A.5.9–14)DOC-010
Business continuity (A.5.29–30)DOC-011, DOC-012
Supply chain security (A.5.19–23)DOC-015
HR security (A.6.1–5)DOC-016, DOC-017
Physical security (A.7.1–14)DOC-018
Network security (A.8.20–23)DOC-019
Change and vulnerability management (A.8.8, 8.32)DOC-013, DOC-014

6. Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-021 Audit and Compliance Procedure | v1.0 | NIS2/ISMS