1.Internal Audit ISO 27001 คืออะไร
Internal Audit ISO 27001 คือการตรวจประเมินภายในระบบบริหารจัดการความมั่นคงปลอดภัยสารสนเทศ
หรือ ISMS เพื่อประเมินว่าองค์กรดำเนินงานสอดคล้องกับข้อกำหนดของ
ISO/IEC 27001:2022 และกระบวนการที่องค์กรกำหนดไว้หรือไม่
การตรวจที่ดีไม่ควรดูเพียงว่าองค์กรมีเอกสารครบหรือไม่
แต่ต้องตรวจด้วยว่า Policy, Procedure และ Control
ต่าง ๆ ถูกนำไปใช้งานจริง มีหลักฐานรองรับ
และสามารถช่วยควบคุมความเสี่ยงด้าน Information Security ได้อย่างมีประสิทธิผล
ตัวอย่างเช่น องค์กรอาจมี Procedure
กำหนดให้ปิด User Account ทันทีเมื่อพนักงานลาออก
แต่เมื่อ Auditor ตรวจระบบจริงกลับพบว่า Account ของอดีตพนักงานยัง Active อยู่
กรณีนี้ถือเป็นช่องว่างระหว่างสิ่งที่องค์กรกำหนดไว้กับการปฏิบัติงานจริง
2.Internal Audit ISO 27001:2022 ต้องตรวจอะไรบ้าง
โดยทั่วไป การทำ Internal
Audit ควรครอบคลุมข้อกำหนดของระบบ ISMS ใน Clause
4–10 รวมถึง Annex A Controls ที่องค์กรเลือกใช้ตาม
Statement of Applicability หรือ SoA
Clause 4: Context of the Organization
Auditor ควรตรวจว่าองค์กรกำหนดบริบท
ขอบเขต และผู้มีส่วนได้ส่วนเสียของระบบ ISMS ได้เหมาะสมหรือไม่
เช่น
- Internal
และ External Issues
- Interested
Parties
- กฎหมายและข้อกำหนดที่เกี่ยวข้อง
- ISMS
Scope
- Business
Process และระบบที่อยู่ในขอบเขต
ตัวอย่าง Evidence ได้แก่ ISMS Scope, Context Analysis, Interested Parties Register
และ Organization Chart
Clause 5: Leadership
ส่วนนี้เป็นการตรวจบทบาทของผู้บริหารและผู้รับผิดชอบ
ISMS เช่น
- Information
Security Policy
- Roles
and Responsibilities
- Management
Commitment
- การสื่อสารนโยบาย
- การกำหนดผู้รับผิดชอบด้าน Information
Security
Auditor อาจสัมภาษณ์ผู้รับผิดชอบเพื่อดูว่าเข้าใจหน้าที่ของตนเองจริงหรือไม่
ไม่ใช่เพียงมีเอกสารแต่งตั้ง
Clause 6: Planning
Clause 6 เกี่ยวข้องโดยตรงกับ Risk
Management และถือเป็นหัวใจของ ISO 27001
ประเด็นที่ควรตรวจ ได้แก่
- Risk
Assessment Methodology
- Risk
Criteria
- Risk
Register
- Risk
Treatment Plan
- Risk
Owner
- Statement
of Applicability
- Information
Security Objectives
Auditor ควรตรวจความเชื่อมโยงระหว่าง
Risk, Treatment และ Control ว่าสอดคล้องกันจริงหรือไม่
Clause 7: Support
ส่วนนี้ครอบคลุมเรื่องทรัพยากร บุคลากร
ความรู้ และเอกสาร เช่น
- Competency
- Security
Awareness
- Training
- Communication
- Document
Control
- Record
Control
ตัวอย่าง Evidence ได้แก่ Training Record, Competency Matrix, Document Master List และ Approval Record
Clause 8: Operation
Clause 8 เน้นการดำเนินงานจริงของระบบ
ISMS
Auditor อาจตรวจ
- การทำ Risk Assessment ตามรอบ
- การดำเนินการตาม Risk Treatment
Plan
- การควบคุมการเปลี่ยนแปลง
- การควบคุมผู้ให้บริการภายนอก
- การนำ Security Controls ไปใช้งานจริง
ในขั้นตอนนี้อาจต้องตรวจระบบจริง เช่น Firewall,
Active Directory, Microsoft 365, Server, Endpoint, Backup และ Cloud
System
Clause 9: Performance Evaluation
Clause 9 ใช้ประเมินว่า ISMS
มีประสิทธิผลหรือไม่
ประเด็นที่ต้องตรวจ เช่น
- Monitoring
- Measurement
- Security
KPI
- Internal
Audit
- Management
Review
ตัวอย่าง Evidence ได้แก่ Audit Plan, Audit Checklist, Internal Audit Report, KPI
Report และ Management Review Minutes
Clause 10: Improvement
เมื่อพบ Nonconformity หรือปัญหา องค์กรต้องสามารถแสดงได้ว่ามีการแก้ไขที่ต้นเหตุ
Auditor ควรตรวจ
- Nonconformity
- Root
Cause Analysis
- Corrective
Action
- Corrective
Action Plan
- Effectiveness
Verification
- Continual
Improvement
การแก้ปัญหาเฉพาะหน้าอย่างเดียวอาจไม่เพียงพอ
หากองค์กรยังไม่ได้แก้สาเหตุที่ทำให้ปัญหาเกิดขึ้น
3.Annex A Controls ต้องตรวจด้วยหรือไม่
ต้องตรวจ โดยเฉพาะ Control
ที่องค์กรระบุว่า Applicable ใน Statement
of Applicability
Annex A ของ ISO/IEC
27001:2022 แบ่ง Controls ออกเป็น 4 กลุ่ม ได้แก่
- Organizational
Controls
- People
Controls
- Physical
Controls
- Technological
Controls
ตัวอย่างหัวข้อที่ Auditor
มักตรวจ ได้แก่
- Access
Control
- Privileged
Access
- Asset
Management
- Supplier
Security
- Security
Awareness
- Physical
Security
- Backup
- Vulnerability
Management
- Logging
and Monitoring
- Network
Security
- Incident
Management
- Business
Continuity
อย่างไรก็ตาม Auditor
ไม่ควรใช้วิธีถามเพียงว่า “มีหรือไม่มี” แต่ควรตรวจว่ามี Evidence
และ Control ทำงานได้จริงหรือไม่
4.Evidence ที่ Auditor มักขอตรวจมีอะไรบ้าง
Evidence ในการทำ Internal
Audit ISO 27001 ไม่จำเป็นต้องเป็นเอกสารเสมอไป
อาจเป็นข้อมูลจากระบบจริงได้เช่นกัน
ตัวอย่าง ได้แก่
- Policy
- Procedure
- Record
- Screenshot
- System
Configuration
- Log
- Ticket
- Email
Approval
- Access
List
- Risk
Register
- Asset
Register
- Training
Record
- Backup
Log
- Vulnerability
Scan
- Management
Review Minutes
หลักสำคัญคือ Evidence
ต้องสามารถยืนยันได้ว่ากระบวนการนั้นถูกดำเนินการจริง
5.ตัวอย่างการตรวจ User
Access Management
หากตรวจเรื่อง User
Access Auditor ไม่ควรถามเพียงว่าองค์กรมี Access Control
Procedure หรือไม่
ควรตรวจต่อ เช่น
- รายชื่อพนักงานเข้าใหม่
- รายชื่อพนักงานลาออก
- Active
User ในระบบ
- Privileged
Account
- User
Approval
- Access
Review
- MFA
- Shared
Account
- Service
Account
จากนั้นเลือก Sample
เพื่อตรวจให้ครบวงจรตั้งแต่
Request → Approval → Provisioning → Review →
Revocation
วิธีนี้ช่วยให้ Auditor
ประเมินได้ว่า Control ทำงานจริง
ไม่ใช่เพียงมีเอกสารรองรับ
6.Internal Audit ต่างจาก Certification
Audit อย่างไร
Internal Audit เป็นการตรวจภายในที่องค์กรใช้ค้นหาช่องว่างและปรับปรุงระบบก่อนเข้าสู่การตรวจจาก
Certification Body
ส่วน Certification Audit เป็นการตรวจจากหน่วยงานรับรองภายนอก
เพื่อพิจารณาว่าองค์กรมีระบบที่สอดคล้องกับมาตรฐาน ISO/IEC 27001 หรือไม่
ดังนั้น Internal Audit ที่ดีควรช่วยให้องค์กรพบปัญหาก่อนที่ External Auditor จะเป็นผู้พบ
7.ควรทำ Internal
Audit เมื่อใด
องค์กรควรวาง Audit
Programme ให้เหมาะกับความเสี่ยง ความสำคัญของกระบวนการ
ผลจากการตรวจครั้งก่อน และการเปลี่ยนแปลงของระบบ
โดยเฉพาะก่อน Certification
Audit, Surveillance Audit หรือ Recertification Audit ควรเผื่อเวลาสำหรับ
Internal Audit → Finding → Root Cause →
Corrective Action → Evidence → Verification
ไม่ควรทำ Internal Audit ใกล้วันตรวจเกินไป เพราะหากพบ Nonconformity องค์กรอาจไม่มีเวลาแก้ไขอย่างเพียงพอ
8.สรุป
Internal Audit ISO 27001:2022 ไม่ใช่เพียงการตรวจเอกสาร
แต่เป็นการตรวจว่า ISMS ขององค์กรถูกนำไปใช้จริง มี Evidence
รองรับ และสามารถควบคุมความเสี่ยงด้าน Information Security ได้อย่างมีประสิทธิผล
การตรวจที่เหมาะสมควรครอบคลุม
- Clause
4–10
- Risk
Assessment
- Risk
Treatment
- Statement
of Applicability
- Annex
A Controls
- Policies
and Procedures
- Technical
Controls
- Audit
Evidence
- Findings
- Corrective
Actions
- Effectiveness
Verification
องค์กรที่เตรียมเข้าสู่ Certification
หรือ Surveillance Audit ควรใช้ Internal
Audit เป็นเครื่องมือในการค้นหาช่องว่างและปรับปรุงระบบก่อนการตรวจจริง
เอาเนื้อหามาสร้างรูปประกอบบทความ
