1.ISO 27001 Internal Audit Checklist คืออะไร
ISO 27001 Internal Audit Checklist is a list of issues auditors use to assess the ISMS. Additionally, it helps determine if the organization complies with ISO/IEC 27001:2022 and its defined processes.
A good ISO 27001 Internal Audit Checklist should not simply ask whether the organization has a policy or a backup. Instead, it helps the Auditor verify that what is documented is implemented, supported by evidence, and that controls work effectively.
การตรวจ Internal Audit ISO 27001:2022 โดยทั่วไปจึงควรครอบคลุมทั้ง Clause 4–10 และ Annex A Controls ที่เกี่ยวข้องกับองค์กรตาม Statement of Applicability หรือ SoA
2.Checklist ISO 27001 Clause 4–10 ต้องตรวจอะไรบ้าง
Clause 4: Context of the Organization
Auditor ควรตรวจว่าองค์กรเข้าใจบริบทและกำหนดขอบเขตของ ISMS เหมาะสมกับการดำเนินงานจริงหรือไม่
ประเด็นสำคัญ เช่น
- Internal และ External Issues
- Interested Parties
- กฎหมายและข้อกำหนดที่เกี่ยวข้อง
- ISMS Scope
- กระบวนการ ระบบ และสถานที่ที่อยู่ในขอบเขต
Evidence Example: ISMS Scope, Context Analysis, Interested Parties Register และ Organization Chart
จุดที่ควรระวังคือ Scope ที่ระบุไว้ในเอกสารต้องตรงกับระบบและบริการที่องค์กรใช้งานจริง
Clause 5: Leadership
Clause 5 เน้นบทบาทของผู้บริหารและผู้รับผิดชอบ ISMS
Auditor อาจตรวจว่า
- Information Security Policy ได้รับอนุมัติหรือไม่
- มีการกำหนด Roles and Responsibilities หรือไม่
- ผู้บริหารมีส่วนร่วมในการบริหาร ISMS หรือไม่
- Policy ถูกสื่อสารให้พนักงานรับทราบหรือไม่
- ผู้ที่ได้รับมอบหมายเข้าใจหน้าที่ของตนเองหรือไม่
Evidence Example: Policy, Appointment Letter, Job Description และ Management Meeting Record
การมีรายชื่อคณะทำงานอย่างเดียวไม่เพียงพอ หากผู้ที่ได้รับแต่งตั้งไม่ทราบบทบาทของตนเอง
Clause 6: Planning
Clause 6 เป็นส่วนสำคัญของ ISO 27001 เพราะเกี่ยวข้องกับ Information Security Risk Management โดยตรง
ประเด็นที่ควรตรวจ ได้แก่
- Risk Assessment Methodology
- Risk Criteria
- Risk Register
- Risk Owner
- Risk Treatment Plan
- Statement of Applicability
- Information Security Objectives
Auditor ควรตรวจว่าข้อมูลเหล่านี้เชื่อมโยงกัน เช่น
Risk → Treatment → Control → SoA → Evidence
หาก Risk Register ระบุความเสี่ยงอย่างหนึ่ง แต่ Control ที่เลือกใช้ไม่สัมพันธ์กับความเสี่ยงนั้น อาจเป็นสัญญาณว่ากระบวนการ Risk Management ยังไม่ทำงานอย่างมีประสิทธิผล
Clause 7: Support
Clause 7 ครอบคลุมทรัพยากร personnel ความสามารถ การสร้าง Awareness และ Documented Information
Checklist ควรครอบคลุม เช่น
- Competency ของบุคลากร
- Security Awareness
- Training
- Communication
- Document Control
- Record Control
Evidence Example: Training Record, Competency Matrix, Document Master List และ Approval Record
Auditor ควรตรวจด้วยว่าพนักงานใหม่หรือบุคลากรในตำแหน่งสำคัญได้รับการอบรมตามที่กำหนดจริงหรือไม่
Clause 8: Operation
Clause 8 ใช้ตรวจว่าสิ่งที่องค์กรวางแผนไว้ถูกนำไปดำเนินการจริงหรือไม่
ตัวอย่างประเด็นตรวจ ได้แก่
- การทำ Risk Assessment ตามรอบ
- การติดตาม Risk Treatment Plan
- การติดตาม Action Plan
- Change Management
- Supplier หรือ Outsourced Process
- การนำ Security Controls ไปใช้งานจริง
ในส่วนนี้ Auditor อาจต้องตรวจ Evidence จากระบบจริง เช่น Firewall, Active Directory, Microsoft 365, Server, Endpoint หรือ Backup System
Clause 9: Performance Evaluation
องค์กรต้องสามารถแสดงได้ว่า ISMS ถูกติดตามและประเมินผลอย่างต่อเนื่อง
Auditor ควรตรวจ เช่น
- Monitoring และ Measurement
- Security KPI
- Internal Audit Programme
- Internal Audit Findings
- Management Review
Evidence Example: KPI Report, Audit Plan, Internal Audit Report และ Management Review Minutes
คำถามสำคัญคือ องค์กรทราบได้อย่างไรว่า Security Control ที่นำมาใช้ยังทำงานได้ดีและยังเหมาะสมกับความเสี่ยงในปัจจุบัน
Clause 10: Improvement
เมื่อพบ Nonconformity หรือปัญหา องค์กรควรแก้ไขทั้งเหตุการณ์และสาเหตุที่ทำให้ปัญหาเกิดขึ้น
Checklist อาจครอบคลุม
- Nonconformity
- Root Cause Analysis
- Corrective Action
- Action Owner
- Due Date
- Evidence หลังดำเนินการ
- Effectiveness Verification
ตัวอย่างเช่น หากพบว่า User Account ของพนักงานที่ลาออกแล้วยัง Active การ Disable Account เป็นเพียงการแก้ปัญหาเฉพาะหน้า
Auditor ควรตรวจต่อว่าเหตุใด Offboarding Process จึงไม่สามารถยกเลิกสิทธิ์ได้ตามกำหนด และองค์กรมีมาตรการป้องกันไม่ให้เกิดซ้ำหรือไม่
3.Checklist Annex A ISO 27001:2022
Annex A ของ ISO/IEC 27001:2022 ประกอบด้วย Controls จำนวน 93 Controls แบ่งออกเป็น 4 กลุ่มหลัก
1. Organizational Controls
เป็น Controls ที่เกี่ยวข้องกับการบริหารจัดการ Information Security ในระดับองค์กร เช่น
- Information Security Policies
- Asset Management
- Access Control
- Supplier Security
- Incident Management
- Business Continuity
- Compliance
- Cloud Services
Auditor ควรตรวจทั้ง Policy, Process และ Record ที่แสดงว่ามีการปฏิบัติจริง
2. People Controls
เกี่ยวข้องกับบุคลากรตั้งแต่ก่อนเข้าทำงาน ระหว่างทำงาน จนถึงพ้นสภาพพนักงาน เช่น
- Screening
- Employment Terms
- Security Awareness
- Confidentiality
- Remote Working
- Disciplinary Process
- Offboarding
Evidence อาจประกอบด้วย Employment Contract, NDA, Training Record และ Offboarding Checklist
3. Physical Controls
เป็น Controls ที่ใช้ป้องกันการเข้าถึงสถานที่ อุปกรณ์ และพื้นที่สำคัญโดยไม่ได้รับอนุญาต เช่น
- Physical Security Perimeter
- Access Card
- Visitor Management
- CCTV
- Secure Area
- Equipment Protection
- Clear Desk / Clear Screen
- Cabling Security
Auditor อาจตรวจทั้งเอกสารและการเดินตรวจพื้นที่จริง
4. Technological Controls
เป็น Controls ที่เกี่ยวข้องกับระบบ IT และ Cybersecurity โดยตรง เช่น
- Endpoint Security
- Privileged Access
- Secure Authentication
- Vulnerability Management
- Backup
- Logging and Monitoring
- Network Security
- Cryptography
- Secure Development
- Change Management
หัวข้อเหล่านี้ไม่ควรตรวจเพียง Procedure แต่ควรดู System Configuration, Log หรือ Evidence จากระบบจริงด้วย
4.Example Checklist ตรวจ Access Control
Access Control เป็นหัวข้อที่ Auditor มักใช้ Sampling เพื่อทดสอบการทำงานจริง
ข้อมูลที่อาจขอตรวจ เช่น
- รายชื่อพนักงาน
- Active User List
- Resigned Employee List
- Privileged Account
- Access Request
- Approval Record
- Access Review
- MFA
- Shared Account
Auditor อาจตรวจตั้งแต่
Request → Approval → Provisioning → Review → Revocation
Example Finding ที่พบได้ เช่น พนักงานลาออกแล้วแต่ Account ยัง Active หรือ User มีสิทธิ์มากเกินความจำเป็น
Example Checklist ตรวจ Backup
Auditor ไม่ควรถามเพียงว่า “องค์กรมี Backup หรือไม่”
ควรตรวจต่อ เช่น
- Backup อะไรบ้าง
- Backup Frequency เท่าไร
- Backup Job สำเร็จหรือไม่
- Failed Job มีการติดตามหรือไม่
- Backup ถูกเก็บไว้ที่ใด
- ใครเข้าถึงได้
- มี Restore Test หรือไม่
- Restore Test ล่าสุดเมื่อใด
Evidence Example: Backup Configuration, Backup Log และ Restore Test Report
เพราะการ Backup สำเร็จไม่ได้หมายความว่าองค์กรจะสามารถกู้คืนข้อมูลได้จริงเมื่อเกิดเหตุ
5.Evidence ที่ควรเตรียมก่อน Internal Audit
องค์กรสามารถเตรียมหลักฐานสำคัญล่วงหน้า เช่น
- ISMS Scope
- Risk Register
- Risk Treatment Plan
- Statement of Applicability
- Asset Register
- Policy และ Procedure
- Training Records
- Access List
- Access Review
- Vulnerability Report
- Backup Report
- Incident Record
- Supplier Assessment
- Internal Audit Report
- Management Review Record
การเตรียม Evidence ล่วงหน้าช่วยให้การตรวจดำเนินไปได้รวดเร็ว และทำให้ Auditor ใช้เวลาไปกับการทดสอบ Control มากกว่าการค้นหาเอกสาร
6.Internal Audit Checklist ไม่ควรมีแค่ Yes หรือ No
ข้อผิดพลาดที่พบบ่อยคือการใช้ Checklist แบบ
มี Firewall — Yes
มี Backup — Yes
มี Antivirus — Yes
แล้วสรุปว่าผ่าน
ในทางปฏิบัติ Auditor ควรพิจารณาว่า Control นั้น
ถูกออกแบบ → ถูกนำไปใช้ → ทำงานอย่างต่อเนื่อง → มีประสิทธิผล
ตัวอย่างเช่น องค์กรอาจมี Backup System แต่ไม่เคยทำ Restore Test ซึ่งยังไม่สามารถยืนยันได้ว่ากระบวนการกู้คืนข้อมูลจะทำงานได้เมื่อเกิดเหตุจริง
7.Checklist ที่ใช้จริงควรมีอะไรบ้าง
Checklist สำหรับ Internal Audit ควรประกอบด้วยข้อมูลอย่างน้อยดังนี้
| รายการ | ใช้สำหรับ |
| Clause / Control | ระบุข้อกำหนด |
| Audit Question | คำถามที่ใช้ตรวจ |
| Expected Evidence | Evidence ที่ควรพบ |
| Actual Evidence | Evidence ที่ตรวจพบจริง |
| Sampling | ตัวอย่างที่เลือกตรวจ |
| Result | ผลการตรวจ |
| Finding | ประเด็นที่พบ |
| Auditor Note | บันทึกเพิ่มเติม |
ผลการตรวจอาจแบ่งเป็น Conform, Nonconformity, Observation, OFI หรือ Not Checked ตามหลักเกณฑ์ที่องค์กรกำหนด
8.สรุป
ISO 27001 Internal Audit Checklist ที่ดีควรครอบคลุมทั้ง Clause 4–10 และ Annex A Controls ที่เกี่ยวข้องกับขอบเขตและความเสี่ยงขององค์กร
แต่เป้าหมายไม่ใช่เพียงการทำ Checklist ให้ครบทุกข้อ
Auditor ควรสามารถตรวจให้เห็นความเชื่อมโยงระหว่าง
Requirement → Risk → Control → Evidence → Finding → Corrective Action
เพื่อยืนยันว่า ISMS ไม่ได้มีเพียงเอกสาร แต่ถูกนำไปใช้งานจริงและสามารถบริหารความเสี่ยงด้าน Information Security ได้อย่างเหมาะสม
สำหรับองค์กรที่กำลังเตรียม Certification Audit, Surveillance Audit หรือ Recertification Audit การทำ Internal Audit ที่ลงไปถึง Evidence และ Sampling ระบบจริง จะช่วยค้นพบช่องว่างและมีเวลาแก้ไขก่อนเข้าสู่การตรวจรับรอง
ต้องการตรวจ Internal Audit ISO/IEC 27001:2022?
DataFlow Consult ให้บริการ ISO 27001 Internal Audit และ IT Audit ครอบคลุม Clause 4–10, Risk Management, Statement of Applicability, Annex A Controls และ Technical Evidence พร้อมสรุป Findings และข้อเสนอแนะก่อนการตรวจรับรอง
Email: contact@dataflowconsult.com
โทร: 063-4563698
