Donmueang, Bangkok, 10210
063-4563698
contact@dataflowconsult.com
ขอใบเสนอราคา
The Ultimate Guide to ISO 27001 Internal Audit Checklist
Home » IT Audit  »  The Ultimate Guide to ISO 27001 Internal Audit Checklist

1.ISO 27001 Internal Audit Checklist คืออะไร

ISO 27001 Internal Audit Checklist is a list of issues auditors use to assess the ISMS. Additionally, it helps determine if the organization complies with ISO/IEC 27001:2022 and its defined processes.

A good ISO 27001 Internal Audit Checklist should not simply ask whether the organization has a policy or a backup. Instead, it helps the Auditor verify that what is documented is implemented, supported by evidence, and that controls work effectively.

การตรวจ Internal Audit ISO 27001:2022 โดยทั่วไปจึงควรครอบคลุมทั้ง Clause 4–10 และ Annex A Controls ที่เกี่ยวข้องกับองค์กรตาม Statement of Applicability หรือ SoA

2.Checklist ISO 27001 Clause 4–10 ต้องตรวจอะไรบ้าง

Clause 4: Context of the Organization

Auditor ควรตรวจว่าองค์กรเข้าใจบริบทและกำหนดขอบเขตของ ISMS เหมาะสมกับการดำเนินงานจริงหรือไม่

ประเด็นสำคัญ เช่น

  • Internal และ External Issues
  • Interested Parties
  • กฎหมายและข้อกำหนดที่เกี่ยวข้อง
  • ISMS Scope
  • กระบวนการ ระบบ และสถานที่ที่อยู่ในขอบเขต

Evidence Example: ISMS Scope, Context Analysis, Interested Parties Register และ Organization Chart

จุดที่ควรระวังคือ Scope ที่ระบุไว้ในเอกสารต้องตรงกับระบบและบริการที่องค์กรใช้งานจริง

Clause 5: Leadership

Clause 5 เน้นบทบาทของผู้บริหารและผู้รับผิดชอบ ISMS

Auditor อาจตรวจว่า

  • Information Security Policy ได้รับอนุมัติหรือไม่
  • มีการกำหนด Roles and Responsibilities หรือไม่
  • ผู้บริหารมีส่วนร่วมในการบริหาร ISMS หรือไม่
  • Policy ถูกสื่อสารให้พนักงานรับทราบหรือไม่
  • ผู้ที่ได้รับมอบหมายเข้าใจหน้าที่ของตนเองหรือไม่

Evidence Example: Policy, Appointment Letter, Job Description และ Management Meeting Record

การมีรายชื่อคณะทำงานอย่างเดียวไม่เพียงพอ หากผู้ที่ได้รับแต่งตั้งไม่ทราบบทบาทของตนเอง

Clause 6: Planning

Clause 6 เป็นส่วนสำคัญของ ISO 27001 เพราะเกี่ยวข้องกับ Information Security Risk Management โดยตรง

ประเด็นที่ควรตรวจ ได้แก่

  • Risk Assessment Methodology
  • Risk Criteria
  • Risk Register
  • Risk Owner
  • Risk Treatment Plan
  • Statement of Applicability
  • Information Security Objectives

Auditor ควรตรวจว่าข้อมูลเหล่านี้เชื่อมโยงกัน เช่น

Risk → Treatment → Control → SoA → Evidence

หาก Risk Register ระบุความเสี่ยงอย่างหนึ่ง แต่ Control ที่เลือกใช้ไม่สัมพันธ์กับความเสี่ยงนั้น อาจเป็นสัญญาณว่ากระบวนการ Risk Management ยังไม่ทำงานอย่างมีประสิทธิผล

Clause 7: Support

Clause 7 ครอบคลุมทรัพยากร personnel ความสามารถ การสร้าง Awareness และ Documented Information

Checklist ควรครอบคลุม เช่น

  • Competency ของบุคลากร
  • Security Awareness
  • Training
  • Communication
  • Document Control
  • Record Control

Evidence Example: Training Record, Competency Matrix, Document Master List และ Approval Record

Auditor ควรตรวจด้วยว่าพนักงานใหม่หรือบุคลากรในตำแหน่งสำคัญได้รับการอบรมตามที่กำหนดจริงหรือไม่

Clause 8: Operation

Clause 8 ใช้ตรวจว่าสิ่งที่องค์กรวางแผนไว้ถูกนำไปดำเนินการจริงหรือไม่

ตัวอย่างประเด็นตรวจ ได้แก่

  • การทำ Risk Assessment ตามรอบ
  • การติดตาม Risk Treatment Plan
  • การติดตาม Action Plan
  • Change Management
  • Supplier หรือ Outsourced Process
  • การนำ Security Controls ไปใช้งานจริง

ในส่วนนี้ Auditor อาจต้องตรวจ Evidence จากระบบจริง เช่น Firewall, Active Directory, Microsoft 365, Server, Endpoint หรือ Backup System

Clause 9: Performance Evaluation

องค์กรต้องสามารถแสดงได้ว่า ISMS ถูกติดตามและประเมินผลอย่างต่อเนื่อง

Auditor ควรตรวจ เช่น

  • Monitoring และ Measurement
  • Security KPI
  • Internal Audit Programme
  • Internal Audit Findings
  • Management Review

Evidence Example: KPI Report, Audit Plan, Internal Audit Report และ Management Review Minutes

คำถามสำคัญคือ องค์กรทราบได้อย่างไรว่า Security Control ที่นำมาใช้ยังทำงานได้ดีและยังเหมาะสมกับความเสี่ยงในปัจจุบัน

Clause 10: Improvement

เมื่อพบ Nonconformity หรือปัญหา องค์กรควรแก้ไขทั้งเหตุการณ์และสาเหตุที่ทำให้ปัญหาเกิดขึ้น

Checklist อาจครอบคลุม

  • Nonconformity
  • Root Cause Analysis
  • Corrective Action
  • Action Owner
  • Due Date
  • Evidence หลังดำเนินการ
  • Effectiveness Verification

ตัวอย่างเช่น หากพบว่า User Account ของพนักงานที่ลาออกแล้วยัง Active การ Disable Account เป็นเพียงการแก้ปัญหาเฉพาะหน้า

Auditor ควรตรวจต่อว่าเหตุใด Offboarding Process จึงไม่สามารถยกเลิกสิทธิ์ได้ตามกำหนด และองค์กรมีมาตรการป้องกันไม่ให้เกิดซ้ำหรือไม่


3.Checklist Annex A ISO 27001:2022

Annex A ของ ISO/IEC 27001:2022 ประกอบด้วย Controls จำนวน 93 Controls แบ่งออกเป็น 4 กลุ่มหลัก

1. Organizational Controls

เป็น Controls ที่เกี่ยวข้องกับการบริหารจัดการ Information Security ในระดับองค์กร เช่น

  • Information Security Policies
  • Asset Management
  • Access Control
  • Supplier Security
  • Incident Management
  • Business Continuity
  • Compliance
  • Cloud Services

Auditor ควรตรวจทั้ง Policy, Process และ Record ที่แสดงว่ามีการปฏิบัติจริง

2. People Controls

เกี่ยวข้องกับบุคลากรตั้งแต่ก่อนเข้าทำงาน ระหว่างทำงาน จนถึงพ้นสภาพพนักงาน เช่น

  • Screening
  • Employment Terms
  • Security Awareness
  • Confidentiality
  • Remote Working
  • Disciplinary Process
  • Offboarding

Evidence อาจประกอบด้วย Employment Contract, NDA, Training Record และ Offboarding Checklist

3. Physical Controls

เป็น Controls ที่ใช้ป้องกันการเข้าถึงสถานที่ อุปกรณ์ และพื้นที่สำคัญโดยไม่ได้รับอนุญาต เช่น

  • Physical Security Perimeter
  • Access Card
  • Visitor Management
  • CCTV
  • Secure Area
  • Equipment Protection
  • Clear Desk / Clear Screen
  • Cabling Security

Auditor อาจตรวจทั้งเอกสารและการเดินตรวจพื้นที่จริง

4. Technological Controls

เป็น Controls ที่เกี่ยวข้องกับระบบ IT และ Cybersecurity โดยตรง เช่น

  • Endpoint Security
  • Privileged Access
  • Secure Authentication
  • Vulnerability Management
  • Backup
  • Logging and Monitoring
  • Network Security
  • Cryptography
  • Secure Development
  • Change Management

หัวข้อเหล่านี้ไม่ควรตรวจเพียง Procedure แต่ควรดู System Configuration, Log หรือ Evidence จากระบบจริงด้วย

4.Example Checklist ตรวจ Access Control

Access Control เป็นหัวข้อที่ Auditor มักใช้ Sampling เพื่อทดสอบการทำงานจริง

ข้อมูลที่อาจขอตรวจ เช่น

  • รายชื่อพนักงาน
  • Active User List
  • Resigned Employee List
  • Privileged Account
  • Access Request
  • Approval Record
  • Access Review
  • MFA
  • Shared Account

Auditor อาจตรวจตั้งแต่

Request → Approval → Provisioning → Review → Revocation

Example Finding ที่พบได้ เช่น พนักงานลาออกแล้วแต่ Account ยัง Active หรือ User มีสิทธิ์มากเกินความจำเป็น

Example Checklist ตรวจ Backup

Auditor ไม่ควรถามเพียงว่า “องค์กรมี Backup หรือไม่”

ควรตรวจต่อ เช่น

  • Backup อะไรบ้าง
  • Backup Frequency เท่าไร
  • Backup Job สำเร็จหรือไม่
  • Failed Job มีการติดตามหรือไม่
  • Backup ถูกเก็บไว้ที่ใด
  • ใครเข้าถึงได้
  • มี Restore Test หรือไม่
  • Restore Test ล่าสุดเมื่อใด

Evidence Example: Backup Configuration, Backup Log และ Restore Test Report

เพราะการ Backup สำเร็จไม่ได้หมายความว่าองค์กรจะสามารถกู้คืนข้อมูลได้จริงเมื่อเกิดเหตุ

5.Evidence ที่ควรเตรียมก่อน Internal Audit

องค์กรสามารถเตรียมหลักฐานสำคัญล่วงหน้า เช่น

  • ISMS Scope
  • Risk Register
  • Risk Treatment Plan
  • Statement of Applicability
  • Asset Register
  • Policy และ Procedure
  • Training Records
  • Access List
  • Access Review
  • Vulnerability Report
  • Backup Report
  • Incident Record
  • Supplier Assessment
  • Internal Audit Report
  • Management Review Record

การเตรียม Evidence ล่วงหน้าช่วยให้การตรวจดำเนินไปได้รวดเร็ว และทำให้ Auditor ใช้เวลาไปกับการทดสอบ Control มากกว่าการค้นหาเอกสาร

6.Internal Audit Checklist ไม่ควรมีแค่ Yes หรือ No

ข้อผิดพลาดที่พบบ่อยคือการใช้ Checklist แบบ

มี Firewall — Yes
มี Backup — Yes
มี Antivirus — Yes

แล้วสรุปว่าผ่าน

ในทางปฏิบัติ Auditor ควรพิจารณาว่า Control นั้น

ถูกออกแบบ → ถูกนำไปใช้ → ทำงานอย่างต่อเนื่อง → มีประสิทธิผล

ตัวอย่างเช่น องค์กรอาจมี Backup System แต่ไม่เคยทำ Restore Test ซึ่งยังไม่สามารถยืนยันได้ว่ากระบวนการกู้คืนข้อมูลจะทำงานได้เมื่อเกิดเหตุจริง

7.Checklist ที่ใช้จริงควรมีอะไรบ้าง

Checklist สำหรับ Internal Audit ควรประกอบด้วยข้อมูลอย่างน้อยดังนี้

รายการใช้สำหรับ
Clause / Controlระบุข้อกำหนด
Audit Questionคำถามที่ใช้ตรวจ
Expected EvidenceEvidence ที่ควรพบ
Actual EvidenceEvidence ที่ตรวจพบจริง
Samplingตัวอย่างที่เลือกตรวจ
Resultผลการตรวจ
Findingประเด็นที่พบ
Auditor Noteบันทึกเพิ่มเติม

ผลการตรวจอาจแบ่งเป็น Conform, Nonconformity, Observation, OFI หรือ Not Checked ตามหลักเกณฑ์ที่องค์กรกำหนด

8.สรุป

ISO 27001 Internal Audit Checklist ที่ดีควรครอบคลุมทั้ง Clause 4–10 และ Annex A Controls ที่เกี่ยวข้องกับขอบเขตและความเสี่ยงขององค์กร

แต่เป้าหมายไม่ใช่เพียงการทำ Checklist ให้ครบทุกข้อ

Auditor ควรสามารถตรวจให้เห็นความเชื่อมโยงระหว่าง

Requirement → Risk → Control → Evidence → Finding → Corrective Action

เพื่อยืนยันว่า ISMS ไม่ได้มีเพียงเอกสาร แต่ถูกนำไปใช้งานจริงและสามารถบริหารความเสี่ยงด้าน Information Security ได้อย่างเหมาะสม

สำหรับองค์กรที่กำลังเตรียม Certification Audit, Surveillance Audit หรือ Recertification Audit การทำ Internal Audit ที่ลงไปถึง Evidence และ Sampling ระบบจริง จะช่วยค้นพบช่องว่างและมีเวลาแก้ไขก่อนเข้าสู่การตรวจรับรอง

ต้องการตรวจ Internal Audit ISO/IEC 27001:2022?

DataFlow Consult ให้บริการ ISO 27001 Internal Audit และ IT Audit ครอบคลุม Clause 4–10, Risk Management, Statement of Applicability, Annex A Controls และ Technical Evidence พร้อมสรุป Findings และข้อเสนอแนะก่อนการตรวจรับรอง

Email: contact@dataflowconsult.com
โทร: 063-4563698