Jump to main navigation Jump to main navigation Jump to main content Jump to footer content

Conducting internal audits

Conduct a comprehensive information security inventory to verify the maturity of an ISMS and progress in the Higher Education Information Security Program (HISP). In audit-like interviews, all areas (organization, personnel, buildings and technical security) of the information security management system (ISMS) are reviewed in accordance with the DIN ISO/IEC 27001 standard in the current version and an audit report with recommendations for measures is prepared.

 

Scope of Services and Service Specifics 

  • Interviews on the status of the ISMS according to the agreed audit plan
  • Inspection of the data center
  • Preparation of an audit report and recommendations for action

 

Service Parameters

  • Creation of an audit plan in coordination with a local contact person
  • Conducting a 2-day on-site audit
    • Organisational, personnel, physical, technical measures with the help of interviews
    • Visiting the data center
  • Preparation of an audit report with a representation of a maturity level (according to HISP maturity levels)
  • Create a list of actions with recommendations
  • The first draft of the audit report and the list of measures will be submitted within 3 weeks of the completion of the audit

 

Requirements

  • The local contact coordinates the dates set in the audit plan with the people to be interviewed and the availability of a meeting room
  • Collecting ISMS-relevant documents required by the auditors

 

User / Customers

This service is made available to the following categories of users.

 

User classNote
(1), (2)only for members of the Digital Network of Bavaria
(3), (4), (5), (6)not available for these customers

 

An appointment can be booked by the CIO, CISO, ISB, RZ management or the management of the universities in the digital network via a link provided by HITS IS.