How Does wolkvox Conduct Internal and External Audits Related to the ISMS?
Table of Contents
Description
wolkvox conducts internal and external audits of its Information Security Management System (ISMS) as a key part of its commitment to security and regulatory compliance. As a company certified under the ISO/IEC 27001 standard, wolkvox performs audits every six months: internal audits are carried out by a team of internal auditors, while external audits are conducted by SGS, a specialized and internationally recognized provider.
This approach ensures that the ISMS remains aligned with international standards, identifies opportunities for improvement, and complies with legal and contractual requirements.
Features
Internal Audits
- Semiannual frequency: Conducted every 6 months to assess compliance with ISMS controls and the effectiveness of security processes.
- Internal audit team: A trained and independent group within wolkvox performs the audits, ensuring objectivity and deep understanding of internal processes.
- Focus on continuous improvement: Findings are documented and transformed into action plans to correct deviations and optimize the ISMS.
External Audits
- Conducted by SGS: The external provider SGS performs annual audits (or as required by the standard) to validate compliance with ISO/IEC 27001 and other applicable standards.
- Objectivity and rigor: External audits provide an independent perspective, ensuring that processes meet regulatory requirements and industry best practices.
- Certification and renewal: The results of these audits are key to maintaining and renewing ISO 27001 certification, reinforcing trust among clients and stakeholders.
Audit Process
- Planning: Scope, criteria, and schedules are defined for each audit, ensuring that all critical areas are evaluated.
- Execution: Auditors review documentation, interview staff, and verify the implementation of controls in the field.
- Findings report: A detailed report is issued with non-conformities, observations, and recommendations, prioritized by impact.
- Follow-up: wolkvox implements corrective actions and verifies their effectiveness, closing the improvement cycle.