Auditoría ISO 27001 (Interna)ISO 27001 Audit (Internal)
Auditoría interna del SGSI previa a certificación.Internal ISMS audit ahead of certification.
¿Qué es este servicio?What is this service?
Es la auditoría interna del sistema de gestión de seguridad de la información, hecha por un tercero independiente para verificar que el sistema cumple la norma y funciona antes de que llegue el auditor de certificación.
The internal audit of the information security management system, performed by an independent third party to verify the system meets the standard and works before the certification auditor arrives.
¿Para qué se usa?What is it used for?
Responde a dos razones a la vez. La primera es que la norma la exige: sin auditoría interna documentada no hay certificación posible. La segunda es práctica: encontrar las no conformidades ahora, cuando corregirlas cuesta tiempo, en vez de encontrarlas en la auditoría de certificación, cuando cuestan el certificado.
It serves two purposes at once. The first is that the standard requires it: without a documented internal audit there is no certification. The second is practical: finding nonconformities now, when fixing them costs time, instead of at the certification audit, when they cost the certificate.
Qué beneficios traeBenefits it delivers
- Cumple un requisito obligatorio de la norma y a la vez prepara la certificación.
- La independencia es real: el auditor interno de la propia empresa difícilmente audita con dureza a su jefe.
- Detecta la brecha entre lo escrito y lo que la gente hace de verdad, que es donde caen la mayoría de las no conformidades.
- Entrena al equipo en cómo se responde a un auditor, que también se aprende.
- Meets a mandatory requirement of the standard while preparing for certification.
- The independence is real: an in-house internal auditor rarely audits their own boss harshly.
- Detects the gap between what is written and what people actually do, where most nonconformities land.
- Trains the team in how to respond to an auditor, which is also a learned skill.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No es obligatorio por ley costarricense, porque tampoco lo es la propia certificación.
- Si la organización decidió certificarse, entonces sí es obligatorio: lo exige la norma, no el país.
- It is not mandatory under Costa Rican law, since certification itself is not either.
- If the organisation has decided to certify, then it is mandatory: the standard requires it, not the country.
InternacionalInternational
- ISO 27001 exige auditorías internas a intervalos planificados, que cubran todo el alcance del sistema.
- El auditor debe ser objetivo e imparcial, y no puede auditar su propio trabajo.
- Los resultados deben reportarse a la dirección y alimentar la revisión por la dirección.
- ISO 27001 requires internal audits at planned intervals covering the system's entire scope.
- The auditor must be objective and impartial, and cannot audit their own work.
- Results must be reported to management and feed the management review.
Requisitos mínimosMinimum requirements
- Un sistema de gestión ya implementado y con registros: auditar un sistema que arrancó la semana pasada no tiene sentido.
- Alcance y declaración de aplicabilidad definidos.
- Disponibilidad de las personas que operan los controles, que es a quienes se entrevista.
- Evidencia de al menos un ciclo de operación de los controles principales.
- A management system already implemented and generating records: auditing a system that started last week is pointless.
- A defined scope and statement of applicability.
- Availability of the people who operate the controls, since they are the ones interviewed.
- Evidence of at least one operating cycle of the main controls.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de dos a cuatro semanas contando planificación, trabajo de campo e informe. El tamaño del alcance y la cantidad de sedes son lo que mueve el número. Conviene hacerla al menos dos meses antes de la auditoría de certificación, para que dé tiempo a cerrar lo que salga.
The usual market range runs from two to four weeks including planning, fieldwork and reporting. Scope size and number of sites are what move the number. It is worth running it at least two months before the certification audit, to leave time to close what comes up.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.