1
Richiesta & offertaEnquiry & proposal
Scopo, perimetro, siti, asset critici e complessità: programma audit e proposta formale.Scope, perimeter, sites, critical assets and complexity: audit program and formal proposal.
2
PianificazionePlanning
Team con competenze adeguate (settore, ICT, rischi) e piano di audit.Team with relevant competence (sector, ICT, risk) and audit plan.
3
Stage 1Stage 1
Valutazione readiness: ISMS, risk assessment, SoA, politiche e controlli chiave.Readiness review: ISMS, risk assessment, SoA, policies and key controls.
4
Stage 2Stage 2
Audit di efficacia: evidenze, implementazione controlli, incidenti, fornitori, monitoraggi.Effectiveness audit: evidence, control implementation, incidents, suppliers, monitoring.
5
Azioni correttiveCorrective actions
Gestione non conformità: cause, azioni e invio evidenze entro tempi concordati.Nonconformities handling: causes, actions and evidence submission within agreed timelines.
6
Decisione & sorveglianzaDecision & surveillance
Decisione indipendente; audit di sorveglianza e rinnovo a fine ciclo.Independent decision; surveillance audits and renewal at cycle end.