Agile Audit Proposal for ISO IEC 27001 Standard Implementation in Higher Education Faculties
摘要
The Information Security Management System (ISMS) is responsible for protecting information by implementing strategies to ensure its confidentiality, availability, and integrity. Information for the ISMS is collected through a Statement of Applicability, allowing for an ISMS audit of the organization and demonstrating its condition. This work proposes an agile internal audit methodology based on ISO/IEC 27001, aimed at reducing the time required for internal audits and preparing the institution for formal certification.