Zum Hauptinhalt springen

Answer requirements in an audit

How to assess each requirement of an assigned checklist on the inspection item: set the status, document the facts under “Notes on implementation”, store evidence in the “Files” tab and follow up on findings with a task.

Last updated:

On the inspection item, you answer each requirement of the assigned checklists individually: you set the status, record the facts you established and store the evidence. This produces the auditable proof that your measures are effective under ISO/IEC 27001, BSI IT baseline protection or CISIS12.

Prerequisites

  • You have access to the audit via the organisation assignment or via the “All organisations” setting.
  • An “Audit catalog” is assigned to the audit and checklists are assigned to the inspection item. An answer entry with the status “Not processed” then already exists for every requirement.
  • You have permission to edit audits.

Status of requirements

  • “Not processed” – default value when created; the requirement has not yet been assessed.
  • “Implemented” – the requirement is fulfilled.
  • “Partially implemented” – the requirement is partially fulfilled; the gap belongs in the description or in a task.
  • “Not implemented” – the requirement is not fulfilled; measures are required.
  • “Does not apply” – the requirement is not applicable to this inspection item, with a justification.

Assess a requirement

  1. Open the detail view of the inspection item and click the line you want in the “Requirements” section. The “Audit – Requirements” view opens as a page view.
  2. In the “Contents” tab, read the requirement text from the audit catalog under “Description” and check the “Applicability”, for example “Relevance: MUST”.
  3. Click “Edit” at the top right.
  4. Set the “Status” to the appropriate value.
  5. Under “Interviewee”, enter the name or role of the person who provided the information.
  6. Under “Notes on implementation”, describe the facts you established: what was checked, what evidence was available and what gaps were identified. If your team maintains standard wording, insert it as a prepared text block.
  7. Click “Save and close”.

Store evidence and follow-up measures

  1. In the requirement detail view, switch to the “Files” tab and store the evidence there – documents, screenshots or log extracts.
  2. If you assess a requirement as “Not implemented” or “Partially implemented”, create a task with a responsible person and a deadline right away in the “Tasks” tab.

Mark requirements as implemented

  1. For a single requirement, click “Actions” in its detail view and select “Mark as implemented”.
  2. For several requirements, select the entries in the “Requirements” section using the selection boxes, click “Actions” at the top right and select “Mark as implemented”.
  3. Confirm the security prompt “Do you really want to mark these as implemented?” with “Yes, mark as implemented”.

Practical tips

  • In the “Requirements” section, use the “Search term” search field and the “Filter” area to filter by status or checklist, and work through the open MUST requirements first.
  • Every answer is logged in the activity history of the audit. As soon as a requirement receives a final status, the progress display of the inspection item and of the checklist is recalculated.
  • Answers with “Not implemented”, “Partially implemented” or “Does not apply” are the typical trigger for updating your technical and organizational measures.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms