Create and structure a checklist in the audit catalog
Checklists are the structuring level of an audit catalog: they group the requirements of one topic area and define, via the permitted audit object type, what is later inspected. Here is how to create a checklist, name it consistently and duplicate it.
Checklists are the structuring level within an audit catalog: each checklist groups the requirements of one topic area and defines, through the permitted audit object type, what kind of object it is applied to in the audit. This is how you structure your ISMS framework along ISO 27001, BSI IT baseline protection or CISIS12 so that audits stay reproducible.
Prerequisites
- You have access to the parent audit catalog.
- You have permission to edit the audit catalog.
- At least one “Inspection object type” is maintained in the audit catalog — for example
ISMS process,ComplianceorAsset. If none exists, you can create it directly from the checklist form.
Step by step
- Open the detail view of the audit catalog and scroll to the “Checklists” section. The table shows the columns “Designation”, “Description” and “Permitted audit object type”; sort via the column headings and filter with the “Search term” field.
- In the “Checklists” section, click the “New” button. The “New checklist” input window opens.
- Enter the name of the checklist in “Designation” (mandatory field, 1–191 characters), for example
B1.010: Compliance requirements. - Use the optional “Description” field to explain the checklist's scope of application.
- Under “Permitted audit object type”, select an entry from the selection menu. If you need a new type first, click the “Edit” button to the right of the selection menu: the “Inspection object types” sidebar opens, where “New” lets you add another “Designation”.
- Click “Create”. “Cancel” discards the entry.
- In the “Checklists” table, click anywhere in the new row. The checklist opens in a sidebar where you can then add the items to be answered in the “Requirements” section.
Edit, duplicate or delete a checklist
- Open the detail view of the checklist.
- Click “Edit” at the top right, or open the “Actions” selection menu.
- Choose “Edit” to adjust the designation, description and permitted audit object type; “Duplicate” to create a copy of the checklist including its requirements as a new entry; or “Delete” to remove the checklist with all its requirements after a security prompt.
If the audit catalog has the status “Released”, a security prompt appears before every change, because methodological adjustments affect all ongoing audits against this catalog. Every change is logged in the catalog's activity history.
Practical tip: maintain a clear nomenclature for your checklists — for example following the pattern {Area}.{Number}: {Title} as used by CISIS12 or the BSI IT baseline protection compendium. Consistent numbering makes it easier to find items during the audit, to cross-reference them in reports and to maintain large catalogs with hundreds of checklists. Also keep the list of inspection object types short: three to five types are usually enough, as excessively fine subdivision leads to inconsistencies in the audit.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.