Zum Hauptinhalt springen

Edit an audit catalog and map your own standard

How to create your own audit catalog and maintain its master data – designation, status, document ID, language, description and association – so that your own standard or internal audit scheme is available as a reusable methodological framework in your ISMS.

Last updated:

If your audit scheme does not come from a ready-made standard – for example a group-wide security policy, a supplier assessment or an in-house scheme based on ISO/IEC 27001 – you map it as your own audit catalog. This article shows how to create an empty catalog and maintain its master data so that the methodology stays easy to find, versionable and traceable for external auditors.

Prerequisites

  • You are logged in to a team that uses the “Audit catalogues” module.
  • You have permission to view and edit audit catalogues.
  • Setting the status to “Published” additionally requires permission to publish.
  • You have access to the associated organisation, or the catalog is shared for “All organisations”.

Create your own audit catalog

  1. In the left-hand menu, click “Audits” and then “Audit catalogues”.
  2. At the top right, click the arrow icon next to the “New” button.
  3. Select “Create audit catalog”. This creates an empty catalog that you then fill yourself with checklists, requirements, inspection object types, applicabilities and hazards.
  4. Complete the form and save.

The second option, “Load from sample documents”, instead adopts a pre-filled template such as “BSI IT baseline protection” or “CISIS12” – that is the right route when you want to map a proven standard rather than your own.

Edit the master data

  1. Open the detail view of the catalog and click “Edit” at the top right, or click “Edit” in the “Actions” menu.
  2. In the “Contents” tab, “General” section, enter a descriptive “Designation” (mandatory field, 1–150 characters).
  3. Choose the “Status”: “New” while creating it, “In progress” during the methodological setup, “Published” for productive use and “Archived” for superseded versions.
  4. Under “Document ID”, optionally enter your internal identifier, for example AK-001.
  5. Select the “Language” of the catalog.
  6. In the “Description”, record the methodological origin – reference to standards and source, scope of application and intended audience.
  7. In the “Association” section, assign the catalog via “Organisations”. If the methodology is intended to apply to the entire team, enable “All organisations”.
  8. Click “Save”. “Cancel” discards your entries.

What this changes

  • The process is logged and is visible in the “Activities” tab.
  • When transitioning to the “Published” status, a new revision is created automatically; it appears in the “Revisions” tab.
  • If the catalog is inherited to subsidiaries via “Create linked document”, changes affect all derived variants. The “Relationships” tab shows whether dependent documents exist.

Practical tip: set the status to “Published” only once the checklists and their requirements have been fully recorded and the relevant hazards have been assigned. As long as the catalog is “In progress”, contents can be revised without risk – after publication, every change is versioned and becomes visible in relation to audits already in progress.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms