Zum Hauptinhalt springen

Maintain an audit's connections to other documents

The “Relationships” tab of an audit shows in one place which documents use the audit and which work together with it. This lets you prove in your ISMS which methodology the audit is based on and which follow-up measures came out of it.

Last updated:

In your ISMS an audit never stands alone: it is based on an audit catalog and produces tasks, checklists, risk analyses and surveys. After reading this article you will know where these connections are shown together, how to jump from there into the linked document, and how new connections come about.

Prerequisites

  • You have access to the associated organization, or the audit is released for “All organisations”.
  • Access to the organization is enough to simply view the connections. To create tasks, risk analyses or surveys you additionally need the appropriate authorization.

Step by step

  1. Open the “Audits” overview and click anywhere in the line in the table to open the detail view. It starts on the “Contents” tab.
  2. Switch to the “Relationships” tab. It is divided into the two areas “Uses” and “Collaboration & functions”.
  3. In the “Uses” area, check in which other documents this audit is used or referenced: “Audit catalogues” shows the underlying catalog against which the audit is carried out, “Audits” shows other audits that are connected to this one.
  4. In the “Collaboration & functions” area, check the documents that work together with the audit or provide functions for it: “Tasks” (follow-up measures created on the audit or on an individual requirement), “Checklists” (completed checklists in addition to the audit lists from the audit catalog), “Risk analyses” (risk analyses for the inspection items of this audit) and “Surveys” (surveys that supplement the audit, for example for the self-assessment of the persons surveyed).
  5. Click an entry in one of the cards to switch straight into the linked document — for example from the audit into the audit catalog that supplies the inspection object types, applicabilities, requirements and hazards.
  6. Create new connections where they arise in practice: tasks directly on the respective requirement, risk analyses in the “Risk analyses” tab or in the relationship card of the same name. They then appear in the “Relationships” tab.

Why the relationships matter in an ISMS

  • The connection to the audit catalog documents the methodology: under ISO 27001 or BSI IT baseline protection it must be traceable which framework was audited against. If the catalog changes, the application requires explicit confirmation, because existing inspection items and responses may be affected.
  • The connection to tasks documents the effectiveness review: it makes visible that a finding has turned into a trackable measure.
  • The connection to risk analyses closes the loop to risk management — the hazards recorded on the inspection item are formally assessed there.

Tip from practice: Record every identified gap as a task instead of merely noting it in the description of the requirement. Tasks can be tracked via follow-ups and status and appear in the audit's relationships — description texts often get lost in the audit follow-up and only reappear when the next review is due.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms