SlideShare a Scribd company logo
1 of 19
Download to read offline
©
©
A Road Towards ISO 27001 Lead Auditor Certification
• Presented by-
Fahad Zaman Chowdhury
Joint Secretary (Admin)
Bangladesh Computer Society
&
Joint Director (ICT)
Bangladesh Bank
1
©
My Profile
Professional: Joint Director (ICT), Bangladesh Bank
Member, Bangladesh Bank CIRT
Cyber Security Practitioner
Panelist, AFI Cyber Security Program, Malaysia
Academic:
MSc (CS, University of Malaya, Malaysia), MBA (Finance, DU), BSc (EEE, KUET)
Certification: ISO 27001 LA, CDFOM, ECSA
Academic/research Interests
Information Security, Network Security, Game Theory, Security of Pervasive and Ubiquitous Computing
Awards/fellowships/grants
1. Secured best paper award in 8th IEEE Control and System Graduate Research Colloquium (ICSGRC) 2017, Conference held in Shah
Allam, Malaysia
2. Won IEEE quiz award in IEEE student congress organized by IEEE Malaysia Section & Asia Pacific University, Malaysia 2
©
My Profile (Contd.)
Publications And Presentations
1.EDoS Eye: A Game Theoretic Approach to Mitigate Economic Denial of Sustainability Attack in Cloud Computing by Fahad Zaman
Chowdhury, Mohd Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of 8th IEEE Control & System
Graduate Research Colloquium (ICSGRC) 2017, Malaysia.
2. Economic Denial of Sustainability Mitigation Approches in Cloud- Analysis and Open Challenges by Fahad Zaman Chowdhury, Mohd
Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of International Conference on Electrical Engineering and
Computer Science (ICECOS) 2017, Indonesia.
3.An efficient fuzzy keyword matching technique for searching through encrypted cloud data by M A Manazir Ahsan, Fahad Zaman
Chowdhury, Musarat Sabilah, Ainuddin Wahid Bin Abdul Wahab, Mohd Yamani Idna Bin Idris. In proceeding of 2017 International Conference
on Research and Innovation in Information Systems (ICRIIS), Malaysia.
4. Seminar on "A Dynamic Game Modeling of EDoS Eye" presented in Post Graduate Research Excellence Symposium (PGRES) 2017
organized by faculty of computer science and information technology, University of Malaya, Malaysia.
Memberships/affiliations
1. Joint Secretary (Admin), Bangladesh Computer Society
2. Member, Institute of Engineers Bangladesh (IEB)
3. Life Member, Bangladesh Computer Society
4. Member, Engineers Club, Dhaka
5. Former Ex-Co Member, IEEE UM Student branch
Online Profile
1 https://scholar.google.com/citations?user=CaTbyOFiZQUC&hl=en (Google Scholar)
2. https://bd.linkedin.com/in/fahad-zaman-chowdhury-644a5427 (Linkedin)
3. https://www.researchgate.net/profile/Fahad_Chowdhury2 (ResearchGate)
3
©
©
Road Towards
ISO 27001
Lead Auditor
Certification
4
©
Topic
5
Conducting Audit
Audit Findings
Audit Reporting
Audit Follow-Up
©
Conducting Audit
6
Auditing is a Fact-Finding Process
Not
A Fault-Finding Process
©
Conducting Audit
7
ü Objective of an Audit
ü Benefits of Audit
ü Types of Audit
ü Stages of the Audit (Stage 1 & Stage 2 )
ü Surveillance Audits
ü Re-Certification Audits
ü Principles of Auditing (Integrity, Fair presentation, Due Professional Care,
Confidentiality, Independence, Evidence based approach)
ü Responsibilities of a Lead Auditor
ü Traits/Attributes of an Auditor
ü Knowledge and Skills of Auditor
©
Conducting Audit
8
Colleacting and Verifying Information:
Sources of information
Collecting by means of appropriate sampling
Audit Evidence
Evaluating against audit criteria
Audit findings
Reviewing
Audit Conclusions
©
Conducting Audit
9
Auditor’s Task :
Verify
Interviews
Questions
Observation
Examination
©
Conducting Audit
10
• What do Auditors Examine?
Documentation Records Hardware
Software Processes People
©
Audit Findings
11
Audit Findings :
ü Indicate conformity and non-conformity
ü Lead to identification of opportunities for improvement or recording good practices
ü Can be tremed compliance or non-compliance if the criteria selected based on legal
or regulatory requirements
©
Audit Findings
12
Fulfilment of a
requirement
Factual evidence of a
condition in
accordance with a
specified requirement
Non fulfilment of
a requirement
Factual evidence of a
condition not in
accordance with a
specified requirement
©
Audit Findings
13
Major Non-conformity:
ü A significance non-conformance with specified requirements or ISMS requirements
ü Failure of System
ü Significance number of minor failures
©
Audit Reporting
14
ü Record the findings during the audit time and compile it to make it
presentable or reportable
ü Review with the auditee/ audit representative when in doubt
ü Classify or grade the non-conformity
ü Reach to a conclusion of the audit
ü Conduct a closing meeting
©
Audit Follow-Up
15
Audit follow-up is required
ü To verify and assess the effectiveness of the corrective/preventive
actions by the organization.
ü Involves: Verifying, Closing and/or Escalating
Follow-up audit can vary based on the severety of the problem:
ü A limited re-audit
ü A renew of the new/amended documentation
ü Include in the next audit
©
Audit Follow-Up
16
Role of auditee
ü Understand the non-conformity raised
ü Investigate the cause
ü Identify action
ü Select most appropriate actions and develop action plan
ü Take corrective actions
ü Internal verification of completion
ü Inform auditor about implementation and plan for follow-up
©
Audit Follow-Up
17
Role of auditor
ü Review corrective action plan
ü Verifiy corrective actions
ü Close out and confirm compliance report
©
Question and
Answer
18
©
©
Thank You All
19

More Related Content

Similar to BCS ISO 27001 LA Lecture Fahad Zaman.pdf

Project report-on-student-information-management-system-php-mysql
Project report-on-student-information-management-system-php-mysqlProject report-on-student-information-management-system-php-mysql
Project report-on-student-information-management-system-php-mysqlRaj Sharma
 
Project report college information management system on Advanced Java
Project report college information management system on Advanced JavaProject report college information management system on Advanced Java
Project report college information management system on Advanced JavaRishabh Kumar ☁️
 
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...IRJET Journal
 
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMS
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMSSTRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMS
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMSShreejit Jadhav
 
Key Concepts And Principles Of Internal Quality Assurance...
Key Concepts And Principles Of Internal Quality Assurance...Key Concepts And Principles Of Internal Quality Assurance...
Key Concepts And Principles Of Internal Quality Assurance...Lanate Drummond
 
Attendance management system project report.
Attendance management system project report.Attendance management system project report.
Attendance management system project report.Manoj Kumar
 
Develop project pia+ risk identification
Develop project pia+ risk identificationDevelop project pia+ risk identification
Develop project pia+ risk identificationTrilateral Research
 
Erudition- Institute Management System
Erudition- Institute Management SystemErudition- Institute Management System
Erudition- Institute Management SystemIRJET Journal
 
online education system project report
online education system project reportonline education system project report
online education system project reportHagi Sahib
 
An Intelligent Career Guidance System using Machine Learning
An Intelligent Career Guidance System using Machine LearningAn Intelligent Career Guidance System using Machine Learning
An Intelligent Career Guidance System using Machine LearningIRJET Journal
 
Chapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfChapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfKamal Acharya
 
Chapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfChapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfKamal Acharya
 
Project-Student Financial Service System
Project-Student Financial Service SystemProject-Student Financial Service System
Project-Student Financial Service Systemchezhiang
 
NUS-ISS Digital Architecture Information Session
NUS-ISS Digital Architecture Information SessionNUS-ISS Digital Architecture Information Session
NUS-ISS Digital Architecture Information Sessionengtsze
 
Studentinformationmanagementsystem.pdf iyr
Studentinformationmanagementsystem.pdf iyrStudentinformationmanagementsystem.pdf iyr
Studentinformationmanagementsystem.pdf iyr053VENKADESHKUMARVK
 

Similar to BCS ISO 27001 LA Lecture Fahad Zaman.pdf (20)

Project report-on-student-information-management-system-php-mysql
Project report-on-student-information-management-system-php-mysqlProject report-on-student-information-management-system-php-mysql
Project report-on-student-information-management-system-php-mysql
 
Project report college information management system on Advanced Java
Project report college information management system on Advanced JavaProject report college information management system on Advanced Java
Project report college information management system on Advanced Java
 
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
 
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMS
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMSSTRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMS
STRATEGIC FINANCIAL MANAGEMENT FOR ENHANCED UI/UX DESIGN IN DIGITAL PLATFORMS
 
CC 207 Module.docx
CC 207 Module.docxCC 207 Module.docx
CC 207 Module.docx
 
My thesis proposal
My thesis proposalMy thesis proposal
My thesis proposal
 
Key Concepts And Principles Of Internal Quality Assurance...
Key Concepts And Principles Of Internal Quality Assurance...Key Concepts And Principles Of Internal Quality Assurance...
Key Concepts And Principles Of Internal Quality Assurance...
 
Attendance management system project report.
Attendance management system project report.Attendance management system project report.
Attendance management system project report.
 
Develop project pia+ risk identification
Develop project pia+ risk identificationDevelop project pia+ risk identification
Develop project pia+ risk identification
 
Erudition- Institute Management System
Erudition- Institute Management SystemErudition- Institute Management System
Erudition- Institute Management System
 
online education system project report
online education system project reportonline education system project report
online education system project report
 
Hafsa 131003112307-phpapp02
Hafsa 131003112307-phpapp02Hafsa 131003112307-phpapp02
Hafsa 131003112307-phpapp02
 
System maintenance.ppt
System maintenance.pptSystem maintenance.ppt
System maintenance.ppt
 
Online Job Portal
Online Job PortalOnline Job Portal
Online Job Portal
 
An Intelligent Career Guidance System using Machine Learning
An Intelligent Career Guidance System using Machine LearningAn Intelligent Career Guidance System using Machine Learning
An Intelligent Career Guidance System using Machine Learning
 
Chapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfChapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdf
 
Chapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdfChapter_1_INTRODUCTION.pdf
Chapter_1_INTRODUCTION.pdf
 
Project-Student Financial Service System
Project-Student Financial Service SystemProject-Student Financial Service System
Project-Student Financial Service System
 
NUS-ISS Digital Architecture Information Session
NUS-ISS Digital Architecture Information SessionNUS-ISS Digital Architecture Information Session
NUS-ISS Digital Architecture Information Session
 
Studentinformationmanagementsystem.pdf iyr
Studentinformationmanagementsystem.pdf iyrStudentinformationmanagementsystem.pdf iyr
Studentinformationmanagementsystem.pdf iyr
 

Recently uploaded

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 

Recently uploaded (20)

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 

BCS ISO 27001 LA Lecture Fahad Zaman.pdf

  • 1. © © A Road Towards ISO 27001 Lead Auditor Certification • Presented by- Fahad Zaman Chowdhury Joint Secretary (Admin) Bangladesh Computer Society & Joint Director (ICT) Bangladesh Bank 1
  • 2. © My Profile Professional: Joint Director (ICT), Bangladesh Bank Member, Bangladesh Bank CIRT Cyber Security Practitioner Panelist, AFI Cyber Security Program, Malaysia Academic: MSc (CS, University of Malaya, Malaysia), MBA (Finance, DU), BSc (EEE, KUET) Certification: ISO 27001 LA, CDFOM, ECSA Academic/research Interests Information Security, Network Security, Game Theory, Security of Pervasive and Ubiquitous Computing Awards/fellowships/grants 1. Secured best paper award in 8th IEEE Control and System Graduate Research Colloquium (ICSGRC) 2017, Conference held in Shah Allam, Malaysia 2. Won IEEE quiz award in IEEE student congress organized by IEEE Malaysia Section & Asia Pacific University, Malaysia 2
  • 3. © My Profile (Contd.) Publications And Presentations 1.EDoS Eye: A Game Theoretic Approach to Mitigate Economic Denial of Sustainability Attack in Cloud Computing by Fahad Zaman Chowdhury, Mohd Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of 8th IEEE Control & System Graduate Research Colloquium (ICSGRC) 2017, Malaysia. 2. Economic Denial of Sustainability Mitigation Approches in Cloud- Analysis and Open Challenges by Fahad Zaman Chowdhury, Mohd Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of International Conference on Electrical Engineering and Computer Science (ICECOS) 2017, Indonesia. 3.An efficient fuzzy keyword matching technique for searching through encrypted cloud data by M A Manazir Ahsan, Fahad Zaman Chowdhury, Musarat Sabilah, Ainuddin Wahid Bin Abdul Wahab, Mohd Yamani Idna Bin Idris. In proceeding of 2017 International Conference on Research and Innovation in Information Systems (ICRIIS), Malaysia. 4. Seminar on "A Dynamic Game Modeling of EDoS Eye" presented in Post Graduate Research Excellence Symposium (PGRES) 2017 organized by faculty of computer science and information technology, University of Malaya, Malaysia. Memberships/affiliations 1. Joint Secretary (Admin), Bangladesh Computer Society 2. Member, Institute of Engineers Bangladesh (IEB) 3. Life Member, Bangladesh Computer Society 4. Member, Engineers Club, Dhaka 5. Former Ex-Co Member, IEEE UM Student branch Online Profile 1 https://scholar.google.com/citations?user=CaTbyOFiZQUC&hl=en (Google Scholar) 2. https://bd.linkedin.com/in/fahad-zaman-chowdhury-644a5427 (Linkedin) 3. https://www.researchgate.net/profile/Fahad_Chowdhury2 (ResearchGate) 3
  • 4. © © Road Towards ISO 27001 Lead Auditor Certification 4
  • 6. © Conducting Audit 6 Auditing is a Fact-Finding Process Not A Fault-Finding Process
  • 7. © Conducting Audit 7 ü Objective of an Audit ü Benefits of Audit ü Types of Audit ü Stages of the Audit (Stage 1 & Stage 2 ) ü Surveillance Audits ü Re-Certification Audits ü Principles of Auditing (Integrity, Fair presentation, Due Professional Care, Confidentiality, Independence, Evidence based approach) ü Responsibilities of a Lead Auditor ü Traits/Attributes of an Auditor ü Knowledge and Skills of Auditor
  • 8. © Conducting Audit 8 Colleacting and Verifying Information: Sources of information Collecting by means of appropriate sampling Audit Evidence Evaluating against audit criteria Audit findings Reviewing Audit Conclusions
  • 9. © Conducting Audit 9 Auditor’s Task : Verify Interviews Questions Observation Examination
  • 10. © Conducting Audit 10 • What do Auditors Examine? Documentation Records Hardware Software Processes People
  • 11. © Audit Findings 11 Audit Findings : ü Indicate conformity and non-conformity ü Lead to identification of opportunities for improvement or recording good practices ü Can be tremed compliance or non-compliance if the criteria selected based on legal or regulatory requirements
  • 12. © Audit Findings 12 Fulfilment of a requirement Factual evidence of a condition in accordance with a specified requirement Non fulfilment of a requirement Factual evidence of a condition not in accordance with a specified requirement
  • 13. © Audit Findings 13 Major Non-conformity: ü A significance non-conformance with specified requirements or ISMS requirements ü Failure of System ü Significance number of minor failures
  • 14. © Audit Reporting 14 ü Record the findings during the audit time and compile it to make it presentable or reportable ü Review with the auditee/ audit representative when in doubt ü Classify or grade the non-conformity ü Reach to a conclusion of the audit ü Conduct a closing meeting
  • 15. © Audit Follow-Up 15 Audit follow-up is required ü To verify and assess the effectiveness of the corrective/preventive actions by the organization. ü Involves: Verifying, Closing and/or Escalating Follow-up audit can vary based on the severety of the problem: ü A limited re-audit ü A renew of the new/amended documentation ü Include in the next audit
  • 16. © Audit Follow-Up 16 Role of auditee ü Understand the non-conformity raised ü Investigate the cause ü Identify action ü Select most appropriate actions and develop action plan ü Take corrective actions ü Internal verification of completion ü Inform auditor about implementation and plan for follow-up
  • 17. © Audit Follow-Up 17 Role of auditor ü Review corrective action plan ü Verifiy corrective actions ü Close out and confirm compliance report