Independent internal audit
for your ICT systems
and physical security.
An internal audit of ICT systems and physical security is the mechanism that allows your organization to determine, with certainty and objective evidence, whether its management system actually works or exists only on paper. It is a specialized service performed by independent professionals, with a level of impartiality that no internal team can guarantee for itself.
All relevant ICT standards—ISO 27001, ENS, TISAX, ISO 22301, ISO 20000—require periodic internal audits as part of the continuous improvement cycle. It is a formal requirement. But reducing the internal audit to a mere compliance formality is one of the most common and costly mistakes organizations make.
A well-executed internal audit allows you to: detect actual gaps between documented procedures and actual practice; identify unanticipated risks that have emerged over time; verify the actual effectiveness of controls, not just their formal existence; anticipate findings that the external auditor will uncover, allowing time to correct them; demonstrate the actual status to management with objective evidence; and fuel the cycle of continuous improvement required by all standards.
This is the fundamental principle—and, at the same time, the one most frequently ignored—when organizations attempt to address compliance using their own resources.
An auditor cannot audit their own work. Not because of a lack of technical knowledge, but because the absence of independence inevitably skews the process: what is reviewed, how findings are interpreted, what is documented as a finding, and what is overlooked. This is not necessarily intentional. It is an inherent limitation that standards recognize and require to be mitigated.
ISO 19011 clearly states that auditors must be objective and independent of the activity they are auditing. ISO/IEC 27001, ENS, TISAX, ISO 22301, and ISO 20000 explicitly state this.
Situations in which independence is compromised: the system manager audits controls that he or she has designed; the IT department audits its own processes; the security manager reviews his or her own plan; a consultant who participated in the implementation later conducts the internal audit.
An ICT systems auditor may be formally independent—having not participated in the audited activity—and yet still lack impartiality if they have a stake in the outcome.
An impartial auditor: has no interest in the outcome being favorable or unfavorable; does not tailor their conclusions to what management wants to hear; does not formulate findings based on personal relationships with those being audited; documents what they find, not what is convenient to document; applies the same criteria regardless of department, position, or seniority.
Impartiality is especially critical in small and medium-sized organizations, where personal relationships between the internal auditor and those being audited are inevitably closer. In that context, an independent external auditor is not a luxury option: it is the only way to ensure reliable results.
Review of the ISMS in accordance with ISO/IEC 27001 and its Annex A. Verification of the effectiveness of controls, compliance with policies, risk management, incident handling, and management review.
Review of compliance with the ENS in accordance with Royal Decree 311/2022 and CCN-STIC guidelines. Verification based on system category (basic, medium, high), gap analysis, and report in the required format.
Review in accordance with the VDA ISA questionnaire and TISAX assessment criteria. Preparation for the official assessment by an ENX-accredited provider.
Review of the SGCN. Verification of continuity plans, BIAs, drills and tests, and actual response capability in the event of an outage.
Review of the SMS in accordance with ISO/IEC 20000-1. Verification of delivery and support processes, incident management, change management, service levels, and continuous improvement.
Independent review of physical access control, CCTV, intrusion detection, environmental protection, and procedures. Physical and logical security are inseparable.
Scope, criteria, timeline, and areas to be reviewed.
Analysis of policies, procedures, records, and risks.
Interviews, direct observation, verification of evidence.
Major nonconformities, minor nonconformities, observations.
Reference document for management.
Closing meeting with management and team leaders.
Verification of the resolution of nonconformities and the effectiveness of corrective actions.
This is one of the structural decisions that defines how IMTS operates and that it applies without exception, regardless of the project, the client, or the urgency.
IMTS is not committed to selling a one-time service. It is committed to being a reliable and specialized partner in security, compliance, and intelligence. Fifteen years of supporting companies and public agencies back this up.
To schedule an initial meeting at no cost and with no obligation. Complete discretion from the very first contact.