Abstract :
An information system security audit is a comprehensive evaluation of the IT infrastructure and security policies implemented by the National Amil Zakat Agency in Bengkalis Regency. This audit is conducted with reference to the ISO 27001 standard, an international framework for information security management. The purpose of this study is to evaluate the extent to which the National Amil Zakat Agency of Bengkalis Regency complies with international security standards, identify potential security gaps, and provide recommendations to improve the security of their information systems. The audit results show that the Bengkalis Regency National Amil Zakat Agency has implemented a number of security controls in accordance with the ISO 27001 standard, but has not involved formal, clearly documented documents. It is recommended that the Bengkalis Regency National Amil Zakat Agency create SOPs/Procedures for operational responsibility, Malware Protection, Backup, and Logging and Monitoring. The point is to ensure organizational compliance with the ISO 27001 standard by regulating the steps needed to implement security controls, manage risks, and comply with information security policies.