Skip to content

Evidence request lists

ISO 27001:2022

Evidence request list. 100 controls, 100 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 0 – ISO 27001:2022

0.1
General
Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.
0.2
Compatibility with other management system standards
Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.

Clause 9 – ISO 27001:2022

9.2.1
General

Conduct internal audits of the information security management system at planned intervals, to establish whether it conforms both to the organisation's own requirements and to the requirements of this document, and whether it is effectively implemented and maintained.

Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.
9.2.2
Internal audit programme

Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, taking account of the importance of the processes concerned and the results of previous audits. Define the criteria and scope of each audit, select auditors and conduct audits in a way that ensures objectivity and impartiality of the audit process, report results to relevant management, and retain documented information as evidence of the programme and the results.

Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.
9.3.1
General

Top management shall review the organisation's information security management system at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.
9.3.2
Management review inputs

The management review shall consider the status of actions from previous reviews, changes in external and internal issues relevant to the management system, changes in the needs and expectations of interested parties, feedback on information security performance including trends in nonconformities and corrective actions, monitoring and measurement results, audit results and fulfilment of information security objectives, feedback from interested parties, results of risk assessment and the status of the risk treatment plan, and opportunities for continual improvement.

Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.
9.3.3
Management review results

The results of the management review shall include decisions related to continual improvement opportunities and to any need for changes to the information security management system. Documented information shall be retained as evidence of the results of management reviews.

Artefacts an auditor will ask for
  • ISMS scope
  • Statement of applicability
  • Risk assessment
  • Risk treatment
  • Policies
  • Competence records
  • Internal audit
  • Management review
Where this commonly fails
  • SoA exists but exclusion justifications are boilerplate without evidence of analysis.
  • Risk assessment performed annually with no update on material change.
  • Internal audit programme exists but findings closed without effectiveness verification.
  • Management review minutes lack documented decisions on risk treatment.

Organizational controls – ISO 27001:2022

5.1
Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

Artefacts an auditor will ask for
  • Security policy document
  • Policy approval records
  • Policy distribution log
  • Policy review schedule
  • Policy change records
Where this commonly fails
  • Policies not formally approved by senior management
  • No evidence of distribution or employee acknowledgment
  • Review dates not documented or missed
  • Version control missing, leading to outdated policies
5.10
Acceptable use of information and other associated assets

Define and enforce rules for how information and assets may be used and handled.

Artefacts an auditor will ask for
  • Acceptable use policy
  • User acknowledgement records
  • Training records
  • Enforcement logs
Where this commonly fails
  • Policy not reviewed or updated regularly
  • Missing documented employee acknowledgments
  • Training limited to onboarding with no refresher sessions
  • Violations not consistently recorded or enforced
5.11
Return of assets

Recover all organizational assets on exit or role change.

Artefacts an auditor will ask for
  • Asset return checklist
  • Exit interview records
  • Asset inventory update
  • Decommission authorization
Where this commonly fails
  • Missing signatures on return forms
  • Failure to update inventory promptly
  • Inconsistent handling of data‑bearing devices
  • No documented approval for asset disposal
5.12
Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

Artefacts an auditor will ask for
  • Classification policy
  • Classification scheme
  • Labeling guidelines
  • Asset inventory with classification
  • Training records
Where this commonly fails
  • Classification levels not aligned with business impact
  • Inconsistent labeling across departments
  • Missing periodic review of classifications
  • Unclear ownership for classification decisions
5.13
Labelling of information

Label information consistently with the classification scheme so handling rules can follow it.

Artefacts an auditor will ask for
  • Labeling policy
  • Classification scheme
  • Label application log
  • Labelled asset inventory
  • Awareness training records
Where this commonly fails
  • Labels applied inconsistently across departments
  • No evidence of periodic review of label assignments
  • Reliance on manual labeling without automation controls
  • Training not linked to labeling responsibilities
5.14
Information transfer

Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.

Artefacts an auditor will ask for
  • Transfer policy
  • Transfer agreements
  • Transfer procedures
  • Transfer logs
  • Training records
Where this commonly fails
  • Reliance on informal verbal agreements
  • Missing logs for ad-hoc transfers
  • No periodic review of transfer agreements
  • Inconsistent application across business units
5.15
Access control

Set rules for physical and logical access based on business and security requirements.

Artefacts an auditor will ask for
  • Physical access policy
  • Logical access policy
  • Access rights review
  • Privileged account management
Where this commonly fails
  • Infrequent review of access rights
  • Missing documentation for temporary access
  • Overly broad role definitions
  • Inadequate segregation of duties enforcement
5.16
Identity management

Manage the full life cycle of identities.

Artefacts an auditor will ask for
  • User provisioning workflow
  • Identity repository records
  • Access revocation logs
  • Privileged account review
  • Role assignment matrix
Where this commonly fails
  • relying on manual spreadsheets for provisioning
  • infrequent review of privileged accounts
  • missing documentation of deprovisioning steps
  • inconsistent role definitions across systems
5.17
Authentication information

Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.

Artefacts an auditor will ask for
  • Password policy
  • Secret inventory
  • User training records
  • Access review logs
Where this commonly fails
  • Policies exist but not enforced
  • No centralized inventory of secrets
  • Training not documented or infrequent
  • Access reviews are superficial or outdated
5.18
Access rights

Provision, review, modify and remove access rights in line with the access control policy.

Artefacts an auditor will ask for
  • Access provision records
  • Access review reports
  • Access revocation logs
  • Role definition documents
Where this commonly fails
  • Reviews lack documented corrective actions
  • Access changes not tied to approved request workflow
  • Legacy accounts remain active after employee departure
  • Role definitions not updated to reflect current business processes
5.19
Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Artefacts an auditor will ask for
  • Supplier risk assessment
  • Contractual security requirements
  • Supplier security monitoring
  • Supplier incident management
Where this commonly fails
  • Treating all suppliers as low risk
  • Missing security clauses in contracts
  • Insufficient ongoing monitoring of supplier security
  • No documented breach notification process
5.2
Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

Artefacts an auditor will ask for
  • Role definitions
  • Responsibility matrix
  • Assignment records
  • Authority delegation
Where this commonly fails
  • Roles not updated after staff changes
  • No documented acceptance of responsibilities
  • Unclear separation between ownership and operational duties
  • Delegated authority not reflected in policy documents
5.20
Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Artefacts an auditor will ask for
  • Contract security clauses
  • Supplier risk assessment
  • Security incident reporting
  • Performance monitoring reports
  • Contract termination provisions
Where this commonly fails
  • missing explicit security clauses
  • no documented risk assessment before onboarding
  • lack of ongoing monitoring evidence
  • inadequate incident reporting procedures
5.21
Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Artefacts an auditor will ask for
  • Supplier security requirements
  • Contractual security clauses
  • Supply chain risk assessments
  • Supplier audit reports
  • Incident response collaboration
Where this commonly fails
  • Treating supplier security as one-off check
  • Missing contractual security clauses
  • No ongoing monitoring of supplier performance
  • Insufficient evidence of incident coordination
5.22
Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Artefacts an auditor will ask for
  • Supplier security monitoring reports
  • Supplier service review meetings
  • Supplier change management records
  • Supplier contractual compliance evidence
Where this commonly fails
  • relying on informal verbal updates
  • missing documented approval for supplier changes
  • infrequent or ad‑hoc monitoring
  • no evidence linking monitoring to risk treatment
5.23
Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Artefacts an auditor will ask for
  • Cloud service selection
  • Cloud contract management
  • Cloud security monitoring
  • Cloud exit plan
Where this commonly fails
  • Relying solely on provider's security assurances
  • No documented exit or data migration procedures
  • Insufficient risk assessment before cloud onboarding
  • Contracts missing specific security and audit clauses
5.24
Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Artefacts an auditor will ask for
  • Incident response plan
  • Role assignment matrix
  • Training and awareness records
  • Exercise and testing reports
  • Communication procedure documents
Where this commonly fails
  • roles are defined but not formally assigned or approved
  • plans are outdated and lack version control
  • testing is infrequent or only documented without evidence
  • communication templates are missing or not reviewed
5.25
Assessment and decision on information security events

Triage security events and decide which become incidents.

Artefacts an auditor will ask for
  • Event triage workflow
  • Incident decision log
  • Classification criteria
  • Escalation procedure
Where this commonly fails
  • no documented triage steps
  • decisions not recorded or lack timestamps
  • classification criteria outdated or missing
  • escalation contacts not kept current
5.26
Response to information security incidents

Respond to incidents according to the documented procedures.

Artefacts an auditor will ask for
  • Incident response plan
  • Incident handling records
  • Post incident analysis
  • Stakeholder communication
Where this commonly fails
  • Plans not tested regularly
  • Incident logs incomplete or inconsistent
  • No formal post‑incident review process
  • Communication with affected parties delayed
5.27
Learning from information security incidents

Feed lessons from incidents back into stronger controls.

Artefacts an auditor will ask for
  • Incident root cause reports
  • Post incident review minutes
  • Corrective action records
  • Lessons learned repository
Where this commonly fails
  • Root cause analysis limited to symptoms
  • No formal tracking of corrective actions
  • Lessons not shared beyond IT team
  • Updates to policies delayed
5.28
Collection of evidence

Have procedures to identify, collect, acquire and preserve evidence related to security events.

Artefacts an auditor will ask for
  • Evidence collection policy
  • Incident response log
  • Forensic preservation report
  • Chain of custody form
Where this commonly fails
  • Procedures not aligned with legal requirements
  • Missing documented chain of custody
  • Inconsistent preservation of volatile data
  • Lack of regular review and testing of evidence collection process
5.29
Information security during disruption

Plan how to keep information security at the right level during disruption.

Artefacts an auditor will ask for
  • Disruption security plan
  • Business continuity test reports
  • Security control adjustment log
  • Incident communication records
Where this commonly fails
  • Plans not updated after tests
  • Missing documented approval for temporary control changes
  • Insufficient evidence of communication with external parties
  • Reliance on informal procedures only
5.3
Segregation of duties

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

Artefacts an auditor will ask for
  • Role separation matrix
  • Approval workflow records
  • Access rights review reports
  • Segregation conflict log
Where this commonly fails
  • Combining conflicting roles in small teams
  • Lack of documented exceptions
  • Infrequent access rights reviews
  • Reliance on informal approvals
5.30
ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

Artefacts an auditor will ask for
  • Ict continuity plan
  • Readiness test results
  • Resource allocation records
  • Simulation exercise reports
Where this commonly fails
  • Testing frequency not aligned with risk
  • Plans not updated after infrastructure changes
  • Insufficient documentation of test outcomes
  • Lack of coordination with third‑party providers
5.31
Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Artefacts an auditor will ask for
  • Legal register
  • Contractual obligations
  • Regulatory filing records
  • Privacy impact assessments
Where this commonly fails
  • outdated legal register
  • missing security clauses in contracts
  • no documented process for regulatory monitoring
  • incomplete privacy impact assessments
5.32
Intellectual property rights

Implement procedures to protect intellectual property and respect licensing.

Artefacts an auditor will ask for
  • Software license inventory
  • Ip protection policies
  • Third party agreements
  • Training records
  • Incident reports
Where this commonly fails
  • Missing up-to-date license inventory
  • No documented process for reviewing third-party contracts
  • Inadequate employee training on IP obligations
  • Failure to record IP breach incidents
5.33
Protection of records

Protect records from loss, destruction, falsification, unauthorized access and unauthorized release.

Artefacts an auditor will ask for
  • Record retention policy
  • Access control logs
  • Backup and recovery procedures
  • Media disposal records
  • Integrity verification reports
Where this commonly fails
  • retention schedules not aligned with legal requirements
  • inadequate logging of physical record access
  • backups stored without segregation from production
  • absence of documented media sanitization evidence
5.34
Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Artefacts an auditor will ask for
  • Privacy policy
  • Data inventory
  • Processing agreements
  • Breach records
Where this commonly fails
  • Missing documented consent for all data subjects
  • Incomplete inventory of PII across legacy systems
  • No formal review of third‑party processing agreements
  • Inadequate breach notification timelines
5.35
Independent review of information security

Have the security approach and its implementation reviewed independently on a cadence and after significant change.

Artefacts an auditor will ask for
  • Review schedule
  • Review reports
  • Reviewer independence
  • Change trigger log
Where this commonly fails
  • reviews performed by internal staff only
  • infrequent or ad-hoc review cadence
  • lack of documented reviewer independence
  • findings not tracked to remediation
5.36
Compliance with policies, rules and standards for information security

Regularly check that people actually comply with the security policies, rules and standards.

Artefacts an auditor will ask for
  • Policy compliance audits
  • Employee acknowledgement records
  • Exception handling logs
  • Monitoring reports
Where this commonly fails
  • Irregular or ad-hoc compliance checks
  • Missing evidence of employee acknowledgment
  • No formal process for policy exceptions
  • Reliance on self-reported compliance without independent verification
5.37
Documented operating procedures

Document operating procedures for information processing facilities and make them available to those who need them.

Artefacts an auditor will ask for
  • Operating procedure manuals
  • Procedure distribution records
  • Procedure revision history
  • Access control logs
Where this commonly fails
  • outdated procedures still in use
  • no evidence of distribution to staff
  • missing version control for revisions
  • procedures not aligned with actual practice
5.4
Management responsibilities

Require every staff member to actually apply the policies and procedures, not just acknowledge them.

Artefacts an auditor will ask for
  • Policy acknowledgement records
  • Training and competence records
  • Procedure execution logs
  • Supervisory compliance reviews
Where this commonly fails
  • Relying on one‑time acknowledgment without ongoing verification
  • Missing records of actual policy execution
  • No supervisory follow‑up on compliance
  • Training not linked to specific policy responsibilities
5.5
Contact with authorities

Keep working relationships with regulators, law enforcement and CERTs before you need them.

Artefacts an auditor will ask for
  • Authority contact register
  • Formal agreements
  • Incident response coordination
  • Awareness and training
Where this commonly fails
  • Contact list not kept current
  • No formal agreements with authorities
  • Lack of documented coordination during incidents
  • Training not covering authority interaction
5.6
Contact with special interest groups

Stay plugged into security forums and specialist groups for early warning and shared practice.

Artefacts an auditor will ask for
  • Group memberships
  • Participation logs
  • Information sharing records
  • Risk update reports
Where this commonly fails
  • Memberships not documented
  • Participation limited to passive receipt of emails
  • No evidence of internal use of shared information
  • Updates not linked to risk assessments
5.7
Threat intelligence

Collect and analyse threat information and turn it into decisions, not just unread feeds.

Artefacts an auditor will ask for
  • Threat feed subscriptions
  • Threat intel analysis reports
  • Decision making records
  • Intelligence sharing logs
Where this commonly fails
  • Collecting feeds without validation
  • No documented process linking intel to decisions
  • Reliance on a single source
  • Failure to retain analysis artifacts
5.8
Information security in project management

Bake security requirements into every project from initiation, whatever the delivery method.

Artefacts an auditor will ask for
  • Project security requirements
  • Project risk assessment
  • Design and implementation reviews
  • Change and issue management
  • Project closure security evidence
Where this commonly fails
  • Security requirements added after project start
  • Risk assessments not linked to project milestones
  • Design reviews lacking documented security focus
  • Change records missing security impact analysis
5.9
Inventory of information and other associated assets

Maintain a current asset inventory with owners.

Artefacts an auditor will ask for
  • Asset register
  • Ownership assignments
  • Asset change log
  • Asset classification matrix
Where this commonly fails
  • Outdated entries in inventory
  • Missing owner signatures
  • No systematic change tracking
  • Classification not linked to assets

People controls – ISO 27001:2022

6.1
Screening

Background-check candidates and personnel proportional to risk and classification, within the law.

Artefacts an auditor will ask for
  • Screening policy
  • Risk based screening procedures
  • Candidate check records
  • Employee screening logs
  • Third party screening reports
Where this commonly fails
  • One‑size‑fits‑all screening regardless of risk
  • Missing documentation of approvals for exceptions
  • Screening performed without evidence of legal compliance
  • Failure to retain records for required retention period
6.2
Terms and conditions of employment

State the security responsibilities of both the person and the organization in the employment agreement.

Artefacts an auditor will ask for
  • Employment contracts
  • Confidentiality agreements
  • Security awareness acknowledgement
  • Termination procedures
Where this commonly fails
  • missing security clauses in standard contracts
  • no documented employee acknowledgment of policies
  • inconsistent handling of access revocation on termination
6.3
Information security awareness, education and training

Give personnel and relevant parties appropriate, current security training for their role.

Artefacts an auditor will ask for
  • Training program plan
  • Role based training records
  • Attendance logs
  • Training effectiveness reports
Where this commonly fails
  • Training not aligned to specific job functions
  • Content not updated on a regular basis
  • Missing or incomplete attendance documentation
  • No systematic measurement of training impact
6.4
Disciplinary process

Have a formal, communicated disciplinary process for security policy violations.

Artefacts an auditor will ask for
  • Disciplinary policy
  • Violation reporting
  • Sanction log
  • Employee acknowledgement
  • Appeal process
Where this commonly fails
  • Policy exists but not communicated to staff
  • No documented evidence of sanctions applied
  • Lack of formal appeal mechanism
  • Inconsistent record-keeping of violations
6.5
Responsibilities after termination or change of employment

Define and enforce security responsibilities that remain valid after an exit or role change.

Artefacts an auditor will ask for
  • Exit checklist
  • Access revocation records
  • Asset return log
  • Confidentiality nondisclosure acknowledgement
Where this commonly fails
  • Delayed revocation of privileged accounts
  • Incomplete asset collection
  • No documented acknowledgment of ongoing confidentiality duties
  • Reliance on informal verbal handover
6.6
Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

Artefacts an auditor will ask for
  • Nda policy
  • Nda templates
  • Signed nda registry
  • Nda review process
  • Third party nda records
Where this commonly fails
  • NDAs not refreshed when data classification changes
  • Contractor agreements missing required signatures
  • No scheduled review of NDA effectiveness
  • Templates stored on personal drives instead of central repository
6.7
Remote working

Apply security measures when people access, process or store information outside the organization's premises.

Artefacts an auditor will ask for
  • Remote access policy
  • Secure connection mechanisms
  • Endpoint security
  • User awareness training
  • Monitoring and logging
Where this commonly fails
  • Missing MFA for remote access
  • Outdated device security baselines
  • Inconsistent logging of remote sessions
  • Lack of formal remote work policy enforcement
6.8
Information security event reporting

Give people an easy, timely channel to report observed or suspected security events.

Artefacts an auditor will ask for
  • Reporting channel
  • Event submission records
  • Awareness and training
  • Escalation procedure
  • Performance metrics
Where this commonly fails
  • no anonymous reporting option
  • reporting channel not communicated to all staff
  • lack of documented escalation timelines
  • inconsistent logging of reported events

Physical controls – ISO 27001:2022

7.1
Physical security perimeters

Define and use security perimeters to protect areas holding information and assets.

Artefacts an auditor will ask for
  • Perimeter design
  • Access point controls
  • Visitor management
  • Surveillance records
Where this commonly fails
  • outdated floor plans
  • inconsistent access log retention
  • lack of visitor escort verification
  • insufficient CCTV coverage
7.10
Storage media

Manage storage media across acquisition, use, transport and disposal per classification and handling rules.

Artefacts an auditor will ask for
  • Media inventory
  • Media handling procedures
  • Media transport logs
  • Media disposal evidence
Where this commonly fails
  • No documented classification for media
  • Transport logs missing chain-of-custody signatures
  • Disposal performed without verification evidence
  • Media inventory not kept up-to-date
7.11
Supporting utilities

Protect information processing facilities from power failures and other utility disruptions.

Artefacts an auditor will ask for
  • Power backup systems
  • Utility monitoring
  • Maintenance contracts
  • Environmental controls
Where this commonly fails
  • No documented testing of backup power
  • Reliance on single power source without redundancy
  • Outdated maintenance records
  • Missing real-time monitoring alerts
7.12
Cabling security

Protect power and data cabling from interception, interference and damage.

Artefacts an auditor will ask for
  • Cable routing diagrams
  • Physical protection measures
  • Inspection and testing records
  • Access control logs
Where this commonly fails
  • Relying on informal sketches instead of approved diagrams
  • Missing regular physical inspections of cable pathways
  • Inadequate segregation of power and data cables
  • Failure to control and log access to cable distribution points
7.13
Equipment maintenance

Maintain equipment correctly to preserve availability, integrity and confidentiality.

Artefacts an auditor will ask for
  • Maintenance schedule
  • Maintenance logs
  • Calibration records
  • Service contracts
Where this commonly fails
  • no documented maintenance schedule
  • maintenance logs lack timestamps
  • absence of calibration certificates
  • informal repairs without records
7.14
Secure disposal or re-use of equipment

Verify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.

Artefacts an auditor will ask for
  • Disposal records
  • Data wipe logs
  • Asset retirement procedures
  • Software license verification
Where this commonly fails
  • Relying on visual inspection only
  • Missing documentation for third‑party disposal
  • Inconsistent wiping methods across device types
  • Failure to verify license removal before redeployment
7.2
Physical entry

Protect secure areas with appropriate entry controls and access points.

Artefacts an auditor will ask for
  • Entry control policies
  • Visitor log records
  • Access card provisioning
  • Physical barrier records
  • Entry point audit reports
Where this commonly fails
  • Use of informal sign-in sheets instead of controlled logs
  • Failure to promptly remove or update access rights after role changes
  • Lack of documented maintenance for locks and alarm systems
  • Inconsistent enforcement of visitor escort and badge policies
7.3
Securing offices, rooms and facilities

Design and apply physical security for offices, rooms and facilities.

Artefacts an auditor will ask for
  • Physical access control
  • Visitor and contractor management
  • Facility security design
  • Environmental protection measures
Where this commonly fails
  • informal lock checks replace documented maintenance
  • visitor logs missing timestamps or signatures
  • floor plans not updated to reflect current security zones
  • absence of records for lock and alarm system testing
7.4
Physical security monitoring

Continuously monitor premises for unauthorized physical access.

Artefacts an auditor will ask for
  • Cctv logs
  • Access control logs
  • Incident reports
  • Maintenance records
Where this commonly fails
  • logs not retained for required period
  • camera blind spots unaddressed
  • manual log entries not synchronized with electronic records
  • lack of regular testing of alarm systems
7.5
Protecting against physical and environmental threats

Design and apply protection against natural disasters and other physical and environmental threats.

Artefacts an auditor will ask for
  • Risk assessment reports
  • Disaster recovery plans
  • Facility security design
  • Environmental monitoring logs
Where this commonly fails
  • risk assessments not updated after infrastructure changes
  • recovery procedures lack site-specific details
  • physical controls documented but not verified in practice
  • environmental monitoring not integrated with incident response
7.6
Working in secure areas

Design and apply security measures for working in secure areas.

Artefacts an auditor will ask for
  • Area access control
  • Visitor management
  • Physical barriers
  • Monitoring and surveillance
  • Training and awareness
Where this commonly fails
  • informal access permissions used instead of documented controls
  • visitor logs missing key details or not retained
  • surveillance footage retention periods not aligned with policy
  • physical barriers not inspected on a regular schedule
7.7
Clear desk and clear screen

Enforce clear-desk rules for papers and media and clear-screen rules for processing facilities.

Artefacts an auditor will ask for
  • Desk policy
  • Screen lock procedures
  • Media handling records
  • Workspace audit reports
Where this commonly fails
  • Policy exists but not enforced
  • No regular desk inspections
  • Screen lock settings vary across devices
  • Employee awareness not documented
7.8
Equipment siting and protection

Site equipment securely and protect it.

Artefacts an auditor will ask for
  • Site layout plans
  • Environmental controls
  • Physical security measures
  • Maintenance records
Where this commonly fails
  • Assuming perimeter security covers equipment
  • Outdated or missing environmental monitoring data
  • Lack of documented siting criteria
  • Inconsistent access logs for equipment areas
7.9
Security of assets off-premises

Protect assets used or held off-site.

Artefacts an auditor will ask for
  • Offsite asset inventory
  • Transport security procedures
  • Third party agreements
  • Remote storage encryption
  • Asset disposal records
Where this commonly fails
  • Missing offsite asset register
  • Inadequate transport controls
  • No third‑party risk assessments
  • Encryption not verified for remote storage

Technological controls – ISO 27001:2022

8.1
User end point devices

Protect information stored on, processed by or reachable through user endpoints.

Artefacts an auditor will ask for
  • Device inventory
  • Endpoint security settings
  • Encryption and data protection
  • Mobile device management
  • User awareness records
Where this commonly fails
  • Incomplete device inventory
  • Inconsistent encryption enforcement
  • Irregular patching of endpoints
  • Lack of BYOD controls
8.10
Information deletion

Delete information in systems, devices and media when no longer required.

Artefacts an auditor will ask for
  • Deletion policy
  • Media disposal log
  • System deletion audit
  • Data retention schedule
Where this commonly fails
  • Retaining data beyond approved period
  • No evidence of secure erase verification
  • Policies not aligned with actual practice
  • Incomplete media disposal records
8.11
Data masking

Use data masking in line with access policy, business need and applicable law.

Artefacts an auditor will ask for
  • Masking policy
  • Masking rules
  • Implementation logs
  • Access review reports
Where this commonly fails
  • Masking applied inconsistently across data stores
  • Lack of documented justification for masking decisions
  • Failure to review and update masking rules
  • Insufficient monitoring of masking effectiveness
8.12
Data leakage prevention

Apply data leakage prevention to systems and channels handling sensitive information.

Artefacts an auditor will ask for
  • DLP policy
  • DLP solution configuration
  • DLP monitoring reports
  • Incident handling records
  • Employee awareness training
Where this commonly fails
  • Policy not enforced across all data channels
  • DLP rules outdated and misaligned with business processes
  • Insufficient monitoring and alert retention
  • Lack of documented response to DLP incidents
8.13
Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

Artefacts an auditor will ask for
  • Backup policy
  • Backup schedule
  • Backup test reports
  • Retention records
  • Access logs
Where this commonly fails
  • infrequent restore testing
  • missing retention documentation
  • undefined backup responsibilities
  • inconsistent backup verification
8.14
Redundancy of information processing facilities

Build enough redundancy into processing facilities to meet availability requirements.

Artefacts an auditor will ask for
  • Redundancy design
  • Capacity planning
  • Failover testing
  • Maintenance records
Where this commonly fails
  • reliance on undocumented manual backups
  • absence of regular failover drills
  • capacity forecasts not aligned with business growth
  • maintenance activities not tracked centrally
8.15
Logging

Produce, store, protect and analyse logs of activities, exceptions and faults.

Artefacts an auditor will ask for
  • Log collection policy
  • Log storage and protection
  • Log review and analysis
  • Log retention and disposal
Where this commonly fails
  • Inconsistent log collection across systems
  • Insufficient protection of log integrity
  • Irregular or undocumented log review
  • Retention periods not aligned with policy
8.16
Monitoring activities

Monitor networks, systems and applications for anomalies and act on potential incidents.

Artefacts an auditor will ask for
  • Network anomaly detection logs
  • System integrity monitoring reports
  • Application behavior alerts
  • Incident response records
Where this commonly fails
  • alerts not correlated across sources
  • lack of documented response procedures for anomalies
  • insufficient retention of monitoring logs
  • overreliance on manual review
8.17
Clock synchronization

Synchronize system clocks to approved time sources.

Artefacts an auditor will ask for
  • Time source inventory
  • Sync configuration
  • Sync monitoring
  • Deviation response
Where this commonly fails
  • Using unsanctioned public NTP servers
  • No regular verification of time drift
  • Missing documentation of configuration changes
  • Inadequate handling of synchronization failures
8.18
Use of privileged utility programs

Restrict and tightly control utilities that can override system and application controls.

Artefacts an auditor will ask for
  • Privileged tool inventory
  • Utility access logs
  • Privileged account approval
  • Utility usage audit
Where this commonly fails
  • Missing inventory of privileged utilities
  • Logs not centralized or retained
  • Lack of formal approval workflow
  • Infrequent review of utility usage
8.19
Installation of software on operational systems

Securely manage software installation on production systems.

Artefacts an auditor will ask for
  • Installation requests
  • Approval evidence
  • Implementation logs
  • Verification reports
Where this commonly fails
  • Missing formal approval for installations
  • No evidence of post‑install verification
  • Reliance on informal requests instead of documented tickets
  • Failure to update inventory of installed software
8.2
Privileged access rights

Restrict and manage the allocation and use of privileged access.

Artefacts an auditor will ask for
  • Privileged account inventory
  • Privileged access approval
  • Privileged access review
  • Privileged access logging
Where this commonly fails
  • Outdated privileged account inventory
  • Missing or informal approval documentation
  • Infrequent or superficial access reviews
  • Privileged activity logs not retained or insufficiently protected
8.20
Networks security

Secure, manage and control networks and network devices.

Artefacts an auditor will ask for
  • Network topology diagrams
  • Firewall rule sets
  • Network access control lists
  • Wireless security configurations
Where this commonly fails
  • outdated topology diagrams
  • inconsistent firewall rule documentation
  • missing periodic review of ACLs
  • weak wireless encryption settings
8.21
Security of network services

Identify, implement and monitor security mechanisms and service levels for network services.

Artefacts an auditor will ask for
  • Network service inventory
  • Service security configurations
  • Monitoring and logging
  • Service level agreements
  • Change management records
Where this commonly fails
  • Out‑of‑date service inventory missing recent cloud assets
  • Log retention periods shorter than required for forensic analysis
  • SLA compliance not verified against actual performance data
  • Configuration drift not tracked leading to undocumented rule changes
8.22
Segregation of networks

Segregate groups of services, users and systems in the network.

Artefacts an auditor will ask for
  • Network segmentation policy
  • Network topology diagrams
  • Firewall rule set documents
  • Segregation testing reports
Where this commonly fails
  • Informal or outdated network maps used instead of documented diagrams
  • Inconsistent VLAN tagging and naming across locations
  • Exceptions to segmentation not recorded or approved
  • Segregation controls rarely tested after changes
8.23
Web filtering

Manage access to external websites to reduce exposure to malicious content.

Artefacts an auditor will ask for
  • Filter policy
  • Category rules
  • Proxy logs
  • Exception requests
  • Awareness training
Where this commonly fails
  • Outdated URL category lists
  • Insufficient logging retention
  • No documented exception process
  • Lack of periodic policy review
8.24
Use of cryptography

Define and implement rules for effective use of cryptography and key management.

Artefacts an auditor will ask for
  • Encryption policy
  • Key management procedures
  • Algorithm inventory
  • Key usage records
Where this commonly fails
  • Missing documented key lifecycle
  • Use of outdated or weak algorithms
  • Inadequate segregation of duties for key handling
  • Lack of regular key rotation evidence
8.25
Secure development life cycle

Establish and apply rules for secure development of software and systems.

Artefacts an auditor will ask for
  • Secure dev policy
  • Threat modeling artifacts
  • Code review logs
  • Security testing reports
Where this commonly fails
  • Policy exists but not enforced
  • Threat models not updated for new features
  • Code reviews performed inconsistently
  • Security testing limited to final release
8.26
Application security requirements

Identify, specify and approve security requirements when developing or acquiring applications.

Artefacts an auditor will ask for
  • Security requirements spec
  • Requirement approval records
  • Development process integration
  • Third party application requirements
Where this commonly fails
  • Security requirements not formally approved
  • Missing requirements for third‑party components
  • No traceability between requirements and implemented controls
  • Outdated or incomplete threat modeling
8.27
Secure system architecture and engineering principles

Establish and apply secure engineering principles to system development.

Artefacts an auditor will ask for
  • System architecture documents
  • Secure design guidelines
  • Threat modeling artifacts
  • Security testing reports
  • Change control records
Where this commonly fails
  • Design reviews not documented
  • Threat modeling performed sporadically
  • Secure coding standards not enforced
  • Testing results not linked to remediation
8.28
Secure coding

Apply secure coding principles to software development.

Artefacts an auditor will ask for
  • Secure coding policy
  • Developer training records
  • Code review logs
  • Static analysis reports
  • Vulnerability mitigation records
Where this commonly fails
  • inconsistent application of coding standards
  • lack of documented review evidence
  • reliance on manual testing only
  • missing tracking of remediation actions
8.29
Security testing in development and acceptance

Define and run security testing across the development life cycle.

Artefacts an auditor will ask for
  • Security test plan
  • Test execution reports
  • Vulnerability remediation log
  • Acceptance criteria records
Where this commonly fails
  • testing only after release
  • inconsistent test coverage across modules
  • lack of documented remediation evidence
  • no formal acceptance signoff
8.3
Information access restriction

Restrict access to information and assets per the access control policy.

Artefacts an auditor will ask for
  • Access control policy
  • Role based access matrix
  • User access review reports
  • Privileged account logs
  • Termination access revocation records
Where this commonly fails
  • infrequent or missing access reviews
  • roles not aligned with actual job responsibilities
  • privileged activity not captured in a central log
  • termination revocation steps not documented
8.30
Outsourced development

Direct, monitor and review outsourced system development.

Artefacts an auditor will ask for
  • Outsourced development contracts
  • Vendor security assessments
  • Development process monitoring
  • Deliverable acceptance records
Where this commonly fails
  • contracts lack specific security obligations
  • no ongoing monitoring of vendor performance
  • insufficient evidence of code security testing
  • reliance on vendor assurances without independent verification
8.31
Separation of development, test and production environments

Separate and secure development, test and production environments.

Artefacts an auditor will ask for
  • Environment separation policy
  • Network segmentation diagram
  • Access control matrix
  • Change and deployment logs
Where this commonly fails
  • Policies exist but are not enforced
  • Shared credentials across environments
  • Insufficient network isolation between zones
  • Missing audit trails for environment changes
8.32
Change management

Put changes to facilities and systems through change management procedures.

Artefacts an auditor will ask for
  • Change requests
  • Change approvals
  • Implementation testing
  • Post implementation reviews
Where this commonly fails
  • missing formal approval
  • no rollback plan documented
  • testing performed after production deployment
  • change records not linked to assets
8.33
Test information

Select, protect and manage test information appropriately.

Artefacts an auditor will ask for
  • Test data classification
  • Test data access controls
  • Test data retention and disposal
  • Test data encryption
Where this commonly fails
  • Treating test data like production data without classification
  • Granting broad access to test data without documented approvals
  • Retaining test data far beyond its purpose
  • Failing to encrypt test data in non-production environments
8.34
Protection of information systems during audit testing

Plan and agree audit tests on operational systems with management to avoid disruption.

Artefacts an auditor will ask for
  • Test plan approval
  • Stakeholder agreement
  • Risk assessment testing
  • Change control notifications
  • Post test review
Where this commonly fails
  • testing conducted without documented management signoff
  • failure to assess and document risk before testing
  • lack of communication to operations leading to unexpected outages
  • no post-test review or lessons learned captured
8.4
Access to source code

Appropriately manage read and write access to source code, development tools and libraries.

Artefacts an auditor will ask for
  • Repository access controls
  • Development tool access
  • Library dependency controls
  • Change approval records
Where this commonly fails
  • shared accounts used for source code repositories
  • permissions not reviewed on a regular basis
  • third‑party library approvals undocumented
  • insufficient logging of code change activities
8.5
Secure authentication

Implement authentication technologies and procedures based on access restrictions and policy.

Artefacts an auditor will ask for
  • Auth policy
  • Credential provisioning
  • MFA implementation
  • Access log monitoring
  • Privileged account controls
Where this commonly fails
  • Reliance on static passwords only
  • Inconsistent MFA enforcement across systems
  • No periodic review of authentication logs
  • Missing documentation of credential lifecycle
8.6
Capacity management

Monitor and tune resource use against current and expected capacity needs.

Artefacts an auditor will ask for
  • Capacity planning reports
  • Utilization metrics
  • Forecasting models
  • Tuning action logs
Where this commonly fails
  • relying on manual spreadsheets only
  • no regular review schedule
  • failure to link forecasts with business growth plans
  • ignoring seasonal usage patterns
8.7
Protection against malware

Implement malware protection backed by user awareness.

Artefacts an auditor will ask for
  • Anti malware policy
  • Endpoint protection
  • User awareness program
  • Malware incident handling
Where this commonly fails
  • Outdated malware signatures not regularly updated
  • Training limited to annual sessions
  • No documented process for malware incident escalation
  • Inconsistent endpoint protection across device types
8.8
Management of technical vulnerabilities

Obtain vulnerability information, evaluate exposure, and take appropriate remediation.

Artefacts an auditor will ask for
  • Vulnerability feed logs
  • Risk assessment reports
  • Remediation ticket records
  • Patch deployment evidence
Where this commonly fails
  • Relying on ad-hoc scans only
  • Missing documented risk ranking for vulnerabilities
  • No evidence of timely remediation verification
  • Failure to retain proof of feed subscription
8.9
Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

Artefacts an auditor will ask for
  • Baseline configurations
  • Change control records
  • Configuration audit reports
  • Secure hardening guidelines
  • Deviation approvals
Where this commonly fails
  • outdated baselines
  • missing change approvals
  • infrequent configuration audits
  • unauthorized deviations not documented
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27001:2022 framework page.