ISO 27001:2022
Evidence request list. 100 controls, 100 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Clause 0 – ISO 27001:2022
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
Clause 9 – ISO 27001:2022
Conduct internal audits of the information security management system at planned intervals, to establish whether it conforms both to the organisation's own requirements and to the requirements of this document, and whether it is effectively implemented and maintained.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, taking account of the importance of the processes concerned and the results of previous audits. Define the criteria and scope of each audit, select auditors and conduct audits in a way that ensures objectivity and impartiality of the audit process, report results to relevant management, and retain documented information as evidence of the programme and the results.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
Top management shall review the organisation's information security management system at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
The management review shall consider the status of actions from previous reviews, changes in external and internal issues relevant to the management system, changes in the needs and expectations of interested parties, feedback on information security performance including trends in nonconformities and corrective actions, monitoring and measurement results, audit results and fulfilment of information security objectives, feedback from interested parties, results of risk assessment and the status of the risk treatment plan, and opportunities for continual improvement.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
The results of the management review shall include decisions related to continual improvement opportunities and to any need for changes to the information security management system. Documented information shall be retained as evidence of the results of management reviews.
- ISMS scope
- Statement of applicability
- Risk assessment
- Risk treatment
- Policies
- Competence records
- Internal audit
- Management review
- SoA exists but exclusion justifications are boilerplate without evidence of analysis.
- Risk assessment performed annually with no update on material change.
- Internal audit programme exists but findings closed without effectiveness verification.
- Management review minutes lack documented decisions on risk treatment.
Organizational controls – ISO 27001:2022
Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
- Security policy document
- Policy approval records
- Policy distribution log
- Policy review schedule
- Policy change records
- Policies not formally approved by senior management
- No evidence of distribution or employee acknowledgment
- Review dates not documented or missed
- Version control missing, leading to outdated policies
Define and enforce rules for how information and assets may be used and handled.
- Acceptable use policy
- User acknowledgement records
- Training records
- Enforcement logs
- Policy not reviewed or updated regularly
- Missing documented employee acknowledgments
- Training limited to onboarding with no refresher sessions
- Violations not consistently recorded or enforced
Recover all organizational assets on exit or role change.
- Asset return checklist
- Exit interview records
- Asset inventory update
- Decommission authorization
- Missing signatures on return forms
- Failure to update inventory promptly
- Inconsistent handling of data‑bearing devices
- No documented approval for asset disposal
Classify information by confidentiality, integrity, availability and interested-party requirements.
- Classification policy
- Classification scheme
- Labeling guidelines
- Asset inventory with classification
- Training records
- Classification levels not aligned with business impact
- Inconsistent labeling across departments
- Missing periodic review of classifications
- Unclear ownership for classification decisions
Label information consistently with the classification scheme so handling rules can follow it.
- Labeling policy
- Classification scheme
- Label application log
- Labelled asset inventory
- Awareness training records
- Labels applied inconsistently across departments
- No evidence of periodic review of label assignments
- Reliance on manual labeling without automation controls
- Training not linked to labeling responsibilities
Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.
- Transfer policy
- Transfer agreements
- Transfer procedures
- Transfer logs
- Training records
- Reliance on informal verbal agreements
- Missing logs for ad-hoc transfers
- No periodic review of transfer agreements
- Inconsistent application across business units
Set rules for physical and logical access based on business and security requirements.
- Physical access policy
- Logical access policy
- Access rights review
- Privileged account management
- Infrequent review of access rights
- Missing documentation for temporary access
- Overly broad role definitions
- Inadequate segregation of duties enforcement
Manage the full life cycle of identities.
- User provisioning workflow
- Identity repository records
- Access revocation logs
- Privileged account review
- Role assignment matrix
- relying on manual spreadsheets for provisioning
- infrequent review of privileged accounts
- missing documentation of deprovisioning steps
- inconsistent role definitions across systems
Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
- Password policy
- Secret inventory
- User training records
- Access review logs
- Policies exist but not enforced
- No centralized inventory of secrets
- Training not documented or infrequent
- Access reviews are superficial or outdated
Provision, review, modify and remove access rights in line with the access control policy.
- Access provision records
- Access review reports
- Access revocation logs
- Role definition documents
- Reviews lack documented corrective actions
- Access changes not tied to approved request workflow
- Legacy accounts remain active after employee departure
- Role definitions not updated to reflect current business processes
Define and apply processes to manage the security risk suppliers introduce.
- Supplier risk assessment
- Contractual security requirements
- Supplier security monitoring
- Supplier incident management
- Treating all suppliers as low risk
- Missing security clauses in contracts
- Insufficient ongoing monitoring of supplier security
- No documented breach notification process
Name who owns what in security and make the allocation explicit and traceable.
- Role definitions
- Responsibility matrix
- Assignment records
- Authority delegation
- Roles not updated after staff changes
- No documented acceptance of responsibilities
- Unclear separation between ownership and operational duties
- Delegated authority not reflected in policy documents
Establish and agree the relevant security requirements in each supplier contract.
- Contract security clauses
- Supplier risk assessment
- Security incident reporting
- Performance monitoring reports
- Contract termination provisions
- missing explicit security clauses
- no documented risk assessment before onboarding
- lack of ongoing monitoring evidence
- inadequate incident reporting procedures
Extend security requirements down the ICT products and services supply chain.
- Supplier security requirements
- Contractual security clauses
- Supply chain risk assessments
- Supplier audit reports
- Incident response collaboration
- Treating supplier security as one-off check
- Missing contractual security clauses
- No ongoing monitoring of supplier performance
- Insufficient evidence of incident coordination
Regularly monitor, review and manage change in supplier security practice and service delivery.
- Supplier security monitoring reports
- Supplier service review meetings
- Supplier change management records
- Supplier contractual compliance evidence
- relying on informal verbal updates
- missing documented approval for supplier changes
- infrequent or ad‑hoc monitoring
- no evidence linking monitoring to risk treatment
Govern acquisition, use, management and exit of cloud services against your security requirements.
- Cloud service selection
- Cloud contract management
- Cloud security monitoring
- Cloud exit plan
- Relying solely on provider's security assurances
- No documented exit or data migration procedures
- Insufficient risk assessment before cloud onboarding
- Contracts missing specific security and audit clauses
Define incident roles, processes and readiness before an incident happens.
- Incident response plan
- Role assignment matrix
- Training and awareness records
- Exercise and testing reports
- Communication procedure documents
- roles are defined but not formally assigned or approved
- plans are outdated and lack version control
- testing is infrequent or only documented without evidence
- communication templates are missing or not reviewed
Triage security events and decide which become incidents.
- Event triage workflow
- Incident decision log
- Classification criteria
- Escalation procedure
- no documented triage steps
- decisions not recorded or lack timestamps
- classification criteria outdated or missing
- escalation contacts not kept current
Respond to incidents according to the documented procedures.
- Incident response plan
- Incident handling records
- Post incident analysis
- Stakeholder communication
- Plans not tested regularly
- Incident logs incomplete or inconsistent
- No formal post‑incident review process
- Communication with affected parties delayed
Feed lessons from incidents back into stronger controls.
- Incident root cause reports
- Post incident review minutes
- Corrective action records
- Lessons learned repository
- Root cause analysis limited to symptoms
- No formal tracking of corrective actions
- Lessons not shared beyond IT team
- Updates to policies delayed
Have procedures to identify, collect, acquire and preserve evidence related to security events.
- Evidence collection policy
- Incident response log
- Forensic preservation report
- Chain of custody form
- Procedures not aligned with legal requirements
- Missing documented chain of custody
- Inconsistent preservation of volatile data
- Lack of regular review and testing of evidence collection process
Plan how to keep information security at the right level during disruption.
- Disruption security plan
- Business continuity test reports
- Security control adjustment log
- Incident communication records
- Plans not updated after tests
- Missing documented approval for temporary control changes
- Insufficient evidence of communication with external parties
- Reliance on informal procedures only
Split conflicting duties so no single person can run a sensitive process end to end unchecked.
- Role separation matrix
- Approval workflow records
- Access rights review reports
- Segregation conflict log
- Combining conflicting roles in small teams
- Lack of documented exceptions
- Infrequent access rights reviews
- Reliance on informal approvals
Plan, implement, maintain and test ICT readiness against business continuity objectives.
- Ict continuity plan
- Readiness test results
- Resource allocation records
- Simulation exercise reports
- Testing frequency not aligned with risk
- Plans not updated after infrastructure changes
- Insufficient documentation of test outcomes
- Lack of coordination with third‑party providers
Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
- Legal register
- Contractual obligations
- Regulatory filing records
- Privacy impact assessments
- outdated legal register
- missing security clauses in contracts
- no documented process for regulatory monitoring
- incomplete privacy impact assessments
Implement procedures to protect intellectual property and respect licensing.
- Software license inventory
- Ip protection policies
- Third party agreements
- Training records
- Incident reports
- Missing up-to-date license inventory
- No documented process for reviewing third-party contracts
- Inadequate employee training on IP obligations
- Failure to record IP breach incidents
Protect records from loss, destruction, falsification, unauthorized access and unauthorized release.
- Record retention policy
- Access control logs
- Backup and recovery procedures
- Media disposal records
- Integrity verification reports
- retention schedules not aligned with legal requirements
- inadequate logging of physical record access
- backups stored without segregation from production
- absence of documented media sanitization evidence
Identify and meet privacy and PII-protection requirements from law, regulation and contract.
- Privacy policy
- Data inventory
- Processing agreements
- Breach records
- Missing documented consent for all data subjects
- Incomplete inventory of PII across legacy systems
- No formal review of third‑party processing agreements
- Inadequate breach notification timelines
Have the security approach and its implementation reviewed independently on a cadence and after significant change.
- Review schedule
- Review reports
- Reviewer independence
- Change trigger log
- reviews performed by internal staff only
- infrequent or ad-hoc review cadence
- lack of documented reviewer independence
- findings not tracked to remediation
Regularly check that people actually comply with the security policies, rules and standards.
- Policy compliance audits
- Employee acknowledgement records
- Exception handling logs
- Monitoring reports
- Irregular or ad-hoc compliance checks
- Missing evidence of employee acknowledgment
- No formal process for policy exceptions
- Reliance on self-reported compliance without independent verification
Document operating procedures for information processing facilities and make them available to those who need them.
- Operating procedure manuals
- Procedure distribution records
- Procedure revision history
- Access control logs
- outdated procedures still in use
- no evidence of distribution to staff
- missing version control for revisions
- procedures not aligned with actual practice
Require every staff member to actually apply the policies and procedures, not just acknowledge them.
- Policy acknowledgement records
- Training and competence records
- Procedure execution logs
- Supervisory compliance reviews
- Relying on one‑time acknowledgment without ongoing verification
- Missing records of actual policy execution
- No supervisory follow‑up on compliance
- Training not linked to specific policy responsibilities
Keep working relationships with regulators, law enforcement and CERTs before you need them.
- Authority contact register
- Formal agreements
- Incident response coordination
- Awareness and training
- Contact list not kept current
- No formal agreements with authorities
- Lack of documented coordination during incidents
- Training not covering authority interaction
Stay plugged into security forums and specialist groups for early warning and shared practice.
- Group memberships
- Participation logs
- Information sharing records
- Risk update reports
- Memberships not documented
- Participation limited to passive receipt of emails
- No evidence of internal use of shared information
- Updates not linked to risk assessments
Collect and analyse threat information and turn it into decisions, not just unread feeds.
- Threat feed subscriptions
- Threat intel analysis reports
- Decision making records
- Intelligence sharing logs
- Collecting feeds without validation
- No documented process linking intel to decisions
- Reliance on a single source
- Failure to retain analysis artifacts
Bake security requirements into every project from initiation, whatever the delivery method.
- Project security requirements
- Project risk assessment
- Design and implementation reviews
- Change and issue management
- Project closure security evidence
- Security requirements added after project start
- Risk assessments not linked to project milestones
- Design reviews lacking documented security focus
- Change records missing security impact analysis
Maintain a current asset inventory with owners.
- Asset register
- Ownership assignments
- Asset change log
- Asset classification matrix
- Outdated entries in inventory
- Missing owner signatures
- No systematic change tracking
- Classification not linked to assets
People controls – ISO 27001:2022
Background-check candidates and personnel proportional to risk and classification, within the law.
- Screening policy
- Risk based screening procedures
- Candidate check records
- Employee screening logs
- Third party screening reports
- One‑size‑fits‑all screening regardless of risk
- Missing documentation of approvals for exceptions
- Screening performed without evidence of legal compliance
- Failure to retain records for required retention period
State the security responsibilities of both the person and the organization in the employment agreement.
- Employment contracts
- Confidentiality agreements
- Security awareness acknowledgement
- Termination procedures
- missing security clauses in standard contracts
- no documented employee acknowledgment of policies
- inconsistent handling of access revocation on termination
Give personnel and relevant parties appropriate, current security training for their role.
- Training program plan
- Role based training records
- Attendance logs
- Training effectiveness reports
- Training not aligned to specific job functions
- Content not updated on a regular basis
- Missing or incomplete attendance documentation
- No systematic measurement of training impact
Have a formal, communicated disciplinary process for security policy violations.
- Disciplinary policy
- Violation reporting
- Sanction log
- Employee acknowledgement
- Appeal process
- Policy exists but not communicated to staff
- No documented evidence of sanctions applied
- Lack of formal appeal mechanism
- Inconsistent record-keeping of violations
Define and enforce security responsibilities that remain valid after an exit or role change.
- Exit checklist
- Access revocation records
- Asset return log
- Confidentiality nondisclosure acknowledgement
- Delayed revocation of privileged accounts
- Incomplete asset collection
- No documented acknowledgment of ongoing confidentiality duties
- Reliance on informal verbal handover
Identify, document, review and sign NDAs that reflect the organization's protection needs.
- Nda policy
- Nda templates
- Signed nda registry
- Nda review process
- Third party nda records
- NDAs not refreshed when data classification changes
- Contractor agreements missing required signatures
- No scheduled review of NDA effectiveness
- Templates stored on personal drives instead of central repository
Apply security measures when people access, process or store information outside the organization's premises.
- Remote access policy
- Secure connection mechanisms
- Endpoint security
- User awareness training
- Monitoring and logging
- Missing MFA for remote access
- Outdated device security baselines
- Inconsistent logging of remote sessions
- Lack of formal remote work policy enforcement
Give people an easy, timely channel to report observed or suspected security events.
- Reporting channel
- Event submission records
- Awareness and training
- Escalation procedure
- Performance metrics
- no anonymous reporting option
- reporting channel not communicated to all staff
- lack of documented escalation timelines
- inconsistent logging of reported events
Physical controls – ISO 27001:2022
Define and use security perimeters to protect areas holding information and assets.
- Perimeter design
- Access point controls
- Visitor management
- Surveillance records
- outdated floor plans
- inconsistent access log retention
- lack of visitor escort verification
- insufficient CCTV coverage
Manage storage media across acquisition, use, transport and disposal per classification and handling rules.
- Media inventory
- Media handling procedures
- Media transport logs
- Media disposal evidence
- No documented classification for media
- Transport logs missing chain-of-custody signatures
- Disposal performed without verification evidence
- Media inventory not kept up-to-date
Protect information processing facilities from power failures and other utility disruptions.
- Power backup systems
- Utility monitoring
- Maintenance contracts
- Environmental controls
- No documented testing of backup power
- Reliance on single power source without redundancy
- Outdated maintenance records
- Missing real-time monitoring alerts
Protect power and data cabling from interception, interference and damage.
- Cable routing diagrams
- Physical protection measures
- Inspection and testing records
- Access control logs
- Relying on informal sketches instead of approved diagrams
- Missing regular physical inspections of cable pathways
- Inadequate segregation of power and data cables
- Failure to control and log access to cable distribution points
Maintain equipment correctly to preserve availability, integrity and confidentiality.
- Maintenance schedule
- Maintenance logs
- Calibration records
- Service contracts
- no documented maintenance schedule
- maintenance logs lack timestamps
- absence of calibration certificates
- informal repairs without records
Verify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
- Disposal records
- Data wipe logs
- Asset retirement procedures
- Software license verification
- Relying on visual inspection only
- Missing documentation for third‑party disposal
- Inconsistent wiping methods across device types
- Failure to verify license removal before redeployment
Protect secure areas with appropriate entry controls and access points.
- Entry control policies
- Visitor log records
- Access card provisioning
- Physical barrier records
- Entry point audit reports
- Use of informal sign-in sheets instead of controlled logs
- Failure to promptly remove or update access rights after role changes
- Lack of documented maintenance for locks and alarm systems
- Inconsistent enforcement of visitor escort and badge policies
Design and apply physical security for offices, rooms and facilities.
- Physical access control
- Visitor and contractor management
- Facility security design
- Environmental protection measures
- informal lock checks replace documented maintenance
- visitor logs missing timestamps or signatures
- floor plans not updated to reflect current security zones
- absence of records for lock and alarm system testing
Continuously monitor premises for unauthorized physical access.
- Cctv logs
- Access control logs
- Incident reports
- Maintenance records
- logs not retained for required period
- camera blind spots unaddressed
- manual log entries not synchronized with electronic records
- lack of regular testing of alarm systems
Design and apply protection against natural disasters and other physical and environmental threats.
- Risk assessment reports
- Disaster recovery plans
- Facility security design
- Environmental monitoring logs
- risk assessments not updated after infrastructure changes
- recovery procedures lack site-specific details
- physical controls documented but not verified in practice
- environmental monitoring not integrated with incident response
Design and apply security measures for working in secure areas.
- Area access control
- Visitor management
- Physical barriers
- Monitoring and surveillance
- Training and awareness
- informal access permissions used instead of documented controls
- visitor logs missing key details or not retained
- surveillance footage retention periods not aligned with policy
- physical barriers not inspected on a regular schedule
Enforce clear-desk rules for papers and media and clear-screen rules for processing facilities.
- Desk policy
- Screen lock procedures
- Media handling records
- Workspace audit reports
- Policy exists but not enforced
- No regular desk inspections
- Screen lock settings vary across devices
- Employee awareness not documented
Site equipment securely and protect it.
- Site layout plans
- Environmental controls
- Physical security measures
- Maintenance records
- Assuming perimeter security covers equipment
- Outdated or missing environmental monitoring data
- Lack of documented siting criteria
- Inconsistent access logs for equipment areas
Protect assets used or held off-site.
- Offsite asset inventory
- Transport security procedures
- Third party agreements
- Remote storage encryption
- Asset disposal records
- Missing offsite asset register
- Inadequate transport controls
- No third‑party risk assessments
- Encryption not verified for remote storage
Technological controls – ISO 27001:2022
Protect information stored on, processed by or reachable through user endpoints.
- Device inventory
- Endpoint security settings
- Encryption and data protection
- Mobile device management
- User awareness records
- Incomplete device inventory
- Inconsistent encryption enforcement
- Irregular patching of endpoints
- Lack of BYOD controls
Delete information in systems, devices and media when no longer required.
- Deletion policy
- Media disposal log
- System deletion audit
- Data retention schedule
- Retaining data beyond approved period
- No evidence of secure erase verification
- Policies not aligned with actual practice
- Incomplete media disposal records
Use data masking in line with access policy, business need and applicable law.
- Masking policy
- Masking rules
- Implementation logs
- Access review reports
- Masking applied inconsistently across data stores
- Lack of documented justification for masking decisions
- Failure to review and update masking rules
- Insufficient monitoring of masking effectiveness
Apply data leakage prevention to systems and channels handling sensitive information.
- DLP policy
- DLP solution configuration
- DLP monitoring reports
- Incident handling records
- Employee awareness training
- Policy not enforced across all data channels
- DLP rules outdated and misaligned with business processes
- Insufficient monitoring and alert retention
- Lack of documented response to DLP incidents
Maintain and regularly test backups of information, software and systems per the backup policy.
- Backup policy
- Backup schedule
- Backup test reports
- Retention records
- Access logs
- infrequent restore testing
- missing retention documentation
- undefined backup responsibilities
- inconsistent backup verification
Build enough redundancy into processing facilities to meet availability requirements.
- Redundancy design
- Capacity planning
- Failover testing
- Maintenance records
- reliance on undocumented manual backups
- absence of regular failover drills
- capacity forecasts not aligned with business growth
- maintenance activities not tracked centrally
Produce, store, protect and analyse logs of activities, exceptions and faults.
- Log collection policy
- Log storage and protection
- Log review and analysis
- Log retention and disposal
- Inconsistent log collection across systems
- Insufficient protection of log integrity
- Irregular or undocumented log review
- Retention periods not aligned with policy
Monitor networks, systems and applications for anomalies and act on potential incidents.
- Network anomaly detection logs
- System integrity monitoring reports
- Application behavior alerts
- Incident response records
- alerts not correlated across sources
- lack of documented response procedures for anomalies
- insufficient retention of monitoring logs
- overreliance on manual review
Synchronize system clocks to approved time sources.
- Time source inventory
- Sync configuration
- Sync monitoring
- Deviation response
- Using unsanctioned public NTP servers
- No regular verification of time drift
- Missing documentation of configuration changes
- Inadequate handling of synchronization failures
Restrict and tightly control utilities that can override system and application controls.
- Privileged tool inventory
- Utility access logs
- Privileged account approval
- Utility usage audit
- Missing inventory of privileged utilities
- Logs not centralized or retained
- Lack of formal approval workflow
- Infrequent review of utility usage
Securely manage software installation on production systems.
- Installation requests
- Approval evidence
- Implementation logs
- Verification reports
- Missing formal approval for installations
- No evidence of post‑install verification
- Reliance on informal requests instead of documented tickets
- Failure to update inventory of installed software
Restrict and manage the allocation and use of privileged access.
- Privileged account inventory
- Privileged access approval
- Privileged access review
- Privileged access logging
- Outdated privileged account inventory
- Missing or informal approval documentation
- Infrequent or superficial access reviews
- Privileged activity logs not retained or insufficiently protected
Secure, manage and control networks and network devices.
- Network topology diagrams
- Firewall rule sets
- Network access control lists
- Wireless security configurations
- outdated topology diagrams
- inconsistent firewall rule documentation
- missing periodic review of ACLs
- weak wireless encryption settings
Identify, implement and monitor security mechanisms and service levels for network services.
- Network service inventory
- Service security configurations
- Monitoring and logging
- Service level agreements
- Change management records
- Out‑of‑date service inventory missing recent cloud assets
- Log retention periods shorter than required for forensic analysis
- SLA compliance not verified against actual performance data
- Configuration drift not tracked leading to undocumented rule changes
Segregate groups of services, users and systems in the network.
- Network segmentation policy
- Network topology diagrams
- Firewall rule set documents
- Segregation testing reports
- Informal or outdated network maps used instead of documented diagrams
- Inconsistent VLAN tagging and naming across locations
- Exceptions to segmentation not recorded or approved
- Segregation controls rarely tested after changes
Manage access to external websites to reduce exposure to malicious content.
- Filter policy
- Category rules
- Proxy logs
- Exception requests
- Awareness training
- Outdated URL category lists
- Insufficient logging retention
- No documented exception process
- Lack of periodic policy review
Define and implement rules for effective use of cryptography and key management.
- Encryption policy
- Key management procedures
- Algorithm inventory
- Key usage records
- Missing documented key lifecycle
- Use of outdated or weak algorithms
- Inadequate segregation of duties for key handling
- Lack of regular key rotation evidence
Establish and apply rules for secure development of software and systems.
- Secure dev policy
- Threat modeling artifacts
- Code review logs
- Security testing reports
- Policy exists but not enforced
- Threat models not updated for new features
- Code reviews performed inconsistently
- Security testing limited to final release
Identify, specify and approve security requirements when developing or acquiring applications.
- Security requirements spec
- Requirement approval records
- Development process integration
- Third party application requirements
- Security requirements not formally approved
- Missing requirements for third‑party components
- No traceability between requirements and implemented controls
- Outdated or incomplete threat modeling
Establish and apply secure engineering principles to system development.
- System architecture documents
- Secure design guidelines
- Threat modeling artifacts
- Security testing reports
- Change control records
- Design reviews not documented
- Threat modeling performed sporadically
- Secure coding standards not enforced
- Testing results not linked to remediation
Apply secure coding principles to software development.
- Secure coding policy
- Developer training records
- Code review logs
- Static analysis reports
- Vulnerability mitigation records
- inconsistent application of coding standards
- lack of documented review evidence
- reliance on manual testing only
- missing tracking of remediation actions
Define and run security testing across the development life cycle.
- Security test plan
- Test execution reports
- Vulnerability remediation log
- Acceptance criteria records
- testing only after release
- inconsistent test coverage across modules
- lack of documented remediation evidence
- no formal acceptance signoff
Restrict access to information and assets per the access control policy.
- Access control policy
- Role based access matrix
- User access review reports
- Privileged account logs
- Termination access revocation records
- infrequent or missing access reviews
- roles not aligned with actual job responsibilities
- privileged activity not captured in a central log
- termination revocation steps not documented
Direct, monitor and review outsourced system development.
- Outsourced development contracts
- Vendor security assessments
- Development process monitoring
- Deliverable acceptance records
- contracts lack specific security obligations
- no ongoing monitoring of vendor performance
- insufficient evidence of code security testing
- reliance on vendor assurances without independent verification
Separate and secure development, test and production environments.
- Environment separation policy
- Network segmentation diagram
- Access control matrix
- Change and deployment logs
- Policies exist but are not enforced
- Shared credentials across environments
- Insufficient network isolation between zones
- Missing audit trails for environment changes
Put changes to facilities and systems through change management procedures.
- Change requests
- Change approvals
- Implementation testing
- Post implementation reviews
- missing formal approval
- no rollback plan documented
- testing performed after production deployment
- change records not linked to assets
Select, protect and manage test information appropriately.
- Test data classification
- Test data access controls
- Test data retention and disposal
- Test data encryption
- Treating test data like production data without classification
- Granting broad access to test data without documented approvals
- Retaining test data far beyond its purpose
- Failing to encrypt test data in non-production environments
Plan and agree audit tests on operational systems with management to avoid disruption.
- Test plan approval
- Stakeholder agreement
- Risk assessment testing
- Change control notifications
- Post test review
- testing conducted without documented management signoff
- failure to assess and document risk before testing
- lack of communication to operations leading to unexpected outages
- no post-test review or lessons learned captured
Appropriately manage read and write access to source code, development tools and libraries.
- Repository access controls
- Development tool access
- Library dependency controls
- Change approval records
- shared accounts used for source code repositories
- permissions not reviewed on a regular basis
- third‑party library approvals undocumented
- insufficient logging of code change activities
Implement authentication technologies and procedures based on access restrictions and policy.
- Auth policy
- Credential provisioning
- MFA implementation
- Access log monitoring
- Privileged account controls
- Reliance on static passwords only
- Inconsistent MFA enforcement across systems
- No periodic review of authentication logs
- Missing documentation of credential lifecycle
Monitor and tune resource use against current and expected capacity needs.
- Capacity planning reports
- Utilization metrics
- Forecasting models
- Tuning action logs
- relying on manual spreadsheets only
- no regular review schedule
- failure to link forecasts with business growth plans
- ignoring seasonal usage patterns
Implement malware protection backed by user awareness.
- Anti malware policy
- Endpoint protection
- User awareness program
- Malware incident handling
- Outdated malware signatures not regularly updated
- Training limited to annual sessions
- No documented process for malware incident escalation
- Inconsistent endpoint protection across device types
Obtain vulnerability information, evaluate exposure, and take appropriate remediation.
- Vulnerability feed logs
- Risk assessment reports
- Remediation ticket records
- Patch deployment evidence
- Relying on ad-hoc scans only
- Missing documented risk ranking for vulnerabilities
- No evidence of timely remediation verification
- Failure to retain proof of feed subscription
Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
- Baseline configurations
- Change control records
- Configuration audit reports
- Secure hardening guidelines
- Deviation approvals
- outdated baselines
- missing change approvals
- infrequent configuration audits
- unauthorized deviations not documented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27001:2022 framework page.