ISO/IEC 27003:2017
Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context
Determine external and internal issues relevant to ISMS purpose that affect ability to achieve intended outcomes.
- Context analysis report
- PESTLE assessment
- Internal issues register
- Context not refreshed
- External issues omitted
Identify interested parties relevant to the ISMS and their information security requirements.
- Stakeholder register
- Requirements matrix
- Legal and contractual obligations log
- Requirements not tracked
- Stakeholders incomplete
Context of the Organization (Clause 4)
Guidance on continuously analyzing internal and external issues (political, legal, technological, competitive, market, cultural) that affect information security objectives.
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on identifying all interested parties (customers, regulators, employees, suppliers, shareholders) and their requirements relevant to the ISMS.
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on defining boundaries and applicability of the ISMS, considering interfaces and dependencies, organizational units, locations, and technologies.
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on establishing, implementing, maintaining, and continually improving the ISMS including required processes and their interactions.
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Improvement
React to nonconformities, evaluate need for action to eliminate causes, implement corrections, and review effectiveness.
- NC register
- Root-cause analyses
- Effectiveness checks
- No root cause
- Effectiveness not verified
Continually improve suitability, adequacy, and effectiveness of the ISMS.
- Improvement register
- Trend analysis
- Lessons-learned records
- No trend analysis
- Lessons not captured
Improvement (Clause 10)
Guidance on continually improving the suitability, adequacy, and effectiveness of the ISMS through use of corrective actions, audit results, analysis of events, and management reviews.
- CAPA register with root cause and verification
- Improvement programme tracker
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Root cause analysis is symptomatic only
- Effectiveness checks not performed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on reacting to nonconformities, evaluating need for action to eliminate causes, implementing corrective actions, reviewing effectiveness, and making changes to the ISMS if necessary.
- CAPA register with root cause and verification
- Improvement programme tracker
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Root cause analysis is symptomatic only
- Effectiveness checks not performed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Leadership
Top management demonstrates leadership and commitment to the ISMS via policy, resourcing, and integration.
- Signed ISMS policy
- Management review minutes
- Resource allocation evidence
- No management review
- Policy unsigned
Leadership (Clause 5)
Guidance on how top management demonstrates leadership by ensuring information security policy and objectives are established, resources are allocated, and the ISMS achieves intended outcomes.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on establishing the policy including appropriate scope, framework for objectives, commitment to requirements, and commitment to continual improvement.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Signed and dated policy set with version history
- Annual review and approval records
- Process owner attestation
- Tooling configuration export
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Policies past their review date
- No evidence policies were communicated to staff
- Evidence is point in time rather than ongoing
Guidance on assigning and communicating roles and responsibilities for information security, ensuring reporting lines and accountability.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Operation
Plan, implement, and control processes needed to meet requirements and implement actions from Clause 6.
- Process documentation
- Operational records
- Change control
- Processes undocumented
- Changes uncontrolled
Perform information security risk assessments at planned intervals or when significant changes occur, with retained results.
- Assessment cadence schedule
- Triggered assessments
- Retained results
- No trigger-based assessments
- Cadence missed
Implement the information security risk treatment plan and retain evidence of results.
- Treatment evidence
- Control implementation logs
- Effectiveness reviews
- No closure tracking
- Effectiveness untested
Operation (Clause 8)
Guidance on planning, implementing, and controlling processes needed to meet information security requirements, including managing planned changes and outsourced processes.
- Scope statement signed by management
- Stakeholder and interested party register
- Process maps with defined controls and owners
- Change control records
- Process owner attestation
- Tooling configuration export
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Operational controls not linked to risks
- Change records missing rollback evidence
- Evidence is point in time rather than ongoing
Guidance on performing information security risk assessments at planned intervals or when significant changes occur, and retaining documented results.
- Risk register with likelihood, impact, and treatment plans
- Risk assessment methodology document
- Process maps with defined controls and owners
- Change control records
- Process owner attestation
- Tooling configuration export
- Risk register not refreshed on a defined cadence
- Inherent vs residual risk scoring not documented
- Operational controls not linked to risks
- Change records missing rollback evidence
- Evidence is point in time rather than ongoing
Guidance on implementing the risk treatment plan, applying selected controls, and retaining documented results of risk treatment.
- Process maps with defined controls and owners
- Change control records
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Operational controls not linked to risks
- Change records missing rollback evidence
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Organization
Assign and communicate responsibilities and authorities for ISMS roles including reporting on performance.
- RACI matrix
- Role descriptions
- Org chart
- No CISO appointed
- RACI incomplete
Performance
Determine what, how, and when to monitor and measure; analyse and evaluate results to assess ISMS performance.
- Measurement plan
- KPI dashboards
- Evaluation reports
- No measurement plan
- KPIs unrelated to objectives
Conduct internal audits at planned intervals to verify ISMS conformance and effective implementation.
- Audit programme
- Audit reports
- Auditor independence evidence
- Auditor not independent
- Programme missed
Top management reviews ISMS at planned intervals for continuing suitability, adequacy, and effectiveness.
- Review minutes
- Inputs and outputs
- Action register
- Inputs incomplete
- Actions not tracked
Performance Evaluation (Clause 9)
Guidance on determining what needs to be monitored/measured, methods, timing, and responsibilities. Evaluating ISMS performance and effectiveness.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
Guidance on planning and conducting internal audits at planned intervals to verify ISMS conformance and effective implementation.
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on top management review of the ISMS at planned intervals, including required inputs (status of actions, changes, feedback, risk results) and outputs (improvement decisions, resource needs).
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Planning
Plan actions to address risks and opportunities that ensure ISMS achieves intended outcomes.
- Risk and opportunity register
- Action plans
- Effectiveness reviews
- Opportunities ignored
- Actions not tracked
Establish measurable security objectives at relevant functions and levels, with plans to achieve them.
- Objectives register
- KPI definitions
- Achievement reports
- Objectives not measurable
- Owners missing
Planning (Clause 6)
Guidance on the risk assessment process including risk identification, analysis, evaluation, and selection of risk treatment options. Creation of the Statement of Applicability.
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on setting measurable information security objectives at relevant functions and levels, and planning actions, resources, responsibilities, and timeframes.
- Consent capture and withdrawal logs
- Data subject request workflow and SLA tracker
- Scope statement signed by management
- Stakeholder and interested party register
- Process owner attestation
- Tooling configuration export
- Consent records lack timestamp or version
- DSR responses miss statutory deadline
- Scope boundaries unclear for cloud services
- Stakeholder needs not refreshed annually
- Evidence is point in time rather than ongoing
Policy
Establish information security policy aligned to strategic context, with commitments and continual improvement.
- ISMS policy document
- Approval record
- Distribution evidence
- Not communicated
- No review cadence
Risk Management
Define and apply a risk assessment process with criteria, repeatability, and documented results.
- Risk methodology
- Risk register
- Assessment reports
- Methodology informal
- Results not retained
Select treatment options, determine controls, produce Statement of Applicability, and gain risk owner approval.
- Risk treatment plan
- Statement of Applicability
- Risk owner approvals
- SoA outdated
- Residual risk unsigned
Scope
Determine boundaries and applicability of the ISMS considering external and internal issues, interested parties, and interfaces with other organizations.
- Scope statement
- Boundary diagram
- Interface and dependency map
- Scope ambiguous
- Interfaces undocumented
Support
Determine and provide resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS.
- Budget allocation
- Staffing plan
- Tooling inventory
- Underfunded
- No staffing plan
Determine necessary competence, ensure persons are competent, and retain evidence of competence.
- Competence matrix
- Training records
- Certification copies
- No competence matrix
- Training informal
Persons under the organization's control are aware of policy, their contribution, and implications of non-conformance.
- Awareness programme content
- Completion metrics
- Reinforcement campaigns
- One-time training only
- No completion tracking
Determine internal and external communications relevant to the ISMS including what, when, with whom, and how.
- Communication plan
- Distribution logs
- External notice templates
- No plan
- External comms ad hoc
Create, update, and control documented information required by the ISMS with appropriate identification and protection.
- Document register
- Version control evidence
- Retention schedule
- No version control
- Retention undefined
Support (Clause 7)
Guidance on determining and providing resources needed for establishment, implementation, maintenance, and continual improvement of the ISMS.
- Control narrative tied to evidence
- Sample of operating evidence over the period
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Evidence sampling not representative
- Operating effectiveness not demonstrated
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on determining necessary competence of persons, ensuring they are competent through education, training, or experience, and retaining evidence.
- Training completion records by role
- Phishing simulation results
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Role based training not delivered to high risk teams
- Training metrics not reported to leadership
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on ensuring all persons doing work under the organisation's control are aware of the information security policy, their contribution, and implications of non-conformance.
- Training completion records by role
- Phishing simulation results
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Role based training not delivered to high risk teams
- Training metrics not reported to leadership
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on determining the need for internal and external communications relevant to the ISMS: what, when, with whom, who communicates, and the processes.
- Control narrative tied to evidence
- Sample of operating evidence over the period
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Evidence sampling not representative
- Operating effectiveness not demonstrated
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Guidance on creating, updating, and controlling documented information required by the ISMS, including access, storage, retention, and disposition.
- Signed and dated policy set with version history
- Annual review and approval records
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Policies past their review date
- No evidence policies were communicated to staff
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.