Skip to content

Evidence request lists

ISO/IEC 27010:2015

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Agreements

27010-4.2
Sharing Agreements

Define written agreements covering scope, rules, handling and liabilities for shared information.

Artefacts an auditor will ask for
  • Signed information sharing agreements
  • Liability clauses
  • Scope definitions
Where this commonly fails
  • No signed agreement
  • Liabilities undefined

Clause 11-13: Physical, Operations, and Communications Security

27010-11.1
Physical Protection

Protect physical locations and assets used to process or store shared information.

Artefacts an auditor will ask for
  • Site security plans
  • Asset register
  • Access logs
Where this commonly fails
  • Site security weak
  • Asset register stale
27010-12.1
Operational Procedures

Document operational procedures for collecting, validating, anonymising and distributing shared information.

Artefacts an auditor will ask for
  • SOP library
  • Anonymisation guidance
  • Validation logs
Where this commonly fails
  • No anonymisation step
  • Validation skipped
27010-12.2
Protection from malware

Malware protection for systems used in inter-organizational information sharing

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear
27010-13.1
Communications Security

Secure communications channels among community members using approved transport mechanisms.

Artefacts an auditor will ask for
  • Approved channel list
  • Configuration records
  • Channel testing reports
Where this commonly fails
  • Unsecured channels used
  • No channel testing
27010-13.2
Information transfer

Policies and procedures for information transfer between organizations and sectors

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear

Clause 14-16: System Development, Supplier Relations, and Incident Management

27010-14.1
Supplier and Third Party Handling

Manage suppliers and trusted intermediaries handling shared information with explicit obligations.

Artefacts an auditor will ask for
  • Supplier contracts
  • Due diligence records
  • Monitoring evidence
Where this commonly fails
  • Obligations not flowed down
  • No monitoring
27010-15.1
Incident Management

Detect, report, and respond to information sharing incidents including misuse and disclosures.

Artefacts an auditor will ask for
  • Incident playbook
  • Incident register
  • Lessons learned reports
Where this commonly fails
  • No misuse reporting
  • Lessons not shared with community
27010-16.1
Continuity of Sharing

Plan continuity of community operations including continuity of sharing systems and contacts.

Artefacts an auditor will ask for
  • Continuity plan
  • Test reports
  • Contact backup records
Where this commonly fails
  • No continuity test
  • Backup contacts missing

Clause 17-18 and Annexes: Continuity and Compliance

27010-17.1
Compliance

Ensure information sharing complies with legal, regulatory and contractual requirements including privacy laws.

Artefacts an auditor will ask for
  • Compliance register
  • Legal opinions
  • Privacy impact assessments
Where this commonly fails
  • No privacy assessment
  • Cross border issues ignored
27010-18.1
Review and Improvement

Review information sharing arrangements periodically and improve based on metrics and feedback.

Artefacts an auditor will ask for
  • Review minutes
  • Improvement actions
  • Member feedback surveys
Where this commonly fails
  • No reviews
  • Feedback unused
27010-A
Benefits of information sharing

Annex A describing potential benefits from sharing sensitive information between organizations

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear
27010-B
Trust assessment guidance

Annex B with guidance on assessing trust degree in information provided by community members

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear
27010-C
Traffic Light Protocol

Annex C describing the Traffic Light Protocol for indicating permitted distribution of information

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear
27010-D
Information sharing community models

Annex D with examples of models for organizing an information sharing community

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear

Clause 5-6: Information Security Policies and Organization

27010-5.1
Management Direction

Senior management direction supports inter organisational information sharing and security.

Artefacts an auditor will ask for
  • Sharing policy
  • Executive endorsement
  • Communications plan
Where this commonly fails
  • No policy
  • Executive endorsement missing
27010-5.2
Information sharing community policies

Policies governing the formation and operation of information sharing communities

Artefacts an auditor will ask for
  • Information sharing agreement
  • Trust assessment
  • Traffic Light Protocol labels
  • Sharing community charter
Where this commonly fails
  • No sharing agreement
  • Trust ad hoc
  • TLP misapplied
  • Community model unclear
27010-6.1
Roles and Responsibilities

Define roles for community manager, members and any trusted third parties handling shared information.

Artefacts an auditor will ask for
  • RACI matrix
  • Role descriptions
  • Appointment records
Where this commonly fails
  • Roles unclear
  • No community manager
27010-6.2
Contact with Authorities

Maintain controlled contact with regulators and law enforcement for information sharing matters.

Artefacts an auditor will ask for
  • Contact list
  • Engagement procedure
  • Escalation records
Where this commonly fails
  • No authority contact list
  • No escalation routes

Clause 7-8: Human Resources and Asset Management

27010-7.1
Information Classification for Sharing

Apply community wide classification scheme such as Traffic Light Protocol for shared information.

Artefacts an auditor will ask for
  • TLP guidance
  • Classification matrix
  • Labelling examples
Where this commonly fails
  • Inconsistent labels
  • TLP not enforced
27010-7.2
Handling Shared Information

Apply handling rules by classification for storage, transmission, retention and disposal of shared data.

Artefacts an auditor will ask for
  • Handling matrix
  • Retention schedule
  • Disposal records
Where this commonly fails
  • Handling matrix missing
  • Disposal not tracked
27010-8.1
Membership Onboarding

Onboard members against admission criteria including identity verification and confidentiality undertakings.

Artefacts an auditor will ask for
  • Admission checklist
  • Identity verification records
  • Confidentiality agreements
Where this commonly fails
  • No identity proof
  • Confidentiality undertakings missing
27010-8.2
Membership Termination

Terminate membership with return or destruction of shared information and revocation of access.

Artefacts an auditor will ask for
  • Termination procedure
  • Return or destruction records
  • Access revocation logs
Where this commonly fails
  • Access remains active
  • No destruction record

Clause 9-10: Access Control and Cryptography

27010-10.1
Cryptographic Protection

Apply cryptographic protection appropriate to classification for shared information in transit and at rest.

Artefacts an auditor will ask for
  • Cryptography policy
  • Key inventory
  • Algorithm standards
Where this commonly fails
  • Weak algorithms
  • No key rotation
27010-9.1
Access Control to Shared Information

Restrict access to shared information based on roles and need to know within and between members.

Artefacts an auditor will ask for
  • Access matrix
  • Role assignments
  • Reviews
Where this commonly fails
  • Over privileged access
  • No reviews
27010-9.2
Authentication of Sources

Authenticate originators of shared information to ensure trust and integrity.

Artefacts an auditor will ask for
  • Digital signature records
  • Authentication policy
  • Source verification logs
Where this commonly fails
  • No source authentication
  • Unsigned bulletins shared

Community

27010-4.1
Information Sharing Community

Establish formal information sharing community with defined purpose, membership and governance.

Artefacts an auditor will ask for
  • Community charter
  • Member roster
  • Governance documents
Where this commonly fails
  • Informal community
  • No membership criteria

Trust

27010-19.1
Trust Anchors and Reputation

Maintain trust anchors and reputation mechanisms enabling members to assess source reliability.

Artefacts an auditor will ask for
  • Trust framework
  • Reputation scoring
  • Verification records
Where this commonly fails
  • No reputation tracking
  • Trust anchors absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.