ISO/IEC 27010:2015
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Agreements
Define written agreements covering scope, rules, handling and liabilities for shared information.
- Signed information sharing agreements
- Liability clauses
- Scope definitions
- No signed agreement
- Liabilities undefined
Clause 11-13: Physical, Operations, and Communications Security
Protect physical locations and assets used to process or store shared information.
- Site security plans
- Asset register
- Access logs
- Site security weak
- Asset register stale
Document operational procedures for collecting, validating, anonymising and distributing shared information.
- SOP library
- Anonymisation guidance
- Validation logs
- No anonymisation step
- Validation skipped
Malware protection for systems used in inter-organizational information sharing
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Secure communications channels among community members using approved transport mechanisms.
- Approved channel list
- Configuration records
- Channel testing reports
- Unsecured channels used
- No channel testing
Policies and procedures for information transfer between organizations and sectors
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Clause 14-16: System Development, Supplier Relations, and Incident Management
Manage suppliers and trusted intermediaries handling shared information with explicit obligations.
- Supplier contracts
- Due diligence records
- Monitoring evidence
- Obligations not flowed down
- No monitoring
Detect, report, and respond to information sharing incidents including misuse and disclosures.
- Incident playbook
- Incident register
- Lessons learned reports
- No misuse reporting
- Lessons not shared with community
Plan continuity of community operations including continuity of sharing systems and contacts.
- Continuity plan
- Test reports
- Contact backup records
- No continuity test
- Backup contacts missing
Clause 17-18 and Annexes: Continuity and Compliance
Ensure information sharing complies with legal, regulatory and contractual requirements including privacy laws.
- Compliance register
- Legal opinions
- Privacy impact assessments
- No privacy assessment
- Cross border issues ignored
Review information sharing arrangements periodically and improve based on metrics and feedback.
- Review minutes
- Improvement actions
- Member feedback surveys
- No reviews
- Feedback unused
Annex A describing potential benefits from sharing sensitive information between organizations
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Annex B with guidance on assessing trust degree in information provided by community members
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Annex C describing the Traffic Light Protocol for indicating permitted distribution of information
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Annex D with examples of models for organizing an information sharing community
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Clause 5-6: Information Security Policies and Organization
Senior management direction supports inter organisational information sharing and security.
- Sharing policy
- Executive endorsement
- Communications plan
- No policy
- Executive endorsement missing
Policies governing the formation and operation of information sharing communities
- Information sharing agreement
- Trust assessment
- Traffic Light Protocol labels
- Sharing community charter
- No sharing agreement
- Trust ad hoc
- TLP misapplied
- Community model unclear
Define roles for community manager, members and any trusted third parties handling shared information.
- RACI matrix
- Role descriptions
- Appointment records
- Roles unclear
- No community manager
Maintain controlled contact with regulators and law enforcement for information sharing matters.
- Contact list
- Engagement procedure
- Escalation records
- No authority contact list
- No escalation routes
Clause 7-8: Human Resources and Asset Management
Apply community wide classification scheme such as Traffic Light Protocol for shared information.
- TLP guidance
- Classification matrix
- Labelling examples
- Inconsistent labels
- TLP not enforced
Apply handling rules by classification for storage, transmission, retention and disposal of shared data.
- Handling matrix
- Retention schedule
- Disposal records
- Handling matrix missing
- Disposal not tracked
Onboard members against admission criteria including identity verification and confidentiality undertakings.
- Admission checklist
- Identity verification records
- Confidentiality agreements
- No identity proof
- Confidentiality undertakings missing
Terminate membership with return or destruction of shared information and revocation of access.
- Termination procedure
- Return or destruction records
- Access revocation logs
- Access remains active
- No destruction record
Clause 9-10: Access Control and Cryptography
Apply cryptographic protection appropriate to classification for shared information in transit and at rest.
- Cryptography policy
- Key inventory
- Algorithm standards
- Weak algorithms
- No key rotation
Restrict access to shared information based on roles and need to know within and between members.
- Access matrix
- Role assignments
- Reviews
- Over privileged access
- No reviews
Authenticate originators of shared information to ensure trust and integrity.
- Digital signature records
- Authentication policy
- Source verification logs
- No source authentication
- Unsigned bulletins shared
Community
Establish formal information sharing community with defined purpose, membership and governance.
- Community charter
- Member roster
- Governance documents
- Informal community
- No membership criteria
Trust
Maintain trust anchors and reputation mechanisms enabling members to assess source reliability.
- Trust framework
- Reputation scoring
- Verification records
- No reputation tracking
- Trust anchors absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.