ISO/IEC 27014:2020
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assure
Governing body commissions independent assurance activities to verify that information security governance is operating as directed.
- internal audit plan covering security governance
- external assurance reports
- management responses with remediation tracking
- assurance scope limited to operational controls
- no follow-up on assurance findings at board level
Clause 1-4: Introduction and Context
Defines the scope of guidance on concepts, objectives, and processes for governance of information security
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Key terms including governance, governing body, information security, and management
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Fundamental concepts of information security governance and its relationship to organizational governance
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Guidelines for a process on privacy impact assessments and structure and content of a PIA report
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
Privacy impact assessment terminology including PII, privacy risk, and PIA report
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
General overview of PIA process, its purpose, and relationship to other privacy management activities
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
Clause 5: Guiding Principles
Define and document objectives for the governance of information security aligned with organisational strategy and stakeholder expectations.
- board-approved information security governance charter
- alignment matrix linking security objectives to business strategy
- stakeholder register with expectation logs
- security objectives drafted by IT without board ratification
- no traceability from corporate strategy to security goals
Apply the six principles of information security governance covering organisation-wide approach, risk-based decisions, investment, conformance, human behaviour and value delivery.
- written governance principles statement endorsed by governing body
- policy cross-reference to each of the six principles
- minutes showing principles applied in decisions
- principles copy-pasted without contextualisation
- no evidence of principles influencing actual decisions
Ensuring information security governance produces effective outcomes
- Principles statement
- Effectiveness metrics
- Efficiency review
- Improvement plan
- Principles aspirational
- Metrics absent
- Efficiency not tracked
- Improvement abandoned
Delivering information security governance in a resource-efficient manner
- Principles statement
- Effectiveness metrics
- Efficiency review
- Improvement plan
- Principles aspirational
- Metrics absent
- Efficiency not tracked
- Improvement abandoned
Aligning information security governance with business strategy and objectives
- Principles statement
- Effectiveness metrics
- Efficiency review
- Improvement plan
- Principles aspirational
- Metrics absent
- Efficiency not tracked
- Improvement abandoned
Continually improving information security governance based on changing business needs
- Principles statement
- Effectiveness metrics
- Efficiency review
- Improvement plan
- Principles aspirational
- Metrics absent
- Efficiency not tracked
- Improvement abandoned
Clause 6: Governance Relationships
Governing body evaluates the current and forecast performance of information security against objectives, risk appetite and external context.
- quarterly board security performance dashboards
- horizon scan reports
- risk appetite versus current exposure analysis
- evaluation limited to backward-looking metrics
- no forecast or forward-looking indicators
Governing body provides direction by approving the information security strategy, policy, resourcing and risk treatment priorities.
- signed information security strategy document
- approved annual security budget with board minutes
- directives issued to executive management
- strategy never refreshed after initial approval
- budget approved without linkage to risk priorities
Governing body monitors achievement of strategic security objectives, conformance with policy and effectiveness of risk treatments through defined indicators.
- KPI catalogue with thresholds
- monthly monitoring reports to executive committee
- exception reports for breached thresholds
- KPIs measure activity not outcomes
- no escalation path when thresholds breached
Clause 7.3: Governance Processes
Governance process that considers current and forecast achievement of objectives based on current processes and planned changes
- Governance process map
- Direction setting record
- Monitoring dashboard
- Assurance report
- EDM cycle broken
- Direction not cascaded
- Monitoring lagging
- Assurance unreliable
Governance process by which the governing body provides direction on objectives, strategy, resource allocation, and policy approvals
- Governance process map
- Direction setting record
- Monitoring dashboard
- Assurance report
- EDM cycle broken
- Direction not cascaded
- Monitoring lagging
- Assurance unreliable
Governance process that enables the governing body to assess the achievement of its strategic objectives
- Governance process map
- Direction setting record
- Monitoring dashboard
- Assurance report
- EDM cycle broken
- Direction not cascaded
- Monitoring lagging
- Assurance unreliable
Governance process ensuring clear messaging on security priorities throughout the organization
- Governance process map
- Direction setting record
- Monitoring dashboard
- Assurance report
- EDM cycle broken
- Direction not cascaded
- Monitoring lagging
- Assurance unreliable
Governance process confirming that security efforts deliver value and remain aligned with business needs
- Governance process map
- Direction setting record
- Monitoring dashboard
- Assurance report
- EDM cycle broken
- Direction not cascaded
- Monitoring lagging
- Assurance unreliable
Clause 7: Governance Objectives and Processes
Establish integrated comprehensive entity-wide information security
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Make decisions using a risk-based approach to information security
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Set the direction for investment in information security
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Ensure conformance with internal and external requirements
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Foster a security-positive environment across the organization
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Ensure information security performance is related to business outcomes
- Governance objectives
- Decision register
- Conformance report
- Culture survey
- Objectives not cascaded
- Decisions undocumented
- Conformance gaps
- Culture not measured
Communicate
Bi-directional communication between governing body, executive management, internal and external stakeholders on security posture, expectations and obligations.
- stakeholder communication plan
- samples of internal security updates and external disclosures
- feedback logs from stakeholders
- one-way communication only top-down
- external stakeholders excluded from communications plan
Identify, classify and engage internal and external stakeholders with interest in or influence on information security governance.
- stakeholder register with classification
- engagement plan with cadence and channels
- records of engagement activities
- stakeholder list limited to internal parties
- no review of engagement effectiveness
Provide accurate and timely information security disclosures to regulators, customers, investors and the public as required.
- disclosure policy
- samples of regulatory filings and customer-facing security statements
- review and approval workflow for disclosures
- disclosures released without board review
- inconsistent statements across audiences
Conformance
Ensure information security governance demonstrates conformance with internal policy and compliance with external legal and regulatory obligations.
- legal and regulatory register
- compliance attestations
- conformance review reports to board
- regulatory register out of date
- no board-level visibility of compliance status
Improvement
Continually improve information security governance through review of effectiveness, lessons learned and adaptation to changing context.
- annual governance review report
- improvement action register
- lessons learned from incidents fed into governance
- no formal governance review cycle
- improvements stop at operational level
Integration
Information security governance integrates with broader enterprise governance frameworks and risk management.
- mapping of security governance to enterprise risk framework
- shared committee structures
- integrated reporting
- security governance operates in silo from enterprise risk
- duplicate or contradictory reporting lines
Monitor
Define and use measurements that demonstrate whether information security governance objectives are being achieved.
- governance measurement framework
- balanced scorecard for security
- trend analysis over multiple reporting periods
- metrics drawn only from operational layer
- no governance-level outcome metrics
Resources
Allocate resources to information security in proportion to risk and strategic priority, with periodic review of return on investment.
- security investment portfolio
- annual ROI or benefits realisation review
- resource reallocation decisions tied to risk changes
- security funded by historic baseline not risk
- no benefits tracking after project closure
Risk
Governing body defines and communicates information security risk appetite and tolerance levels that guide all downstream decisions.
- approved risk appetite statement for information security
- tolerance thresholds by risk category
- evidence of decisions referencing appetite
- risk appetite expressed in vague qualitative terms only
- no review cadence for appetite statement
Roles
Define explicit responsibilities of the governing body for setting direction, accountability and oversight of information security.
- board terms of reference covering security
- RACI matrix for governance activities
- induction materials for new board members
- security oversight assumed under audit committee with no explicit charter
- no induction on security accountability for new directors
Executive management implements direction from the governing body, operates the information security management system and reports performance upward.
- executive committee charter referencing security
- ISMS operating model showing executive sponsors
- executive performance objectives linked to security
- CISO reports only to CIO with no executive committee visibility
- executives lack security accountability in their objectives
Establish a clear separation and working relationship between governance (direction setting) and management (execution) for information security.
- documented interface between board and executive on security matters
- escalation procedures
- joint planning calendars
- board members involved in operational security decisions
- no defined escalation triggers from management to board
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.