ISO/IEC 27400:2022
Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Clause 1-4: Introduction and Framework
Defines applicability to telecommunications organizations for baseline information security management
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
References to ISO/IEC 27001, ISO/IEC 27002:2022, and telecommunications standards
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Telecommunications-specific information security terminology
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Organization of telecom-specific controls aligned with ISO/IEC 27002:2022 structure
- Telecom control catalog
- Network segregation diagram
- Supplier contract addendum
- Key management procedure
- Sector controls overlaid weakly
- Network segregation incomplete
- Supplier oversight gaps
- Key management informal
Guidelines on risks, principles, and controls for security and privacy of IoT solutions
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
IoT-specific security and privacy terminology
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
Summary of characteristics, stakeholders, life cycles, and risk sources of IoT systems
- IoT scope statement
- IoT glossary
- Concept reference
- Stakeholder map
- Scope vague
- Glossary inconsistent
- Concepts not internalized
- Stakeholders missing
Clause 5: IoT Risk Sources
Establish governance for IoT security and privacy including policy, accountability and oversight across device, network and platform layers.
- IoT security and privacy policy
- accountability matrix covering device, network and platform
- steering committee minutes addressing IoT
- IoT treated as standard IT without specific policy
- no accountability for unmanaged devices on the network
Conduct risk assessments tailored to IoT systems considering device constraints, environmental exposure, network heterogeneity and data sensitivity.
- IoT-specific risk assessment methodology
- threat models per IoT solution
- risk register with treatment status
- generic IT risk methodology applied without IoT considerations
- physical tamper risks ignored
Risk sources related to IoT communication protocols and network infrastructure
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Risk sources related to personal data collection, processing, and storage by IoT systems
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Clause 6: IoT Security Controls
Design IoT devices with security functions including secure boot, authentication, cryptographic protection and tamper resistance proportionate to risk.
- device security architecture documents
- secure boot evidence
- tamper resistance testing reports
- secure boot disabled for development and left disabled in production
- no tamper detection on field devices
Provision unique device identities and credentials with strong authentication mechanisms for device-to-platform and device-to-device communication.
- device identity provisioning procedure
- certificate management evidence
- rotation and revocation logs
- shared credentials used across device fleet
- no revocation when devices are decommissioned
Provide signed and authenticated firmware and software update mechanisms with rollback protection and update logging.
- update mechanism design documents
- signing key management procedures
- update success and failure logs
- updates not signed allowing trivial tampering
- no field deployment of updates after release
Ship devices with secure default configurations including no universal default passwords and minimal exposed services.
- default configuration baseline
- evidence of unique per-device credentials at factory
- exposed service inventory and justification
- universal default password documented in manual
- debug services left enabled in production firmware
Strategies for ongoing security monitoring and incident response for IoT deployments
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Clause 7: IoT Privacy Controls
Segment IoT networks, protect communications with encryption and authenticate flows between devices, gateways and platforms.
- IoT network segmentation diagrams
- encryption configuration evidence for device communications
- firewall rules between IoT and IT networks
- IoT devices share VLAN with corporate IT
- communications use plaintext protocols
Secure IoT gateways as critical aggregation points with hardening, monitoring and access control.
- gateway hardening baseline
- remote management access controls
- monitoring evidence for gateway anomalies
- gateways managed via plaintext remote protocols
- no log forwarding from gateways to central SIEM
Controls ensuring IoT systems collect only necessary data for specified purposes
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Controls for appropriate retention periods and secure deletion of IoT-collected data
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Clause 8: IoT Lifecycle Security
Secure IoT cloud platforms and backend services with standard cloud security controls plus IoT-specific protections for device data ingestion.
- platform architecture diagrams
- cloud configuration baselines
- data ingestion rate limiting and validation evidence
- device data ingestion lacks input validation enabling injection
- platform inherits cloud defaults without IoT hardening
Apply data protection controls across the IoT data lifecycle including minimisation, encryption in transit and at rest, and controlled retention.
- data flow diagrams for IoT solutions
- encryption configuration evidence
- retention schedule for IoT data
- IoT data retained indefinitely without business need
- encryption only between gateway and cloud not device and gateway
Security controls for maintaining and updating IoT devices throughout their operational life
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Security controls for safe decommissioning and disposal of IoT devices and associated data
- IoT device inventory and asset register
- IoT security policy and architecture diagram
- Device lifecycle procedure (provisioning to decommissioning)
- Firmware update and patch logs
- IoT data flow and privacy impact records
- IoT asset inventory incomplete or stale
- Default credentials and weak update mechanisms in field devices
- No data minimisation across telemetry pipelines
- Decommissioning leaves residual data on devices
Lifecycle
Decommission IoT devices securely including credential revocation, data sanitisation and physical disposal aligned with environmental requirements.
- decommissioning procedure
- data sanitisation evidence per device class
- disposal certificates from approved vendors
- devices retired without credential revocation leaving valid certificates in the wild
- no sanitisation of removable storage
Operate
Operate a vulnerability management programme for IoT devices and platforms covering discovery, assessment, prioritisation and remediation.
- IoT vulnerability programme charter
- scan and assessment reports
- remediation tracking with SLAs
- scanning excludes IoT devices fearing disruption
- remediation SLAs absent or unmet
Prepare for and respond to IoT-specific incidents including botnet recruitment, physical compromise and large-scale device failures.
- IoT incident playbooks
- tabletop exercise reports
- device quarantine procedures
- playbooks generic without IoT-specific actions
- no procedure for mass device quarantine
Capture and centralise logs from IoT devices, gateways and platforms with monitoring for anomalies and security events.
- logging configuration baselines for devices and gateways
- central SIEM integration evidence
- monitoring use cases for IoT anomalies
- device logs not forwarded due to bandwidth concerns
- no IoT-specific detection use cases
Privacy
Embed privacy by design in IoT solutions including data minimisation, purpose limitation, transparency and user control over personal data.
- privacy impact assessments per IoT solution
- data minimisation evidence
- user-facing privacy notices and controls
- PIAs performed once at launch never updated
- user controls absent or buried in app settings
Obtain valid consent where required and provide clear transparency about data collection, use and sharing for IoT solutions.
- consent capture records
- privacy notices in accessible format
- evidence of consent withdrawal mechanism
- consent assumed from device activation without explicit capture
- no withdrawal mechanism for users
Enable data subject rights including access, correction, deletion and portability for personal data processed by IoT solutions.
- DSAR procedure covering IoT data
- evidence of rights fulfilment within statutory timeframes
- deletion verification across device and cloud
- deletion limited to cloud while device retains local copies
- DSAR process unaware of IoT data sources
Supply Chain
Manage IoT supplier and third-party risks including device manufacturers, platform providers and integrators through due diligence and contractual controls.
- IoT supplier risk assessments
- contractual security and privacy clauses
- evidence of supplier security testing or attestations
- device manufacturers selected on price without security assessment
- no contractual right to security testing
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.