Skip to content

Evidence request lists

ISO/IEC 27400:2022

Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 1-4: Introduction and Framework

27011-1
Scope

Defines applicability to telecommunications organizations for baseline information security management

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-2
Normative references

References to ISO/IEC 27001, ISO/IEC 27002:2022, and telecommunications standards

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-3
Terms and definitions

Telecommunications-specific information security terminology

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27011-4
Structure of this document

Organization of telecom-specific controls aligned with ISO/IEC 27002:2022 structure

Artefacts an auditor will ask for
  • Telecom control catalog
  • Network segregation diagram
  • Supplier contract addendum
  • Key management procedure
Where this commonly fails
  • Sector controls overlaid weakly
  • Network segregation incomplete
  • Supplier oversight gaps
  • Key management informal
27400-1
Scope

Guidelines on risks, principles, and controls for security and privacy of IoT solutions

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing
27400-3
Terms and definitions

IoT-specific security and privacy terminology

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing
27400-4
IoT overview and concepts

Summary of characteristics, stakeholders, life cycles, and risk sources of IoT systems

Artefacts an auditor will ask for
  • IoT scope statement
  • IoT glossary
  • Concept reference
  • Stakeholder map
Where this commonly fails
  • Scope vague
  • Glossary inconsistent
  • Concepts not internalized
  • Stakeholders missing

Clause 5: IoT Risk Sources

27400-5.1
IoT Security and Privacy Governance

Establish governance for IoT security and privacy including policy, accountability and oversight across device, network and platform layers.

Artefacts an auditor will ask for
  • IoT security and privacy policy
  • accountability matrix covering device, network and platform
  • steering committee minutes addressing IoT
Where this commonly fails
  • IoT treated as standard IT without specific policy
  • no accountability for unmanaged devices on the network
27400-5.2
IoT Risk Assessment

Conduct risk assessments tailored to IoT systems considering device constraints, environmental exposure, network heterogeneity and data sensitivity.

Artefacts an auditor will ask for
  • IoT-specific risk assessment methodology
  • threat models per IoT solution
  • risk register with treatment status
Where this commonly fails
  • generic IT risk methodology applied without IoT considerations
  • physical tamper risks ignored
27400-5.3
Network and communication risks

Risk sources related to IoT communication protocols and network infrastructure

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices
27400-5.4
Data and privacy risks

Risk sources related to personal data collection, processing, and storage by IoT systems

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices

Clause 6: IoT Security Controls

27400-6.1
Secure Device Design

Design IoT devices with security functions including secure boot, authentication, cryptographic protection and tamper resistance proportionate to risk.

Artefacts an auditor will ask for
  • device security architecture documents
  • secure boot evidence
  • tamper resistance testing reports
Where this commonly fails
  • secure boot disabled for development and left disabled in production
  • no tamper detection on field devices
27400-6.2
Device Identity and Authentication

Provision unique device identities and credentials with strong authentication mechanisms for device-to-platform and device-to-device communication.

Artefacts an auditor will ask for
  • device identity provisioning procedure
  • certificate management evidence
  • rotation and revocation logs
Where this commonly fails
  • shared credentials used across device fleet
  • no revocation when devices are decommissioned
27400-6.3
Secure Update Mechanism

Provide signed and authenticated firmware and software update mechanisms with rollback protection and update logging.

Artefacts an auditor will ask for
  • update mechanism design documents
  • signing key management procedures
  • update success and failure logs
Where this commonly fails
  • updates not signed allowing trivial tampering
  • no field deployment of updates after release
27400-6.4
Default Configuration Security

Ship devices with secure default configurations including no universal default passwords and minimal exposed services.

Artefacts an auditor will ask for
  • default configuration baseline
  • evidence of unique per-device credentials at factory
  • exposed service inventory and justification
Where this commonly fails
  • universal default password documented in manual
  • debug services left enabled in production firmware
27400-6.5
Security monitoring and incident response

Strategies for ongoing security monitoring and incident response for IoT deployments

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices

Clause 7: IoT Privacy Controls

27400-7.1
Network Security for IoT

Segment IoT networks, protect communications with encryption and authenticate flows between devices, gateways and platforms.

Artefacts an auditor will ask for
  • IoT network segmentation diagrams
  • encryption configuration evidence for device communications
  • firewall rules between IoT and IT networks
Where this commonly fails
  • IoT devices share VLAN with corporate IT
  • communications use plaintext protocols
27400-7.2
Gateway Security

Secure IoT gateways as critical aggregation points with hardening, monitoring and access control.

Artefacts an auditor will ask for
  • gateway hardening baseline
  • remote management access controls
  • monitoring evidence for gateway anomalies
Where this commonly fails
  • gateways managed via plaintext remote protocols
  • no log forwarding from gateways to central SIEM
27400-7.3
Data minimization and purpose limitation

Controls ensuring IoT systems collect only necessary data for specified purposes

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices
27400-7.4
Data retention and deletion

Controls for appropriate retention periods and secure deletion of IoT-collected data

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices

Clause 8: IoT Lifecycle Security

27400-8.1
Platform and Backend Security

Secure IoT cloud platforms and backend services with standard cloud security controls plus IoT-specific protections for device data ingestion.

Artefacts an auditor will ask for
  • platform architecture diagrams
  • cloud configuration baselines
  • data ingestion rate limiting and validation evidence
Where this commonly fails
  • device data ingestion lacks input validation enabling injection
  • platform inherits cloud defaults without IoT hardening
27400-8.2
Data Protection in IoT

Apply data protection controls across the IoT data lifecycle including minimisation, encryption in transit and at rest, and controlled retention.

Artefacts an auditor will ask for
  • data flow diagrams for IoT solutions
  • encryption configuration evidence
  • retention schedule for IoT data
Where this commonly fails
  • IoT data retained indefinitely without business need
  • encryption only between gateway and cloud not device and gateway
27400-8.3
Maintenance and update security

Security controls for maintaining and updating IoT devices throughout their operational life

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices
27400-8.4
Decommissioning security

Security controls for safe decommissioning and disposal of IoT devices and associated data

Artefacts an auditor will ask for
  • IoT device inventory and asset register
  • IoT security policy and architecture diagram
  • Device lifecycle procedure (provisioning to decommissioning)
  • Firmware update and patch logs
  • IoT data flow and privacy impact records
Where this commonly fails
  • IoT asset inventory incomplete or stale
  • Default credentials and weak update mechanisms in field devices
  • No data minimisation across telemetry pipelines
  • Decommissioning leaves residual data on devices

Lifecycle

27400-11.1
Decommissioning and Disposal

Decommission IoT devices securely including credential revocation, data sanitisation and physical disposal aligned with environmental requirements.

Artefacts an auditor will ask for
  • decommissioning procedure
  • data sanitisation evidence per device class
  • disposal certificates from approved vendors
Where this commonly fails
  • devices retired without credential revocation leaving valid certificates in the wild
  • no sanitisation of removable storage

Operate

27400-10.1
Vulnerability Management for IoT

Operate a vulnerability management programme for IoT devices and platforms covering discovery, assessment, prioritisation and remediation.

Artefacts an auditor will ask for
  • IoT vulnerability programme charter
  • scan and assessment reports
  • remediation tracking with SLAs
Where this commonly fails
  • scanning excludes IoT devices fearing disruption
  • remediation SLAs absent or unmet
27400-10.2
Incident Response for IoT

Prepare for and respond to IoT-specific incidents including botnet recruitment, physical compromise and large-scale device failures.

Artefacts an auditor will ask for
  • IoT incident playbooks
  • tabletop exercise reports
  • device quarantine procedures
Where this commonly fails
  • playbooks generic without IoT-specific actions
  • no procedure for mass device quarantine
27400-10.3
Logging and Monitoring

Capture and centralise logs from IoT devices, gateways and platforms with monitoring for anomalies and security events.

Artefacts an auditor will ask for
  • logging configuration baselines for devices and gateways
  • central SIEM integration evidence
  • monitoring use cases for IoT anomalies
Where this commonly fails
  • device logs not forwarded due to bandwidth concerns
  • no IoT-specific detection use cases

Privacy

27400-9.1
Privacy by Design for IoT

Embed privacy by design in IoT solutions including data minimisation, purpose limitation, transparency and user control over personal data.

Artefacts an auditor will ask for
  • privacy impact assessments per IoT solution
  • data minimisation evidence
  • user-facing privacy notices and controls
Where this commonly fails
  • PIAs performed once at launch never updated
  • user controls absent or buried in app settings
27400-9.2
Consent and Transparency

Obtain valid consent where required and provide clear transparency about data collection, use and sharing for IoT solutions.

Artefacts an auditor will ask for
  • consent capture records
  • privacy notices in accessible format
  • evidence of consent withdrawal mechanism
Where this commonly fails
  • consent assumed from device activation without explicit capture
  • no withdrawal mechanism for users
27400-9.3
Data Subject Rights for IoT

Enable data subject rights including access, correction, deletion and portability for personal data processed by IoT solutions.

Artefacts an auditor will ask for
  • DSAR procedure covering IoT data
  • evidence of rights fulfilment within statutory timeframes
  • deletion verification across device and cloud
Where this commonly fails
  • deletion limited to cloud while device retains local copies
  • DSAR process unaware of IoT data sources

Supply Chain

27400-11.2
Supplier and Third-Party Management

Manage IoT supplier and third-party risks including device manufacturers, platform providers and integrators through due diligence and contractual controls.

Artefacts an auditor will ask for
  • IoT supplier risk assessments
  • contractual security and privacy clauses
  • evidence of supplier security testing or attestations
Where this commonly fails
  • device manufacturers selected on price without security assessment
  • no contractual right to security testing
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.