Skip to content

Security Review

What is Security Review?

An examination of systems, applications, or processes to identify security weaknesses and verify compliance with security requirements.

Information Security

Each of these is named in at least one of the same controls as security review. The number is how many controls name both.

What the standards actually require on security review

Requirements naming security review across 6 standards, quoted from the control text.

CII operators procuring network products and services that may affect national security must pass a national security review organised by the Cyberspace Administration of China and relevant departments.

CSL-Art35 · CII Procurement Security Review - Art. 35

The State establishes a data-security review system to conduct national security reviews of data-processing activities that affect or may affect national security.

DSL-Art24 · National Security Review of Data Activities (Art. 24)

Institutions shall perform a programme of information security reviews, assessments and testing (including vulnerability assessments, penetration testing and, where relevant, scenario-based testing) to verify the effectiveness of controls.

EBA-GL-3.4.6 · Information security reviews, assessment and testing

Undertakings perform varied information security reviews/assessments/testing to identify vulnerabilities, establish an information security testing framework validating the robustness of measures, with tests by independent competent testers, performed regularl...

EIOPA-ICTSG-GL.12 · Information security reviews, assessment and testing

Requirement defined in ISO 27017:2015, clause 18.2 (Information security reviews). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requiremen...

iso-27017-2015::18.2 · Information security reviews

Requirement defined in ISO 27018:2019, clause 18.2 (Information security reviews). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requiremen...

iso-27018-2019::18.2 · Information security reviews

Questions people ask about security review

What is Security Review?
An examination of systems, applications, or processes to identify security weaknesses and verify compliance with security requirements.
Why is Security Review important for compliance?
Security Review is a key concept in Information Security. Understanding security review helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Review?
Security Review appears in the requirement text of China Cybersecurity Law (CSL), China Data Security Law (DSL), EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600), ISO 27017:2015. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Review?
Explore our compliance framework pages to see how security review applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Review applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.