ISO 27001 5.1 Policies for information security
Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
Evidence an auditor accepts: The approved information security policy, showing the approving authority and the date of approval; the set of topic specific policies beneath it, such as access control, cryptography, backup, acceptable use and supplier security, each with an owner; evidence of publication and of communication to personnel and to relevant interested parties, such as intranet publication records or distribution listsCommon gap: Policies not formally approved by senior managementSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.2 Information security roles and responsibilities
Name who owns what in security and make the allocation explicit and traceable.
Evidence an auditor accepts: The documented allocation of information security roles and responsibilities, naming individuals or positions rather than teams; role descriptions or terms of reference setting out the security duties attached to each role; evidence the allocation was formally approved and communicated to the holdersCommon gap: Roles not updated after staff changesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.7 Threat intelligence
Collect and analyse threat information and turn it into decisions, not just unread feeds.
Evidence an auditor accepts: The defined sources of threat information, covering strategic, tactical and operational levels; the process for analysing raw information into intelligence relevant to the organisation, naming who performs it; intelligence products produced during the period and their distribution listCommon gap: Collecting feeds without validationSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.9 Inventory of information and other associated assets
Maintain a current asset inventory with owners.
Evidence an auditor accepts: The inventory of information and associated assets, showing scope across hardware, software, services, information stores and cloud tenancies; the recorded owner for each entry, and evidence owners have accepted the role; the process and cadence for keeping the inventory current, including additions and retirementsCommon gap: Outdated entries in inventorySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.10 Acceptable use of information and other associated assets
Define and enforce rules for how information and assets may be used and handled.
Evidence an auditor accepts: The acceptable use rules, covering personal use, removable media, cloud storage, email, messaging and use of artificial intelligence services where relevant; handling procedures per classification level, covering storage, transmission, printing, sharing and destruction; evidence rules were communicated and accepted by personnel and by third parties given accessCommon gap: Policy not reviewed or updated regularlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.11 Return of assets
Recover all organizational assets on exit or role change.
Evidence an auditor accepts: The leaver and role change procedure showing asset return as a mandatory step; the checklist or ticket used per departure, listing assets issued to that person from the inventory; signed confirmation of return, and records for assets not returned including the escalation takenCommon gap: Missing signatures on return formsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.12 Classification of information
Classify information by confidentiality, integrity, availability and interested-party requirements.
Evidence an auditor accepts: The classification scheme, defining the levels and the criteria for each against confidentiality, integrity and availability; evidence the criteria account for the requirements of relevant interested parties, such as customers, regulators and contracts; classification applied to actual information assets in the inventory, not only defined in policyCommon gap: Classification levels not aligned with business impactSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.13 Labelling of information
Label information consistently with the classification scheme so handling rules can follow it.
Evidence an auditor accepts: The labelling procedures showing how labels are applied for each medium, covering documents, email, physical media, screens and system records; samples of labelled information from live systems, in each classification level in use; evidence labelling extends to information shared with third partiesCommon gap: Labels applied inconsistently across departmentsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.14 Information transfer
Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.
Evidence an auditor accepts: Transfer rules covering each transfer type in use, being electronic, physical and verbal; transfer agreements with external parties, setting out protection, liability and traceability requirements; technical evidence of protection in transit, such as enforced transport encryption, secure file transfer configuration and managed file transfer logsCommon gap: Reliance on informal verbal agreementsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.15 Access control
Set rules for physical and logical access based on business and security requirements.
Evidence an auditor accepts: The access control policy and the specific rules derived from it, expressed per information asset or asset group; evidence the rules reflect business need and the classification of the information rather than convenience; the mapping from rules to enforcement points, covering logical systems and physical areasCommon gap: Infrequent review of access rightsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.16 Identity management
Manage the full life cycle of identities.
Evidence an auditor accepts: The identity lifecycle procedure covering creation, change and removal, for internal users, external users and non human identities; records showing each identity is traceable to a person or to an accountable owner where the identity is for a service or device; approval records for identity creation, sourced from an authoritative system such as human resources or contract managementCommon gap: relying on manual spreadsheets for provisioningSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.17 Authentication information
Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
Evidence an auditor accepts: The process for allocating authentication information, including initial issue, secure delivery and forced change on first use; rules on strength, reuse, expiry and storage, and the configuration enforcing them; evidence of secure storage, such as hashing configuration for stored credentials and a controlled vault for shared or privileged secretsCommon gap: Policies exist but not enforcedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.18 Access rights
Provision, review, modify and remove access rights in line with the access control policy.
Evidence an auditor accepts: Provisioning records showing the authorisation behind each access grant, tied to the access control rules; modification records where access changed after a role change, showing removal of the previous entitlements; removal records on termination, with the date of removal against the date of departureCommon gap: Reviews lack documented corrective actionsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.19 Information security in supplier relationships
Define and apply processes to manage the security risk suppliers introduce.
Evidence an auditor accepts: The supplier security process, covering identification, risk assessment, selection, onboarding and exit; the supplier register with risk tiering, showing what drives the tier such as data access, criticality or connectivity; risk assessments performed for suppliers in the period, at the depth their tier requiresCommon gap: Treating all suppliers as low riskSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.20 Addressing information security within supplier agreements
Establish and agree the relevant security requirements in each supplier contract.
Evidence an auditor accepts: Executed agreements containing the agreed information security requirements, sampled across supplier tiers; the clause set used, covering confidentiality, information handling, incident notification with a timeframe, subcontracting, personnel screening, return or deletion at exit and right to audit; evidence requirements were scaled to the relationship type rather than applied as one template regardlessCommon gap: missing explicit security clausesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.21 Managing information security in the ICT supply chain
Extend security requirements down the ICT products and services supply chain.
Evidence an auditor accepts: The process for managing ICT supply chain risk, distinct from general supplier management; requirements imposed on ICT suppliers regarding their own suppliers, component provenance and secure development; evidence of verification, such as a software bill of materials, component listings or attestation of development practiceCommon gap: Treating supplier security as one-off checkSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.22 Monitoring, review and change management of supplier services
Regularly monitor, review and manage change in supplier security practice and service delivery.
Evidence an auditor accepts: The schedule of supplier reviews, showing frequency by tier and evidence the schedule was met; service reports and security metrics received from suppliers, and the review of them; records of issues raised with suppliers, and their resolution or escalationCommon gap: relying on informal verbal updatesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.23 Information security for use of cloud services
Govern acquisition, use, management and exit of cloud services against your security requirements.
Evidence an auditor accepts: The process covering cloud acquisition, use, management and exit, including who may acquire a cloud service; the register of cloud services in use, with data classification, owner and criticality per service; the shared responsibility position documented per service, showing which controls the provider operates and which the organisation mustCommon gap: Relying solely on provider's security assurancesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.24 Information security incident management planning and preparation
Define incident roles, processes and readiness before an incident happens.
Evidence an auditor accepts: The incident management process, defining categories, severity, escalation and the decision authority at each level; documented roles and responsibilities for incident handling, including out of hours coverage and named deputies; evidence the process and roles were communicated to those who must act on themCommon gap: roles are defined but not formally assigned or approvedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.25 Assessment and decision on information security events
Triage security events and decide which become incidents.
Evidence an auditor accepts: The criteria used to decide whether an event is an incident, and the severity scale applied; records of events assessed in the period, including those assessed as not incidents, with the reason recorded; evidence of who performed the assessment and that they were competent and authorised to do soCommon gap: no documented triage stepsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.26 Response to information security incidents
Respond to incidents according to the documented procedures.
Evidence an auditor accepts: Documented response procedures per incident type, and evidence they were followed in actual incidents; incident records carrying detection, containment, eradication and recovery timestamps and the actions taken at each stage; evidence of decisions taken during response and by whom, including any decision to preserve rather than eradicateCommon gap: Plans not tested regularlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.27 Learning from information security incidents
Feed lessons from incidents back into stronger controls.
Evidence an auditor accepts: Post incident review records for incidents meeting the defined threshold, with attendees and findings; root cause analysis distinguishing the technical cause from the process or control failure that allowed it; actions arising, with owner, due date and evidence of completionCommon gap: Root cause analysis limited to symptomsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.28 Collection of evidence
Have procedures to identify, collect, acquire and preserve evidence related to security events.
Evidence an auditor accepts: Procedures for identification, collection, acquisition and preservation of evidence, covering the media types the organisation holds; chain of custody records for evidence collected in the period, showing who held it and when; evidence of the method used to acquire data in a way that preserves integrity, such as hashing and write protectionCommon gap: Procedures not aligned with legal requirementsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.29 Information security during disruption
Plan how to keep information security at the right level during disruption.
Evidence an auditor accepts: Continuity plans showing how information security is maintained while the organisation is operating in a degraded or alternative mode; the assessment of which security controls would be weakened or bypassed during disruption, and the compensating arrangements; evidence security requirements are part of continuity testing, not only recovery of functionCommon gap: Plans not updated after testsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.30 ICT readiness for business continuity
Plan, implement, maintain and test ICT readiness against business continuity objectives.
Evidence an auditor accepts: ICT continuity requirements derived from the business impact analysis, expressed as recovery time and recovery point objectives per service; the ICT continuity plans and the technical capability supporting them, such as replication, failover and alternative capacity; test plans and results for the period, showing objectives were measured against the requirement rather than assumedCommon gap: Testing frequency not aligned with riskSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.31 Legal, statutory, regulatory and contractual requirements
Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Evidence an auditor accepts: The register of legal, statutory, regulatory and contractual requirements relevant to information security, per jurisdiction of operation; the documented approach to meeting each requirement, with the control or process that satisfies it; evidence the register is maintained, showing how new and changed obligations are identified and the date of the last updateCommon gap: outdated legal registerSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.33 Protection of records
Protect records from loss, destruction, falsification, unauthorized access and unauthorized release.
Evidence an auditor accepts: The records retention schedule, showing retention periods and their legal or business basis per record type; evidence of protection appropriate to each record type against loss, destruction, falsification and unauthorised access or release; controls over the storage medium including its readability over the retention periodCommon gap: retention schedules not aligned with legal requirementsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)
Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Evidence an auditor accepts: Identification of the privacy and personally identifiable information requirements that apply, per jurisdiction and per contract; the record of processing activities, showing what personal data is held, why, on what basis and for how long; evidence of the protections applied, such as access restriction, minimisation, pseudonymisation and transfer safeguardsCommon gap: Missing documented consent for all data subjectsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.35 Independent review of information security
Have the security approach and its implementation reviewed independently on a cadence and after significant change.
Evidence an auditor accepts: The plan for independent review, showing the interval and the scope covering approach, people, processes and technologies; reports from reviews performed in the period, and the identity and independence of the reviewer; evidence of independence, meaning the reviewer does not review their own workCommon gap: reviews performed by internal staff onlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.36 Compliance with policies, rules and standards for information security
Regularly check that people actually comply with the security policies, rules and standards.
Evidence an auditor accepts: The programme of compliance checks against the organisation's own policies, rules and standards, showing coverage and frequency; results of checks performed in the period, including technical configuration compliance against the defined standard; records of non conformities identified, their cause and the corrective action takenCommon gap: Irregular or ad-hoc compliance checksSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 5.37 Documented operating procedures
Document operating procedures for information processing facilities and make them available to those who need them.
Evidence an auditor accepts: The set of documented operating procedures for information processing facilities, covering routine operation, backup, monitoring, incident handling and restart; evidence procedures are available to the personnel who need them, including during an outage of the primary system that hosts them; version control and review records, showing procedures are current against the systems they describeCommon gap: outdated procedures still in useSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.1 Screening
Background-check candidates and personnel proportional to risk and classification, within the law.
Evidence an auditor accepts: The screening procedure, showing what checks are performed and how the level is set against the classification of information accessed and the perceived risk; completed screening records for personnel who joined in the period, including contractors and agency staff; evidence of the legal and regulatory limits applied in each jurisdiction, and of candidate consent where requiredCommon gap: One‑size‑fits‑all screening regardless of riskSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.2 Terms and conditions of employment
State the security responsibilities of both the person and the organization in the employment agreement.
Evidence an auditor accepts: Employment contracts and contractor agreements containing the information security responsibilities of both parties; evidence the clauses cover confidentiality, acceptable use, return of assets and obligations continuing after employment; signed acceptance records for personnel in scope, including those who joined before the current clause setCommon gap: missing security clauses in standard contractsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.3 Information security awareness, education and training
Give personnel and relevant parties appropriate, current security training for their role.
Evidence an auditor accepts: The awareness and training programme, distinguishing general awareness from role specific training for those with defined security duties; completion records per individual, with coverage measured against the full population including contractors; content evidence showing the material reflects current policy, current threats and the organisation's own proceduresCommon gap: Training not aligned to specific job functionsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.4 Disciplinary process
Have a formal, communicated disciplinary process for security policy violations.
Evidence an auditor accepts: The formalised disciplinary process covering information security breaches, and evidence it was communicated in advance; evidence of the link from incident and compliance findings into the disciplinary route, including who decides to invoke it; records of cases where the process was invoked, with the assessment of the breach and the outcomeCommon gap: Policy exists but not communicated to staffSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.5 Responsibilities after termination or change of employment
Define and enforce security responsibilities that remain valid after an exit or role change.
Evidence an auditor accepts: Documented responsibilities that remain in force after employment ends or after a change of role, such as confidentiality and non disclosure; evidence these were communicated to the individual at the point of departure or change, with acknowledgement; the leaver and mover procedure showing the security steps and their completion within a defined timeframeCommon gap: Delayed revocation of privileged accountsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.6 Confidentiality or non-disclosure agreements
Identify, document, review and sign NDAs that reflect the organization's protection needs.
Evidence an auditor accepts: The confidentiality or non disclosure agreements in use, and the assessment showing they reflect the organisation's protection needs; signed agreements for personnel and for third parties with access, held and retrievable; evidence of regular review of the agreement terms and of who is coveredCommon gap: NDAs not refreshed when data classification changesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.7 Remote working
Apply security measures when people access, process or store information outside the organization's premises.
Evidence an auditor accepts: The remote working rules, covering approval, permitted locations, equipment, network use and handling of physical material; technical measures evidence, such as device encryption, endpoint protection, secure remote access configuration and enforced patching for remote devices; evidence of protection where personally owned devices are used, including separation of organisational informationCommon gap: Missing MFA for remote accessSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 6.8 Information security event reporting
Give people an easy, timely channel to report observed or suspected security events.
Evidence an auditor accepts: The defined reporting mechanism and channels, and evidence they are known to personnel and to relevant third parties; reporting records for the period, showing volume, source and the time between observation and report; evidence the channel is available at all times and does not depend on a system that may itself be affectedCommon gap: no anonymous reporting optionSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.1 Physical security perimeters
Define and use security perimeters to protect areas holding information and assets.
Evidence an auditor accepts: Definition of the security perimeters, with site plans or drawings showing the boundary of each area holding information and associated assets; the basis for each perimeter, tied to the classification and criticality of what it protects; evidence the perimeter is physically sound, covering walls, doors, windows, roof and floor voidsCommon gap: outdated floor plansSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.2 Physical entry
Protect secure areas with appropriate entry controls and access points.
Evidence an auditor accepts: Entry control configuration for each secure area, showing the authentication required and any multi factor or dual control; the authorisation list per area, with the basis for each person's access; access logs for the period, retained and reviewed, with evidence of what the review looked forCommon gap: Use of informal sign-in sheets instead of controlled logsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.4 Physical security monitoring
Continuously monitor premises for unauthorized physical access.
Evidence an auditor accepts: The design of physical monitoring, covering surveillance, intrusion detection, alarms and guarding, and its coverage against the areas defined; evidence monitoring is continuous, including out of hours and during holidays; records of alarms and detections in the period, with the response taken and the time to respondCommon gap: logs not retained for required periodSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.5 Protecting against physical and environmental threats
Design and apply protection against natural disasters and other physical and environmental threats.
Evidence an auditor accepts: The assessment of physical and environmental threats relevant to each site, covering natural hazards and deliberate and accidental threats; the protective measures selected against that assessment, such as fire detection and suppression, water detection, and protection against extreme weather; testing and maintenance records for protective systems, including fire suppression and detectionCommon gap: risk assessments not updated after infrastructure changesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.7 Clear desk and clear screen
Enforce clear-desk rules for papers and media and clear-screen rules for processing facilities.
Evidence an auditor accepts: The clear desk and clear screen rules, defining what must be cleared and to what standard; technical enforcement evidence for screens, such as enforced screen lock timeout configuration across the estate; evidence of physical checks or sweeps, with findings and follow upCommon gap: Policy exists but not enforcedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.10 Storage media
Manage storage media across acquisition, use, transport and disposal per classification and handling rules.
Evidence an auditor accepts: Procedures covering media across acquisition, use, transportation and disposal, tied to the classification scheme; the media register or tracking record for removable and archival media, showing location and content classification; evidence of protection in transit, including packaging, carrier selection and receipt confirmationCommon gap: No documented classification for mediaSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 7.14 Secure disposal or re-use of equipment
Verify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
Evidence an auditor accepts: The procedure for disposal and re-use of equipment containing storage media, defining the sanitisation method per media type; verification records confirming sensitive data and licensed software were removed or securely overwritten, per item; asset register entries showing the transition from in use to sanitised to disposed or reissuedCommon gap: Relying on visual inspection onlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.1 User end point devices
Protect information stored on, processed by or reachable through user endpoints.
Evidence an auditor accepts: The endpoint device policy covering corporate and personally owned devices, registration, permitted use and required protections; configuration baselines for each device type and evidence of compliance across the estate, with the percentage of devices compliant; evidence of the protective measures in force, such as full disk encryption, endpoint detection, screen lock, patch currency and restriction of administrative rightsCommon gap: Incomplete device inventorySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.2 Privileged access rights
Restrict and manage the allocation and use of privileged access.
Evidence an auditor accepts: The definition of what counts as privileged in each system, and the register of privileged accounts and their holders; authorisation records for each privileged allocation, showing the business justification and the approver; evidence of restriction, such as separate administrative accounts, multi factor authentication, session recording, vaulting or time bound elevationCommon gap: Outdated privileged account inventorySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.3 Information access restriction
Restrict access to information and assets per the access control policy.
Evidence an auditor accepts: Evidence access to information is restricted per the access control policy, sampled at the system and data level rather than only at the network level; configuration of the restriction mechanisms, such as application roles, database permissions, file share permissions and cloud storage policies; evidence of restriction on functions as well as data, including read against write against delete and exportCommon gap: infrequent or missing access reviewsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.5 Secure authentication
Implement authentication technologies and procedures based on access restrictions and policy.
Evidence an auditor accepts: The authentication standard, setting required methods against the sensitivity of the information and the access route; configuration evidence per system showing the enforced authentication, including multi factor coverage and the factors accepted; evidence of protection against brute force and credential stuffing, such as lockout, rate limiting and anomaly detectionCommon gap: Reliance on static passwords onlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.7 Protection against malware
Implement malware protection backed by user awareness.
Evidence an auditor accepts: Malware protection deployment records showing coverage across servers, endpoints, mobile devices, email and web gateways; configuration evidence including update frequency, scanning scope, real time protection and the action taken on detection; coverage reporting showing devices without protection or with outdated definitions, and the follow up on themCommon gap: Outdated malware signatures not regularly updatedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.8 Management of technical vulnerabilities
Obtain vulnerability information, evaluate exposure, and take appropriate remediation.
Evidence an auditor accepts: Defined roles and information sources for vulnerability identification, and the asset scope they cover; scan results and vulnerability inventory for the period, with authenticated scanning where applicable; the defined reaction timeline by severity, and measurement of actual remediation against itCommon gap: Relying on ad-hoc scans onlySource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.9 Configuration management
Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
Evidence an auditor accepts: Documented secure configuration baselines per platform and service, and their basis such as a recognised benchmark; evidence baselines are implemented, sampled across live systems rather than assumed from the build image; automated compliance monitoring output showing conformance and drift, with the frequency of measurementCommon gap: outdated baselinesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.10 Information deletion
Delete information in systems, devices and media when no longer required.
Evidence an auditor accepts: Deletion rules tied to retention requirements, per information type and per system; evidence of deletion actually performed, such as job records, deletion logs or reports of records removed; the method used for each medium, and evidence it renders the information unrecoverable to the required standardCommon gap: Retaining data beyond approved periodSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.11 Data masking
Use data masking in line with access policy, business need and applicable law.
Evidence an auditor accepts: The rules on masking, pseudonymisation and anonymisation, tied to the access control policy and to applicable legislation; identification of the environments and use cases where masking applies, such as development, testing, training, analytics and support; technical evidence of the masking applied, including the technique and evidence it resists re-identificationCommon gap: Masking applied inconsistently across data storesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.13 Information backup
Maintain and regularly test backups of information, software and systems per the backup policy.
Evidence an auditor accepts: The backup policy setting scope, frequency, retention and recovery objectives per system; backup job records for the period showing successes and failures, and the follow up on failures; restoration test records showing actual restores performed, what was restored and whether it met the recovery objectiveCommon gap: infrequent restore testingSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.14 Redundancy of information processing facilities
Build enough redundancy into processing facilities to meet availability requirements.
Evidence an auditor accepts: Availability requirements per service, expressed as measurable objectives; the redundancy design showing how each requirement is met, and where single points of failure remain; evidence of failover testing, with results measured against the objective and the date of the last testCommon gap: reliance on undocumented manual backupsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.15 Logging
Produce, store, protect and analyse logs of activities, exceptions and faults.
Evidence an auditor accepts: The logging standard, defining what events are logged per system type, including access, privileged action, change and failure; evidence of logging enabled, sampled across systems, with the retention period applied; evidence logs are protected against alteration and deletion, including restriction of administrator ability to modify themCommon gap: Inconsistent log collection across systemsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.16 Monitoring activities
Monitor networks, systems and applications for anomalies and act on potential incidents.
Evidence an auditor accepts: The monitoring design showing what is monitored across networks, systems and applications, and against which baseline of normal behaviour; the detection rules or analytics in use, with evidence of how they were derived and their coverage of relevant threat behaviour; the tuning record, showing rules adjusted over time, false positives reduced and gaps closedCommon gap: alerts not correlated across sourcesSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.19 Installation of software on operational systems
Securely manage software installation on production systems.
Evidence an auditor accepts: Procedures governing installation of software on operational systems, including who may install and under what authorisation; evidence of technical restriction, such as removal of installation rights, application allow listing or package repository control; records of installations performed in the period, tied to an approved changeCommon gap: Missing formal approval for installationsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.20 Networks security
Secure, manage and control networks and network devices.
Evidence an auditor accepts: Network documentation showing the current topology, zones, connections and the security controls at each boundary; configuration standards for network devices and evidence of compliance, including management plane protection; firewall and access control rule sets, with evidence of periodic review and removal of obsolete or overly permissive rulesCommon gap: outdated topology diagramsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.21 Security of network services
Identify, implement and monitor security mechanisms and service levels for network services.
Evidence an auditor accepts: Identification of network services in use, whether in house or outsourced, with their owners; the security mechanisms, service levels and management requirements defined for each service; evidence of implementation of those mechanisms, such as encryption, authentication and connection controlsCommon gap: Out‑of‑date service inventory missing recent cloud assetsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.22 Segregation of networks
Segregate groups of services, users and systems in the network.
Evidence an auditor accepts: The segregation design, showing the defined zones and the criteria placing systems, services and users into each; enforcement evidence at each boundary, such as firewall rules, access control lists or micro segmentation policy; evidence of segregation for wireless, guest, third party, management and operational technology networksCommon gap: Informal or outdated network maps used instead of documented diagramsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.23 Web filtering
Manage access to external websites to reduce exposure to malicious content.
Evidence an auditor accepts: The web filtering policy defining the categories blocked and the basis for blocking; configuration evidence showing the filtering in force, including its coverage across office, remote and mobile users; evidence of handling encrypted traffic, and any decisions taken about inspection, with the privacy considerationsCommon gap: Outdated URL category listsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.24 Use of cryptography
Define and implement rules for effective use of cryptography and key management.
Evidence an auditor accepts: The cryptography rules, defining approved algorithms, key lengths and protocols, and where cryptography must be used; evidence of implementation, sampled across data at rest, data in transit and any application layer encryption; the key management procedures covering generation, distribution, storage, rotation, revocation, archival and destructionCommon gap: Missing documented key lifecycleSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.25 Secure development life cycle
Establish and apply rules for secure development of software and systems.
Evidence an auditor accepts: The secure development rules covering the full lifecycle, from requirements through design, build, test and release; evidence the rules apply to all development, including agile teams, integration work and vendor delivered code; evidence of security activities at each stage, such as threat modelling, secure design review, code review and security testingCommon gap: Policy exists but not enforcedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.26 Application security requirements
Identify, specify and approve security requirements when developing or acquiring applications.
Evidence an auditor accepts: The method for identifying security requirements for applications, whether developed or acquired; documented and approved security requirements for applications delivered in the period, covering authentication, authorisation, data protection, logging and error handling; evidence requirements were derived from risk, from the data classification and from applicable legal obligationsCommon gap: Security requirements not formally approvedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.27 Secure system architecture and engineering principles
Establish and apply secure engineering principles to system development.
Evidence an auditor accepts: The documented secure engineering principles, such as defence in depth, least privilege, secure defaults, fail secure and minimising trust; evidence of maintenance, showing the principles are reviewed against current technology and threat; design documentation for systems delivered in the period showing the principles were appliedCommon gap: Design reviews not documentedSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.28 Secure coding
Apply secure coding principles to software development.
Evidence an auditor accepts: The secure coding standard in use, per language and framework, and evidence it was communicated to developers; evidence of application, such as static analysis configuration and results, peer review records and the treatment of findings; evidence of control over third party and open source components, including inventory, known vulnerability checking and update processCommon gap: inconsistent application of coding standardsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.29 Security testing in development and acceptance
Define and run security testing across the development life cycle.
Evidence an auditor accepts: The security testing process defining what testing is performed at which stage, and the acceptance criteria; test results for the period, covering the techniques used such as static analysis, dynamic testing, dependency scanning and penetration testing; evidence testing occurs in the development lifecycle and again at acceptance, rather than only before a major releaseCommon gap: testing only after releaseSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.30 Outsourced development
Direct, monitor and review outsourced system development.
Evidence an auditor accepts: Contractual security requirements imposed on the development supplier, covering secure development practice, testing, code ownership and the right to review; evidence of direction given, such as agreed standards, architecture constraints and acceptance criteria; evidence of monitoring during delivery, including progress and security reviews rather than acceptance testing aloneCommon gap: contracts lack specific security obligationsSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.32 Change management
Put changes to facilities and systems through change management procedures.
Evidence an auditor accepts: The change management procedure covering the types of change, the authorisation required and the route for emergency change; change records for the period, showing risk and security impact assessment, testing evidence, approval and implementation record; evidence of segregation between the person requesting, approving and implementing a changeCommon gap: missing formal approvalSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022 ISO 27001 8.33 Test information
Select, protect and manage test information appropriately.
Evidence an auditor accepts: Rules on selecting test information, showing preference for synthetic or masked data over production copies; authorisation records where production information is used for testing, including who approved and for how long; evidence of protection of test information equivalent to its classification, including access control and deletion after useCommon gap: Treating test data like production data without classificationSource: ISO/IEC 27001:2022; guidance
ISO/IEC 27002:2022