A.5.35A.5 Organizational controls

Independent review of information security

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.35 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Have your approach to managing information security reviewed independently at planned intervals and after significant changes.

How to meet this control

In short: Have the security approach reviewed independently at planned intervals.

  1. Step 01Schedule independent reviews of the ISMS at planned intervals using internal audit or an external assessor
  2. Step 02Use reviewers independent of the area being reviewed and outside its line of authority
  3. Step 03Report findings to the management that commissioned the review and to top management where appropriate
  4. Step 04Trigger additional reviews after major incidents, legal changes or significant business change
  5. Step 05Track corrective actions from each review to closure and keep the records

Tip: Internal audit by someone independent of the area, or an external reviewer.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Establish processes for conducting independent reviews
  • ›Have management plan and initiate periodic reviews that look for improvement opportunities
  • ›Use reviewers independent of the area being reviewed, such as internal audit or an external party
  • ›Ensure reviewers have the right competence and are outside the line of authority being assessed
  • ›Report results to the management that initiated the review and, if appropriate, to top management
  • ›Have management start corrective actions when reviews find the approach inadequate
  • ›Trigger extra reviews when laws change, major incidents occur or the business changes significantly
  • ›Maintain records of the reviews

Audit evidence to keep

  • - Internal audit plan and reports covering the ISMS at planned intervals
  • - Evidence reviewers are independent of the area reviewed
  • - Corrective action records arising from review findings, tracked to closure
  • - Reports of independent reviews delivered to management

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.35. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.