A.8.34A.8 Technological controls

Protection of information systems during audit testing

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.34 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Plan and agree audit and assurance activities on operational systems with management to minimise their impact.

How to meet this control

In short: Plan and agree audit tests to minimise disruption to systems.

  1. Step 01Agree audit scope, timing and access with management before any audit or assurance testing on operational systems
  2. Step 02Limit audit tests to read-only access, or have an experienced administrator run anything beyond read-only
  3. Step 03Verify the security of the devices and accounts the auditor will use before granting access
  4. Step 04Work from isolated copies of system files where possible and delete them after the audit
  5. Step 05Schedule tests that could affect availability outside business hours
  6. Step 06Monitor and log all access made for audit purposes and review it afterward

Tip: Agree scope, timing and read-only access with auditors in advance.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Agree audit requests for access to systems and data with appropriate management beforehand
  • ›Agree and control the scope of technical audit tests
  • ›Limit audit tests to read-only access, or have an experienced administrator run them otherwise
  • ›Verify the security of the devices used before allowing audit access
  • ›Allow only read-only access to isolated copies of system files and delete them after the audit
  • ›Identify and agree any requests for special or additional processing
  • ›Schedule audit tests that can affect availability outside business hours
  • ›Monitor and log all access made for audit and test purposes

Audit evidence to keep

  • - Agreed audit plan with scope, timing and access approved by management
  • - Evidence audit access was read-only or supervised
  • - Verification of the auditor device and account security
  • - Logs of access made during the audit
  • - Record confirming isolated copies were deleted after the audit

Common mistakes

  • - Treating security review as optional when release pressure rises
  • - Testing only happy paths and missing abuse cases
  • - Not linking production changes to approvals and rollback plans

Owner, cadence, and proof

Assign one accountable owner for A.8.34. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.