ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.35: Independent review of information security

How the organization manages information security, and how that is carried out through people, processes and technology, is to be examined by someone independent on a planned cycle and whenever a significant change occurs. Purpose: keep the way information security is managed suitable, adequate and effective over time. Guidance: have processes for independent review, which management plans and initiates periodically. Reviews assess improvement opportunities and whether the approach needs changing, covering the top-level policy, the topic policies and the other controls. Reviewers are independent of the area reviewed (for example internal audit, a manager from elsewhere or a specialist external firm), competent, and outside the line of authority for that area. Results go to the management that commissioned the review and, where appropriate, to top management, and records are kept. Where a review finds the approach or implementation inadequate, for example objectives and requirements not met or practice not in line with the policies (5.1), management starts corrective action. Beyond the periodic cycle, consider an independent review when relevant laws and regulations change, after significant incidents, when a new business is started or an existing one changes, when a product or service is newly adopted or used differently, and when security controls and procedures change substantially. Guidance on conducting such reviews is in ISO/IEC 27007 and in ISO/IEC TS 27008.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 163 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 13 controls

  • AC-22 Publicly Accessible Content
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-6 Authorization
  • CA-7(1) Independent Assessment
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CM-7(1) Periodic Review
  • CP-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • RA-3 Risk Assessment
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 13 controls

  • AC-22 Publicly Accessible Content
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-6 Authorization
  • CA-7(1) Independent Assessment
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CM-7(1) Periodic Review
  • CP-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • RA-3 Risk Assessment
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SR-1 Policy and Procedures (SR-1)

NIST SP 800-53 Rev 5 · 13 controls

ISO 22301:2019 · 12 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 4.4 Business continuity management system
  • 6.1.2 Addressing risks and opportunities
  • 8.3.1 General
  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.2.1 General
  • 9.2.2 Audit programme(s)
  • 9.3 Management review
  • 9.3.2 Management review input

ISO 27701:2019 · 9 controls

  • 5.7 Performance evaluation
  • 5.7.2 Internal audit
  • 5.7.3 Management review
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 6.9.7 Information systems audit considerations

ISO/IEC 42001:2023 · 9 controls

  • 10.1 Continual improvement
  • 10.2 Nonconformity and corrective action
  • 6.1.3 AI risk treatment
  • 6.1.4 AI system impact assessment
  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • 9.3 Management review
  • A.3 Internal organization
  • A.5 Assessing impacts of AI systems

PCI DSS 4.0 · 9 controls

  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 4 controls

  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • ISM-0100 IRAP assessment of gateways
  • ISM-1563 Security assessment report
  • ISM-1636 Security assessment by organisational or IRAP assessors
  • ISM-2019 ASD assessment of TOP SECRET gateways

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)

C5 (Germany) · 3 controls

  • C5-COM-02 Policy for planning and conducting audits
  • C5-COM-03 Internal audits of the information security management system
  • C5-COM-04 Information on information security performance and management assessment of the ISMS

NIS2 Directive · 3 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
  • 53A-3.1 Prepare for Control Assessments
  • 53A-3.3 Conduct Control Assessments
  • 53A-E Assessment Reports

CIS Controls v8 · 2 controls

  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.5 Perform Periodic Internal Penetration Tests

CMMC 2.0 · 2 controls

GDPR · 2 controls

ISO 27001:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

MTCS (Singapore) · 2 controls

  • 18.7 Physical security review
  • 6.7 Information security audits

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • NRC-73.54(h) Cyber Security Program Review
  • NRC7354-8 Programme Oversight, Independent Review, Documentation, Training, Supply Chain
  • AMLCTF-PartA-Review Independent Review
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CERT.IND Independent certification (iRAP or ISO/IEC 27001) where the category requires it
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AEO-13 Measurement, Analyses and Improvement

DORA · 1 control

ISO 19011:2018 · 1 control

  • 6.4.5 Audit information availability and access

ISO 27018:2019 · 1 control

  • 18.2.1 Independent review of information security

ISO/IEC 27041:2015 · 1 control

  • 6.1 6.1 Overview

NY DFS 23 NYCRR 500 · 1 control

  • 6.1.9.C.01 6.1.9.C.01 Components and triggers for information security reviews
  • TSA-SD-09 Annual Cybersecurity Assessment Plan
  • MTSA-Audit Annual Audit of the Security Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.35 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.