Audit tests and other assurance activities that assess operational systems need a plan agreed in advance by whoever tests and the relevant managers. Purpose: keep the effect of audits and other assurance work on operational systems and business processes as small as possible. Guidance: get the relevant managers to agree what systems and data auditors may reach; agree and control the scope of technical audit tests; keep audit tests to read-only use of software and data, and where read-only access cannot obtain the needed information, have an experienced administrator with the required rights run the test for the auditor; if access is granted, set and check the security requirements, such as anti-virus and patching, of the laptops or tablets used before allowing access; allow wider access only to separate copies of system files, removing those copies after the audit or protecting them appropriately if audit documentation rules require keeping them; identify and agree requests for special or extra processing such as running audit tools; run tests that could affect availability outside business hours; and monitor and record every access made for audits or tests. Audits and assurance tests on development and test systems can also affect code integrity or expose sensitive information held there.
This control maps to 32 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 8.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.