ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.34: Protection of information systems during audit testing

Audit tests and other assurance activities that assess operational systems need a plan agreed in advance by whoever tests and the relevant managers. Purpose: keep the effect of audits and other assurance work on operational systems and business processes as small as possible. Guidance: get the relevant managers to agree what systems and data auditors may reach; agree and control the scope of technical audit tests; keep audit tests to read-only use of software and data, and where read-only access cannot obtain the needed information, have an experienced administrator with the required rights run the test for the auditor; if access is granted, set and check the security requirements, such as anti-virus and patching, of the laptops or tablets used before allowing access; allow wider access only to separate copies of system files, removing those copies after the audit or protecting them appropriately if audit documentation rules require keeping them; identify and agree requests for special or extra processing such as running audit tools; run tests that could affect availability outside business hours; and monitor and record every access made for audits or tests. Audits and assurance tests on development and test systems can also affect code integrity or expose sensitive information held there.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 32 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

PCI DSS 4.0 · 4 controls

  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan

SOC 2 · 4 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

PTES · 3 controls

  • PTES-1.1 Define and record the scope in writing before testing
  • PTES-1.4 Agree the rules of engagement: how, when and where testing occurs
  • PTES-3.1 Keep intelligence gathering within scope and the rules of engagement
  • 53A-3.2.6 Finalize the Assessment Plan and Obtain Approval
  • 53A-D Penetration Testing

C5 (Germany) · 1 control

  • C5-COM-02 Policy for planning and conducting audits

CIS Controls v8 · 1 control

  • CIS-18.1 Establish and Maintain a Penetration Testing Program

DORA · 1 control

  • DORA-Art.26 Advanced testing of ICT tools, systems and processes based on TLPT

FedRAMP High · 1 control

  • CA-2 Control Assessments

FedRAMP Moderate · 1 control

  • CA-2 Control Assessments

ISO 22301:2019 · 1 control

ISO 27001:2022 · 1 control

  • 8.34 Protection of information systems during audit testing 

ISO 27701:2019 · 1 control

  • 6.9.7 Information systems audit considerations

NIS2 Directive · 1 control

  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.