ISO/IEC 27000 Protection of Information Systems During Audit Testing, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to protection of information systems during audit testing.
Assessment Step
1
Protection of Information Systems During Audit Testing (ProtectionofInformationSystemsDuringAuditTesting)
Are audit tests and other assurance activities involving the assessment of operational systems planned and agreed between the tester and appropriate management?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Protection of Information Systems During Audit Testing
Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.
Citations
27001
Annex A, Control 8.34
27002
Section 8.34
|