ISO27001:2022 – A8.34

Protection of information systems during audit and testing

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.34

The purpose of ISO 27001 – A8.34 is to minimise the impact audits and other assurance activities might have on operational systems and business processes. No matter if it is during operational audits or testing of systems, this control expects you to ensure these are planned and signed off at an appropriate level in your business. 

Let’s explore what this final, ISO27001 Annex A control expects and why it’s necessary. 

What does the standard require?

The standard states that “Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.” (A8.34 – Protection of information systems during audit and testing) 

Clause 9.2 (Internal Audit) of ISO27001 Information Security Management System is focused on internal audits, but ISO 27001 – A8.34 is specifically focused on activities involving assessment of operational systems. Therefore, this control is specifically looking at technical aspects of audit tests and assessments which need to be planned and agreed. 

Why is this required?

Conducting tests and audits of your systems can introduce risks that may inadvertently interrupt the systems and result in business disruption. 

We worked with a business that experienced a significant outage when someone conducted a Penetration Test without informing the development team.  Although testing often happens with minimum knowledge of the business, if the development team knew that there was a ‘freeze’ on new releases, then it might have prevented the test on systems which were being upgraded at the time as invasive testing was taking place. 

If you undertake audits and vulnerability assessments while running updates or backing up data, then it could affect the integrity and availability of the systems. It might also invalidate the test or assessment, rendering it pointless as the results can’t be trusted. 

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

What do you need to do?

Note that the control doesn’t say how often tests and assessments need to be carried out, only that they need to be planned and agreed. 

Therefore, the first step is to speak to your ITC team to understand what technical assessments and tests are conducted, and when.  Are Vulnerability Assessments run weekly? Monthly? What about Penetration Tests? How is the scope agreed and when are these conducted?

 To ensure that there is no business impact, speak to your Management Review Team (MRT) to establish when it would be appropriate to run any assessments or tests. For example, you probably shouldn’t conduct any tests when the Finance team are running their month-end or year-end reports. It’s also probably a bad idea to conduct tests when the payroll is being processed or when your business is about to launch a new product or service.  

Keep in mind busy periods for your business, so that resources are not stretched and that they are available to help should something go wrong.

 Some will say cyber criminals don’t wait until the business is ready, and that they will carry out an attack at the worse possible time. We would agree with that, but we aren’t cyber criminals. Our goal is not to cause damage to the systems or the business.

It is important for you to be clear about the scope of your test, and what you are trying to achieve, and I would guess that making an enemy of your internal teams is not what you’re trying to do! Cyber criminals don’t care what damage they cause – but you do!

Once you know how your business operates, and what the busy periods are, we would suggest adding the tests and assessments to your ‘Internal Audit Plan’. This is because you’ll be discussing with your Management Review Team (MRT), the scope and timing of the assessments. It also gives you a single view of activities across your business and ISMS, which allows you to satisfy the second requirement.

You need to ensure that you communicate any assessments or tests appropriately to your business. This doesn’t mean announcing exactly when you’re going to conduct the test (although that may be appropriate).

For example, you might consider communicating to your development team that you will conduct a test between two dates. This will allow them either to freeze any business changes, or challenge the timescales.

Once the dates are agreed, note this within your MRT minutes so that you can provide evidence that tests and assessments have been agreed. 

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. The difficulty in this control is that you need to carefully plan your tests and assessments so that they do not put your business at risk.

Q&A

When is the best time to run tests and assessments?

The obvious answers is to run tests and assessments outside normal business hours. However, updates to systems are typically applied and backups are also usually carried out, outside of normal business hours. 

Speak to your IT team and Development teams to understand how they conduct these activities so that you can run your tests at an appropriate time.

More questions?

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.34 – Protection of information systems during audit and testing