What is ISO 27001 Annex A 5.35 – Independent Review of Information Security?
ISO 27001 Annex A 5.35 requires the organization to ensure that its approach to managing information security is independently reviewed at planned intervals or when significant changes occur.
In simple terms:
Someone sufficiently independent of the activity being reviewed should periodically examine whether the organization’s information security arrangements are appropriate, effective, and aligned with its requirements.
The purpose is to provide an independent perspective.
The review can examine areas such as:
- Information security governance
- ISMS implementation
- Security policies
- Risk management
- Access control
- Incident management
- Business continuity
- Supplier security
- Vulnerability management
- Security monitoring
- Compliance
- Technical controls
- Previous audit findings
- Corrective actions
Why is A.5.35 Important?
Organizations naturally develop blind spots.
The people responsible for implementing security may not always identify:
- Control weaknesses
- Missing evidence
- Outdated procedures
- Excessive access
- Unresolved risks
- Inconsistent implementation
- Poorly designed processes
- Repeated audit findings
An independent review introduces another perspective.
Simple Principle
“Do not rely only on the people who operate a control to determine whether the control is working.”
Independent review can help management understand whether the information security program is actually operating as intended.
What Does “Independent” Mean?
Independence does not necessarily mean:
“Hire an external Big Four consulting company.”
The level of independence should be appropriate to the organization’s size, structure, risks, and circumstances.
The reviewer should have sufficient separation from the activity being reviewed so that the review is objective.
Example
If the IT manager is responsible for administering privileged accounts, that same person should not be the only person performing an independent review of whether privileged access is appropriately controlled.
A different person, internal audit function, qualified security professional, or external specialist could perform the review.
Internal vs. External Independent Review
Both approaches may be appropriate depending on the organization.
Internal Review
A person or team within the organization performs a review while maintaining appropriate independence from the activities being reviewed.
Examples:
- Internal audit
- Compliance team
- Security governance team
- Qualified reviewer from another department
External Review
An independent third party performs the review.
Examples:
- Information security consultant
- Independent auditor
- Cybersecurity specialist
- External internal-audit provider
- Qualified security assessment firm
External reviews can be particularly useful for smaller organizations that do not have a dedicated internal audit function.
Important: Independent Review vs. Certification Audit
These activities are related but different.
| Activity | Purpose |
|---|---|
| Internal/Independent Review | Provide an independent assessment of the organization’s information security arrangements |
| Certification Audit | Determine whether the ISMS meets the applicable certification requirements |
| Penetration Test | Identify technical security weaknesses |
| Management Review | Management evaluates the ISMS and its continuing suitability and effectiveness |
| Compliance Review | Evaluate compliance with specific requirements |
A penetration test, for example, should not automatically be treated as the organization’s complete independent information security review.
When Should an Independent Review Be Performed?
A.5.35 expects reviews at planned intervals and when significant changes occur.
A review may be triggered by:
- Major organizational changes
- New business model
- New geographic market
- Major technology changes
- Cloud migration
- Acquisition or merger
- Significant security incident
- Major regulatory change
- New customer security requirements
- Significant changes to the ISMS
- Major supplier changes
- Significant changes in risk
The organization should define an appropriate review frequency based on its circumstances.
Activities Required to Implement A.5.35
1. Define the Independent Review Process
Document:
- Purpose
- Scope
- Frequency
- Reviewer qualifications
- Independence requirements
- Review methodology
- Reporting process
- Corrective action process
- Follow-up process
2. Determine the Review Scope
The review can cover some or all relevant aspects of information security.
For example:
Governance
- Security policies
- Roles and responsibilities
- Management oversight
Risk Management
- Risk assessment
- Risk treatment
- Risk acceptance
Operational Security
- Access management
- Incident management
- Vulnerability management
- Backup
- Change management
Compliance
- Legal requirements
- Contractual requirements
- Customer requirements
Technical Security
- Network security
- Endpoint protection
- Cloud security
- Logging and monitoring
3. Select an Appropriate Reviewer
The reviewer should have suitable:
- Knowledge
- Skills
- Experience
- Independence
- Understanding of the review scope
For a technical review, technical expertise may be necessary.
For an ISMS review, knowledge of information security governance and ISO 27001 may be appropriate.
4. Establish Independence
Before the review begins, consider whether the reviewer has a conflict of interest.
Ask:
“Was this person responsible for designing or operating the control being reviewed?”
If yes, additional safeguards may be needed.
For example:
A security engineer who implemented the firewall rules could provide technical information during the review but should not necessarily be the sole reviewer determining whether those rules are adequate.
5. Prepare a Review Plan
A review plan might define:
- Scope
- Objectives
- Review criteria
- Systems
- Processes
- Departments
- Interviews
- Evidence required
- Sampling
- Review dates
- Reporting format
Example:
| Area | Review Objective |
|---|---|
| Access Control | Determine whether access is appropriately managed |
| Incident Management | Determine whether incidents are handled according to procedure |
| Supplier Security | Determine whether critical suppliers are appropriately assessed |
| Backup | Determine whether backup and restoration controls operate effectively |
| Risk Management | Determine whether risks are identified and treated |
| Compliance | Determine whether key obligations are addressed |
6. Collect Evidence
An independent review should be evidence-based.
Evidence may include:
- Policies
- Procedures
- Risk registers
- Access reviews
- System configurations
- Logs
- Incident records
- Audit reports
- Training records
- Supplier assessments
- Backup tests
- Vulnerability reports
- Corrective action records
The reviewer should avoid relying solely on verbal statements.
7. Evaluate Effectiveness
The reviewer should consider not only:
“Does a policy exist?”
but also:
“Is the policy implemented and working?”
For example:
Policy: Quarterly access reviews are required.
The reviewer should check:
- Was the review performed?
- Was it performed on time?
- Was evidence retained?
- Were inappropriate accesses identified?
- Were corrections completed?
8. Document Findings
Findings should be documented clearly.
Example:
| Finding | Risk | Evidence | Owner | Due Date |
|---|---|---|---|---|
| Privileged access review not completed for Q2 | Medium | Access review record | IT | 30 days |
| Supplier assessment overdue | Medium | Supplier register | Procurement | 45 days |
| Incident procedure outdated | Low | Procedure review | Security | 30 days |
The organization should distinguish between:
- Nonconformities
- Control weaknesses
- Observations
- Improvement opportunities
The terminology can depend on the organization’s review methodology.
9. Report Results to Management
The review should produce a report appropriate to the organization’s needs.
A useful report can include:
- Executive summary
- Scope
- Review criteria
- Methodology
- Areas reviewed
- Findings
- Risk implications
- Recommendations
- Management responses
- Corrective actions
10. Track Corrective Actions
An independent review has limited value if findings are simply recorded and forgotten.
Track:
- Finding
- Action
- Owner
- Priority
- Due date
- Status
- Closure evidence
- Verification
11. Perform Follow-Up
For significant findings, verify that corrective actions were actually implemented.
Example:
Finding
→ Excessive privileged access
Action
→ Remove unnecessary privileges
Verification
→ Review updated access list
Closure
→ Evidence retained
Startup Example
Consider a SaaS startup with 30 employees.
The CTO manages the technology environment.
The company decides to perform an annual independent information security review.
Instead of asking the CTO to review his own security program, the startup engages an independent security professional.
The reviewer examines:
- ISMS scope
- Risk register
- Access controls
- Supplier security
- Incident management
- Backup
- Vulnerability management
- Security monitoring
- Business continuity
- Previous findings
The reviewer identifies:
- Two former contractors still listed in an access register.
- One critical supplier assessment is overdue.
- Backup restoration testing has not been performed as planned.
- One security procedure is outdated.
The startup assigns:
- Owners
- Priorities
- Due dates
and tracks remediation to closure.
Review Flow
Plan
↓
Independent Reviewer
↓
Collect Evidence
↓
Evaluate Controls
↓
Identify Findings
↓
Report Management
↓
Corrective Actions
↓
Follow-Up
This provides management with an independent view of the ISMS.
Startup-Focused Quick Summary
A startup does not necessarily need a large internal audit department.
A practical model is:
1. Define
What should be independently reviewed?
2. Select
Choose a suitably qualified and sufficiently independent reviewer.
3. Review
Evaluate policies, processes, controls and evidence.
4. Report
Document findings and improvement opportunities.
5. Remediate
Assign owners and deadlines.
6. Verify
Confirm that important issues have been addressed.
Simple Model
Plan → Independently Review → Report → Correct → Verify
Example Independent Review Plan
| Review Area | Scope | Evidence |
|---|---|---|
| ISMS Governance | Policies, roles, objectives | ISMS documents |
| Risk Management | Risk assessment and treatment | Risk register |
| Access Management | User and privileged access | Access reviews |
| Incident Management | Incident process | Incident records |
| Supplier Security | Critical suppliers | Supplier assessments |
| Business Continuity | ICT continuity | DR/BCP evidence |
| Vulnerability Management | Vulnerability identification and remediation | Scan reports |
| Backup | Backup and restoration | Restore test |
| Compliance | Key obligations | Compliance register |
| Corrective Actions | Previous findings | Action tracker |
Example Independent Review Report Structure
A practical report may contain:
1. Executive Summary
High-level results for management.
2. Review Objective
Why the review was performed.
3. Scope
Systems, departments, locations and controls covered.
4. Criteria
Policies, ISO 27001 requirements, contractual requirements or other criteria used.
5. Methodology
- Interviews
- Document review
- Evidence sampling
- Technical validation
- Observation
6. Findings
Detailed observations and weaknesses.
7. Risk/Impact
Potential consequences associated with findings.
8. Recommendations
Suggested improvements.
9. Management Response
Management’s planned actions.
10. Corrective Action Plan
Owners and due dates.
11. Follow-Up
Verification of completed actions.
Audit Evidence for A.5.35
An auditor may request:
Governance
- Independent Review Policy/Procedure
- Annual review plan
- Review schedule
Reviewer
- Reviewer qualifications
- Reviewer independence/conflict assessment
- External engagement agreement where applicable
Review
- Review plan
- Review checklist
- Interview records
- Evidence sampling
- Review working papers
Results
- Independent review report
- Findings
- Recommendations
- Management response
Corrective Actions
- Corrective action tracker
- Assigned owners
- Due dates
- Closure evidence
- Follow-up review
A.5.35 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Is independent information security review planned? | Review schedule |
| Is the review performed at defined intervals? | Previous reports |
| Are significant changes considered as review triggers? | Review records |
| Is the reviewer sufficiently independent? | Independence assessment |
| Does the reviewer have appropriate competence? | Qualifications/experience |
| Is the review scope defined? | Review plan |
| Are objective criteria established? | Review criteria |
| Is evidence collected? | Working papers |
| Are findings documented? | Review report |
| Are findings communicated to management? | Management report |
| Are corrective actions assigned? | Action tracker |
| Are due dates established? | Action tracker |
| Are significant findings followed up? | Closure evidence |
| Are recurring findings identified? | Trend/review records |
Common Mistakes
1. Reviewing Your Own Work
The person responsible for operating a control should not automatically be considered sufficiently independent to provide an independent assessment of that same control.
2. Treating an Internal Audit as a Paper Exercise
An independent review should examine evidence rather than simply confirming that documents exist.
3. Checking Only Policies
A policy may say:
“Access reviews are performed quarterly.”
The reviewer should verify whether the reviews actually happened.
4. No Defined Review Frequency
An organization should establish an appropriate planned interval rather than performing reviews only when an external auditor asks for them.
5. No Review After Significant Changes
Major changes can introduce new risks.
Examples:
- Cloud migration
- Acquisition
- New product
- New country
- Major customer
- Significant security incident
6. Findings Without Owners
A finding without an owner is unlikely to be resolved effectively.
7. No Follow-Up
Closing the review report does not necessarily mean that the security weakness has been corrected.
8. Confusing Independent Review With Penetration Testing
A penetration test can provide valuable technical assurance, but it does not necessarily constitute an independent review of the organization’s overall information security management arrangements.
Practical Startup Implementation Model
A startup can implement A.5.35 with a lightweight annual process.
Step 1 – Define Scope
Identify what should be independently reviewed.
Step 2 – Identify Reviewer
Select an appropriately qualified and sufficiently independent person or organization.
Step 3 – Plan
Define objectives, criteria, evidence and schedule.
Step 4 – Review
Evaluate controls and supporting evidence.
Step 5 – Report
Document findings and recommendations.
Step 6 – Correct
Assign owners and deadlines.
Step 7 – Verify
Confirm that significant findings have been addressed.
Simple Model
Scope → Select → Plan → Review → Report → Correct → Verify
Policy vs. Process vs. Evidence
| Type | Example |
|---|---|
| Policy | Information Security Review Policy |
| Process | Independent Security Review Procedure |
| Process | Internal Audit Procedure |
| Document | Annual Security Review Plan |
| Document | Independent Review Checklist |
| Document | Review Report |
| Evidence | Reviewer qualification |
| Evidence | Independence assessment |
| Evidence | Review working papers |
| Evidence | Findings register |
| Evidence | Corrective action tracker |
| Evidence | Follow-up verification |
Remember
Policy = What the organization requires
Process = How independent reviews are performed
Report = What the reviewer found
Evidence = Proof that the review happened and findings were addressed
Relationship With Other ISO 27001 Controls
A.5.35 connects with several other controls.
| Control | Relationship |
|---|---|
| A.5.1 Policies for Information Security | Independent review can evaluate whether security policies remain appropriate |
| A.5.31 Legal/Regulatory/Contractual Requirements | Reviews can assess how applicable obligations are addressed |
| A.5.34 Privacy and Protection of PII | Reviews may examine privacy-related security controls |
| A.5.36 Compliance with Policies, Rules and Standards | A.5.36 focuses on checking compliance with established requirements |
| A.5.37 Documented Operating Procedures | Reviews can assess whether procedures are current and followed |
| A.8.8 Management of Technical Vulnerabilities | Technical security controls may be included in the review |
| A.8.15 Logging | Reviewers may examine logging and audit evidence |
| A.8.16 Monitoring Activities | Review can assess security monitoring effectiveness |
| A.8.32 Change Management | Review may assess whether changes are appropriately controlled |
A.5.35 vs. A.5.36
These controls are related but should not be treated as identical.
| Control | Main Question |
|---|---|
| A.5.35 Independent Review | “Has information security been independently reviewed?” |
| A.5.36 Compliance with Policies, Rules and Standards | “Are people and systems complying with the organization’s established security requirements?” |
Example
A.5.35
An independent reviewer examines the organization’s access-control program.
A.5.36
The organization checks whether employees and administrators are actually following its access-control policies and procedures.
Both can provide assurance, but they address different objectives.
Useful Documents for A.5.35
- Independent Information Security Review Procedure – [Insert Draft Document Link]
- Annual Security Review Plan – [Insert Draft Document Link]
- Independent Reviewer Assessment Checklist – [Insert Draft Document Link]
- Information Security Review Checklist – [Insert Draft Document Link]
- Independent Review Report Template – [Insert Draft Document Link]
- Security Findings Register – [Insert Draft Document Link]
- Corrective Action Tracker – [Insert Draft Document Link]
- Independent Review Follow-Up Checklist – [Insert Draft Document Link]
Questions an Auditor May Ask
Independence
- Who performed your last independent information security review?
- Why was that person considered independent?
- Was the reviewer responsible for operating the controls being reviewed?
Scope
- What areas were reviewed?
- How was the scope determined?
- What criteria were used?
Evidence
- What evidence did the reviewer examine?
- Can you show me the review report?
- Were technical controls included?
Findings
- What findings were identified?
- Which findings were considered significant?
- Who was assigned to address them?
Follow-Up
- Have the findings been remediated?
- Can you show evidence of closure?
- Were any findings repeated from previous reviews?
Startup-Focused Final Takeaway
ISO 27001 Annex A 5.35 is about creating independent assurance around information security.
The goal is not simply to produce another audit report.
The real objective is to identify weaknesses that the organization’s normal operating teams may not see.
For a startup, the process can remain simple:
Plan the review
↓
Use a suitably independent and competent reviewer
↓
Examine actual evidence
↓
Identify weaknesses
↓
Report to management
↓
Assign corrective actions
↓
Verify important issues are resolved
The practical auditor question is:
“Who independently reviews your information security arrangements, how do you ensure that reviewer is sufficiently independent, what did the review identify, and what did you do about the findings?”
That is the practical objective of ISO 27001 Annex A 5.35 – Independent Review of Information Security.
