ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.35 Independent review of information security

ISO 27001 Annex A 5.35 Independent review of information security

What is ISO 27001 Annex A 5.35 – Independent Review of Information Security?

ISO 27001 Annex A 5.35 requires the organization to ensure that its approach to managing information security is independently reviewed at planned intervals or when significant changes occur.

In simple terms:

Someone sufficiently independent of the activity being reviewed should periodically examine whether the organization’s information security arrangements are appropriate, effective, and aligned with its requirements.

The purpose is to provide an independent perspective.

The review can examine areas such as:

  • Information security governance
  • ISMS implementation
  • Security policies
  • Risk management
  • Access control
  • Incident management
  • Business continuity
  • Supplier security
  • Vulnerability management
  • Security monitoring
  • Compliance
  • Technical controls
  • Previous audit findings
  • Corrective actions

Why is A.5.35 Important?

Organizations naturally develop blind spots.

The people responsible for implementing security may not always identify:

  • Control weaknesses
  • Missing evidence
  • Outdated procedures
  • Excessive access
  • Unresolved risks
  • Inconsistent implementation
  • Poorly designed processes
  • Repeated audit findings

An independent review introduces another perspective.

Simple Principle

“Do not rely only on the people who operate a control to determine whether the control is working.”

Independent review can help management understand whether the information security program is actually operating as intended.


What Does “Independent” Mean?

Independence does not necessarily mean:

“Hire an external Big Four consulting company.”

The level of independence should be appropriate to the organization’s size, structure, risks, and circumstances.

The reviewer should have sufficient separation from the activity being reviewed so that the review is objective.

Example

If the IT manager is responsible for administering privileged accounts, that same person should not be the only person performing an independent review of whether privileged access is appropriately controlled.

A different person, internal audit function, qualified security professional, or external specialist could perform the review.


Internal vs. External Independent Review

Both approaches may be appropriate depending on the organization.

Internal Review

A person or team within the organization performs a review while maintaining appropriate independence from the activities being reviewed.

Examples:

  • Internal audit
  • Compliance team
  • Security governance team
  • Qualified reviewer from another department

External Review

An independent third party performs the review.

Examples:

  • Information security consultant
  • Independent auditor
  • Cybersecurity specialist
  • External internal-audit provider
  • Qualified security assessment firm

External reviews can be particularly useful for smaller organizations that do not have a dedicated internal audit function.


Important: Independent Review vs. Certification Audit

These activities are related but different.

ActivityPurpose
Internal/Independent ReviewProvide an independent assessment of the organization’s information security arrangements
Certification AuditDetermine whether the ISMS meets the applicable certification requirements
Penetration TestIdentify technical security weaknesses
Management ReviewManagement evaluates the ISMS and its continuing suitability and effectiveness
Compliance ReviewEvaluate compliance with specific requirements

A penetration test, for example, should not automatically be treated as the organization’s complete independent information security review.


When Should an Independent Review Be Performed?

A.5.35 expects reviews at planned intervals and when significant changes occur.

A review may be triggered by:

  • Major organizational changes
  • New business model
  • New geographic market
  • Major technology changes
  • Cloud migration
  • Acquisition or merger
  • Significant security incident
  • Major regulatory change
  • New customer security requirements
  • Significant changes to the ISMS
  • Major supplier changes
  • Significant changes in risk

The organization should define an appropriate review frequency based on its circumstances.


Activities Required to Implement A.5.35

1. Define the Independent Review Process

Document:

  • Purpose
  • Scope
  • Frequency
  • Reviewer qualifications
  • Independence requirements
  • Review methodology
  • Reporting process
  • Corrective action process
  • Follow-up process

2. Determine the Review Scope

The review can cover some or all relevant aspects of information security.

For example:

Governance

  • Security policies
  • Roles and responsibilities
  • Management oversight

Risk Management

  • Risk assessment
  • Risk treatment
  • Risk acceptance

Operational Security

  • Access management
  • Incident management
  • Vulnerability management
  • Backup
  • Change management

Compliance

  • Legal requirements
  • Contractual requirements
  • Customer requirements

Technical Security

  • Network security
  • Endpoint protection
  • Cloud security
  • Logging and monitoring

3. Select an Appropriate Reviewer

The reviewer should have suitable:

  • Knowledge
  • Skills
  • Experience
  • Independence
  • Understanding of the review scope

For a technical review, technical expertise may be necessary.

For an ISMS review, knowledge of information security governance and ISO 27001 may be appropriate.


4. Establish Independence

Before the review begins, consider whether the reviewer has a conflict of interest.

Ask:

“Was this person responsible for designing or operating the control being reviewed?”

If yes, additional safeguards may be needed.

For example:

A security engineer who implemented the firewall rules could provide technical information during the review but should not necessarily be the sole reviewer determining whether those rules are adequate.


5. Prepare a Review Plan

A review plan might define:

  • Scope
  • Objectives
  • Review criteria
  • Systems
  • Processes
  • Departments
  • Interviews
  • Evidence required
  • Sampling
  • Review dates
  • Reporting format

Example:

AreaReview Objective
Access ControlDetermine whether access is appropriately managed
Incident ManagementDetermine whether incidents are handled according to procedure
Supplier SecurityDetermine whether critical suppliers are appropriately assessed
BackupDetermine whether backup and restoration controls operate effectively
Risk ManagementDetermine whether risks are identified and treated
ComplianceDetermine whether key obligations are addressed

6. Collect Evidence

An independent review should be evidence-based.

Evidence may include:

  • Policies
  • Procedures
  • Risk registers
  • Access reviews
  • System configurations
  • Logs
  • Incident records
  • Audit reports
  • Training records
  • Supplier assessments
  • Backup tests
  • Vulnerability reports
  • Corrective action records

The reviewer should avoid relying solely on verbal statements.


7. Evaluate Effectiveness

The reviewer should consider not only:

“Does a policy exist?”

but also:

“Is the policy implemented and working?”

For example:

Policy: Quarterly access reviews are required.

The reviewer should check:

  • Was the review performed?
  • Was it performed on time?
  • Was evidence retained?
  • Were inappropriate accesses identified?
  • Were corrections completed?

8. Document Findings

Findings should be documented clearly.

Example:

FindingRiskEvidenceOwnerDue Date
Privileged access review not completed for Q2MediumAccess review recordIT30 days
Supplier assessment overdueMediumSupplier registerProcurement45 days
Incident procedure outdatedLowProcedure reviewSecurity30 days

The organization should distinguish between:

  • Nonconformities
  • Control weaknesses
  • Observations
  • Improvement opportunities

The terminology can depend on the organization’s review methodology.


9. Report Results to Management

The review should produce a report appropriate to the organization’s needs.

A useful report can include:

  • Executive summary
  • Scope
  • Review criteria
  • Methodology
  • Areas reviewed
  • Findings
  • Risk implications
  • Recommendations
  • Management responses
  • Corrective actions

10. Track Corrective Actions

An independent review has limited value if findings are simply recorded and forgotten.

Track:

  • Finding
  • Action
  • Owner
  • Priority
  • Due date
  • Status
  • Closure evidence
  • Verification

11. Perform Follow-Up

For significant findings, verify that corrective actions were actually implemented.

Example:

Finding

→ Excessive privileged access

Action

→ Remove unnecessary privileges

Verification

→ Review updated access list

Closure

→ Evidence retained


Startup Example

Consider a SaaS startup with 30 employees.

The CTO manages the technology environment.

The company decides to perform an annual independent information security review.

Instead of asking the CTO to review his own security program, the startup engages an independent security professional.

The reviewer examines:

  • ISMS scope
  • Risk register
  • Access controls
  • Supplier security
  • Incident management
  • Backup
  • Vulnerability management
  • Security monitoring
  • Business continuity
  • Previous findings

The reviewer identifies:

  1. Two former contractors still listed in an access register.
  2. One critical supplier assessment is overdue.
  3. Backup restoration testing has not been performed as planned.
  4. One security procedure is outdated.

The startup assigns:

  • Owners
  • Priorities
  • Due dates

and tracks remediation to closure.

Review Flow

Plan

↓

Independent Reviewer

↓

Collect Evidence

↓

Evaluate Controls

↓

Identify Findings

↓

Report Management

↓

Corrective Actions

↓

Follow-Up

This provides management with an independent view of the ISMS.


Startup-Focused Quick Summary

A startup does not necessarily need a large internal audit department.

A practical model is:

1. Define

What should be independently reviewed?

2. Select

Choose a suitably qualified and sufficiently independent reviewer.

3. Review

Evaluate policies, processes, controls and evidence.

4. Report

Document findings and improvement opportunities.

5. Remediate

Assign owners and deadlines.

6. Verify

Confirm that important issues have been addressed.

Simple Model

Plan → Independently Review → Report → Correct → Verify


Example Independent Review Plan

Review AreaScopeEvidence
ISMS GovernancePolicies, roles, objectivesISMS documents
Risk ManagementRisk assessment and treatmentRisk register
Access ManagementUser and privileged accessAccess reviews
Incident ManagementIncident processIncident records
Supplier SecurityCritical suppliersSupplier assessments
Business ContinuityICT continuityDR/BCP evidence
Vulnerability ManagementVulnerability identification and remediationScan reports
BackupBackup and restorationRestore test
ComplianceKey obligationsCompliance register
Corrective ActionsPrevious findingsAction tracker

Example Independent Review Report Structure

A practical report may contain:

1. Executive Summary

High-level results for management.

2. Review Objective

Why the review was performed.

3. Scope

Systems, departments, locations and controls covered.

4. Criteria

Policies, ISO 27001 requirements, contractual requirements or other criteria used.

5. Methodology

  • Interviews
  • Document review
  • Evidence sampling
  • Technical validation
  • Observation

6. Findings

Detailed observations and weaknesses.

7. Risk/Impact

Potential consequences associated with findings.

8. Recommendations

Suggested improvements.

9. Management Response

Management’s planned actions.

10. Corrective Action Plan

Owners and due dates.

11. Follow-Up

Verification of completed actions.


Audit Evidence for A.5.35

An auditor may request:

Governance

  • Independent Review Policy/Procedure
  • Annual review plan
  • Review schedule

Reviewer

  • Reviewer qualifications
  • Reviewer independence/conflict assessment
  • External engagement agreement where applicable

Review

  • Review plan
  • Review checklist
  • Interview records
  • Evidence sampling
  • Review working papers

Results

  • Independent review report
  • Findings
  • Recommendations
  • Management response

Corrective Actions

  • Corrective action tracker
  • Assigned owners
  • Due dates
  • Closure evidence
  • Follow-up review

A.5.35 Audit Checklist

Audit QuestionEvidence
Is independent information security review planned?Review schedule
Is the review performed at defined intervals?Previous reports
Are significant changes considered as review triggers?Review records
Is the reviewer sufficiently independent?Independence assessment
Does the reviewer have appropriate competence?Qualifications/experience
Is the review scope defined?Review plan
Are objective criteria established?Review criteria
Is evidence collected?Working papers
Are findings documented?Review report
Are findings communicated to management?Management report
Are corrective actions assigned?Action tracker
Are due dates established?Action tracker
Are significant findings followed up?Closure evidence
Are recurring findings identified?Trend/review records

Common Mistakes

1. Reviewing Your Own Work

The person responsible for operating a control should not automatically be considered sufficiently independent to provide an independent assessment of that same control.


2. Treating an Internal Audit as a Paper Exercise

An independent review should examine evidence rather than simply confirming that documents exist.


3. Checking Only Policies

A policy may say:

“Access reviews are performed quarterly.”

The reviewer should verify whether the reviews actually happened.


4. No Defined Review Frequency

An organization should establish an appropriate planned interval rather than performing reviews only when an external auditor asks for them.


5. No Review After Significant Changes

Major changes can introduce new risks.

Examples:

  • Cloud migration
  • Acquisition
  • New product
  • New country
  • Major customer
  • Significant security incident

6. Findings Without Owners

A finding without an owner is unlikely to be resolved effectively.


7. No Follow-Up

Closing the review report does not necessarily mean that the security weakness has been corrected.


8. Confusing Independent Review With Penetration Testing

A penetration test can provide valuable technical assurance, but it does not necessarily constitute an independent review of the organization’s overall information security management arrangements.


Practical Startup Implementation Model

A startup can implement A.5.35 with a lightweight annual process.

Step 1 – Define Scope

Identify what should be independently reviewed.

Step 2 – Identify Reviewer

Select an appropriately qualified and sufficiently independent person or organization.

Step 3 – Plan

Define objectives, criteria, evidence and schedule.

Step 4 – Review

Evaluate controls and supporting evidence.

Step 5 – Report

Document findings and recommendations.

Step 6 – Correct

Assign owners and deadlines.

Step 7 – Verify

Confirm that significant findings have been addressed.

Simple Model

Scope → Select → Plan → Review → Report → Correct → Verify


Policy vs. Process vs. Evidence

TypeExample
PolicyInformation Security Review Policy
ProcessIndependent Security Review Procedure
ProcessInternal Audit Procedure
DocumentAnnual Security Review Plan
DocumentIndependent Review Checklist
DocumentReview Report
EvidenceReviewer qualification
EvidenceIndependence assessment
EvidenceReview working papers
EvidenceFindings register
EvidenceCorrective action tracker
EvidenceFollow-up verification

Remember

Policy = What the organization requires

Process = How independent reviews are performed

Report = What the reviewer found

Evidence = Proof that the review happened and findings were addressed


Relationship With Other ISO 27001 Controls

A.5.35 connects with several other controls.

ControlRelationship
A.5.1 Policies for Information SecurityIndependent review can evaluate whether security policies remain appropriate
A.5.31 Legal/Regulatory/Contractual RequirementsReviews can assess how applicable obligations are addressed
A.5.34 Privacy and Protection of PIIReviews may examine privacy-related security controls
A.5.36 Compliance with Policies, Rules and StandardsA.5.36 focuses on checking compliance with established requirements
A.5.37 Documented Operating ProceduresReviews can assess whether procedures are current and followed
A.8.8 Management of Technical VulnerabilitiesTechnical security controls may be included in the review
A.8.15 LoggingReviewers may examine logging and audit evidence
A.8.16 Monitoring ActivitiesReview can assess security monitoring effectiveness
A.8.32 Change ManagementReview may assess whether changes are appropriately controlled

A.5.35 vs. A.5.36

These controls are related but should not be treated as identical.

ControlMain Question
A.5.35 Independent Review“Has information security been independently reviewed?”
A.5.36 Compliance with Policies, Rules and Standards“Are people and systems complying with the organization’s established security requirements?”

Example

A.5.35

An independent reviewer examines the organization’s access-control program.

A.5.36

The organization checks whether employees and administrators are actually following its access-control policies and procedures.

Both can provide assurance, but they address different objectives.


Useful Documents for A.5.35

  • Independent Information Security Review Procedure – [Insert Draft Document Link]
  • Annual Security Review Plan – [Insert Draft Document Link]
  • Independent Reviewer Assessment Checklist – [Insert Draft Document Link]
  • Information Security Review Checklist – [Insert Draft Document Link]
  • Independent Review Report Template – [Insert Draft Document Link]
  • Security Findings Register – [Insert Draft Document Link]
  • Corrective Action Tracker – [Insert Draft Document Link]
  • Independent Review Follow-Up Checklist – [Insert Draft Document Link]

Questions an Auditor May Ask

Independence

  • Who performed your last independent information security review?
  • Why was that person considered independent?
  • Was the reviewer responsible for operating the controls being reviewed?

Scope

  • What areas were reviewed?
  • How was the scope determined?
  • What criteria were used?

Evidence

  • What evidence did the reviewer examine?
  • Can you show me the review report?
  • Were technical controls included?

Findings

  • What findings were identified?
  • Which findings were considered significant?
  • Who was assigned to address them?

Follow-Up

  • Have the findings been remediated?
  • Can you show evidence of closure?
  • Were any findings repeated from previous reviews?

Startup-Focused Final Takeaway

ISO 27001 Annex A 5.35 is about creating independent assurance around information security.

The goal is not simply to produce another audit report.

The real objective is to identify weaknesses that the organization’s normal operating teams may not see.

For a startup, the process can remain simple:

Plan the review

↓

Use a suitably independent and competent reviewer

↓

Examine actual evidence

↓

Identify weaknesses

↓

Report to management

↓

Assign corrective actions

↓

Verify important issues are resolved

The practical auditor question is:

“Who independently reviews your information security arrangements, how do you ensure that reviewer is sufficiently independent, what did the review identify, and what did you do about the findings?”

That is the practical objective of ISO 27001 Annex A 5.35 – Independent Review of Information Security.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *