A5.35 Independent review of information security
3 min read
An independent review of information security ensures that an organization’s security policies, controls, and procedures are effective, compliant, and aligned with best practices. These reviews help identify gaps, weaknesses, and potential risks that might be overlooked in day-to-day operations.
An independent review can be conducted by:
- Internal auditors (separate from the security team).
- External auditors or consultants (ISO 27001 Lead Auditors, cybersecurity experts).
- Regulatory bodies for compliance with ISO 27001, NIST, GDPR, PCI DSS, SOC 2, etc.
Implementation Guide #
Step 1: Define the Scope and Objectives
- Identify which security policies, controls, and processes will be reviewed.
- Align the review with ISO 27001 requirements and business goals.
- Determine whether the review is internal or external.
Step 2: Select the Right Review Methodology
- Gap Analysis: Compare security policies against ISO 27001 Annex A controls.
- Risk Assessment: Identify potential security risks and their impact.
- Compliance Audit: Check adherence to regulations like GDPR, CCPA, or PCI DSS.
- Technical Security Assessment: Evaluate network, systems, and applications using tools like Nessus, OpenVAS, and Qualys.
Step 3: Conduct the Review
- Interview key stakeholders (CISO, IT security, compliance team).
- Assess security documentation (policies, risk assessments, incident logs).
- Review access control mechanisms, encryption methods, and security configurations.
- Perform penetration testing or vulnerability scans (if part of the review).
Step 4: Document Findings and Provide Recommendations
- Highlight non-compliance issues, security weaknesses, and improvement areas.
- Provide a risk-based action plan with priorities (high, medium, low).
- Recommend corrective actions such as policy updates, control enhancements, or training programs.
Step 5: Implement and Monitor Improvements
- Assign responsibilities for fixing identified issues.
- Set a timeline for implementing security improvements.
- Schedule follow-up reviews to ensure recommendations are applied.
Example Scenario #
Case: An independent review finds that an organization lacks multi-factor authentication (MFA) for privileged accounts.
Actions Taken:
- MFA implementation is mandated for all admin and critical accounts.
- Identity and access management (IAM) policies are updated.
- A follow-up audit is scheduled in six months to verify compliance.
Common Mistakes in Independent Reviews #
- Relying only on internal reviews – External assessments bring fresh perspectives.
- Skipping technical security checks – A review should include both documentation and system-level testing.
- Lack of follow-up – Findings should lead to actionable improvements.
- Ignoring regulatory requirements – Reviews should align with legal and industry standards.
Templates for Implementation #
- ISO 27001 Audit Checklist
- Information Security Review Report Template
- Risk Assessment and Mitigation Plan
How to Pass an Audit #
Key Documents to Prepare:
- Security policies and risk assessment reports.
- Logs of previous security incidents and corrective actions.
- Evidence of penetration testing, vulnerability scans, and security improvements.
What the Auditor Will Check:
- Is an independent security review conducted regularly?
- Are security controls aligned with ISO 27001 and industry best practices?
- Have previous security gaps been addressed and documented?
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.35 Independent Review of Information Security | Preventive, Detective, Compliance |
| Purpose | Ensure security effectiveness, compliance, and continuous improvement |
| Applicability | All organizations handling sensitive data |
| ISO 27001 Domains | Risk Management, Compliance, Audit, Continuous Improvement |
An independent security review is not just about compliance—it’s about ensuring real security improvements. Regular reviews help organizations stay ahead of emerging threats, regulatory changes, and security risks.
Action Step:
Schedule an independent security review at least annually and implement all recommended improvements before the next audit cycle.