Independent Review of Information Security - ISO 27001 Annex A Control
ISO 27001 Annex A 5.35
Independent review is what stops the management system drifting over time.
ISO 27001 Annex A 5.35 - Independent Review of Information Security
Independence is the key word. The review needs to come from someone who is not directly responsible for running the controls being reviewed. Without that independence, the review tends to confirm what is already believed rather than test it. The control accepts that independence can be relative - an internal auditor from another department, a peer review from a different team, or an external auditor each provide different levels.
The scope of the review is the management system as a whole - the policies, the controls, the implementation, the effectiveness. It is broader than a financial audit and broader than a single-control assessment. The reviewer needs to be able to look across the management system and form an overall view of whether it is meeting its objectives.
The output is a report with findings, recommendations and an overall view. The findings flow into the corrective action process. The recommendations get considered by management. The overall view feeds into the management review under Clause 9.3. This loop is part of how the management system stays current rather than drifting over time.
Internal audit is the most common way of meeting this control. It works as long as the auditor is genuinely independent of the area being audited and has the competence to spot what is missing. A polished internal audit report that finds nothing significant year after year is a worse outcome than one that surfaces real issues, because it suggests the audit is not testing hard enough.
Practical Compliance Guidance
Independent review is described in the IMS1 Manual in section 4 on management system documentation alongside the audit programme. The information security audit checklist provides the structured approach for the review.
| alphaZ document | How to use it |
|---|---|
| ISO 27001 Toolkit | The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists. |
| A-C Information Security Management System Audit Checklist | The audit checklist used to structure the review, covering the management system clauses and the Annex A controls. Use as the basis for internal or independent review. |
Note - all the above files can be downloaded with an alphaZ subscription.
