Independent Review of Information Security - ISO 27001 Annex A Control

ISO 27001 Annex A 5.35

Independent review is what stops the management system drifting over time.

ISO 27001 Annex A 5.35 - Independent Review of Information Security

Independence is the key word. The review needs to come from someone who is not directly responsible for running the controls being reviewed. Without that independence, the review tends to confirm what is already believed rather than test it. The control accepts that independence can be relative - an internal auditor from another department, a peer review from a different team, or an external auditor each provide different levels.

The scope of the review is the management system as a whole - the policies, the controls, the implementation, the effectiveness. It is broader than a financial audit and broader than a single-control assessment. The reviewer needs to be able to look across the management system and form an overall view of whether it is meeting its objectives.

The output is a report with findings, recommendations and an overall view. The findings flow into the corrective action process. The recommendations get considered by management. The overall view feeds into the management review under Clause 9.3. This loop is part of how the management system stays current rather than drifting over time.

Internal audit is the most common way of meeting this control. It works as long as the auditor is genuinely independent of the area being audited and has the competence to spot what is missing. A polished internal audit report that finds nothing significant year after year is a worse outcome than one that surfaces real issues, because it suggests the audit is not testing hard enough.

Practical Compliance Guidance

Independent review is described in the IMS1 Manual in section 4 on management system documentation alongside the audit programme. The information security audit checklist provides the structured approach for the review.

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists.
A-C Information Security Management System Audit Checklist The audit checklist used to structure the review, covering the management system clauses and the Annex A controls. Use as the basis for internal or independent review.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

No. The standard requires the review to be independent of those operating the controls, which can be achieved through internal audit, peer review or external audit. ISO 27001 certification involves external audit but that is for the certification rather than directly to satisfy A.5.35. Many organisations meet A.5.35 through their internal audit programme.
At planned intervals as set out in the audit programme, plus whenever significant changes occur to the management system or the organisation. Most organisations aim to cover the full scope at least once a year, broken down into shorter audits across the year focused on different parts.
Independence means the reviewer does not have day-to-day responsibility for what is being reviewed. An internal auditor from a different department auditing information security is independent for that purpose. The Information Security Lead auditing their own controls is not. Where independence is hard to achieve internally, peer review or external audit may be needed.

Further Resources

payment logos