Protection of Information Systems During Audit Testing - ISO 27001 Annex A Control

ISO 27001 Annex A 8.34

Audit testing should reveal weaknesses - not introduce new ones.

ISO 27001 Annex A 8.34 - Protection of Information Systems During Audit Testing

Audit and assurance testing - internal audit, external audit, penetration testing, technical assessments - operates on live systems. The testing itself can have operational impact: scans can disrupt services, audit access can affect performance, examination of sensitive data brings additional people into contact with it. The control asks for these activities to be planned and agreed so that the testing achieves its purpose without creating new risks.

Practical agreement covers scope (what systems and data are in scope), timing (when the testing happens, around production schedules), access (what credentials and tools the tester uses, how access is granted and revoked), and handling of findings (how vulnerabilities are reported, who has visibility, how remediation is tracked). The arrangements should be in place before testing starts.

Confidentiality matters because testers often see sensitive information and security weaknesses that should not be widely known. Contractual arrangements with external testers, internal handling of audit reports, and clear rules on what testers can retain after the engagement all support this. The principle is that the assurance activity adds to security rather than creating its own exposure.

From the auditor's side, the agreement matters because it sets expectations on both sides. Where the scope is clearly defined and the access arrangements are in place, the audit work proceeds efficiently. Where these are negotiated piece by piece during the engagement, the audit takes longer and tends to surface less. Pre-engagement planning is in everyone's interest.

Practical Compliance Guidance

Audit testing arrangements are described in the IMS1 manual at section 8.5 alongside the Information Security Policy. Audit plans and engagement records provide the operational evidence.

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit covering manual, policies, procedures, registers and audit checklists.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The auditor or assessor and appropriate management - typically including the system owner, the information security function, and where third-party testers are involved, the contracting authority. The agreement should be recorded in writing before testing starts.
As confidential information. The audit report typically has restricted distribution while findings are open. Once remediated, findings may move to a wider audience but the original report retains its confidentiality classification. Long-term storage should follow the retention rules for audit records.
Penetration testing has additional considerations - rules of engagement that define what is and is not in scope, communication channels during testing, and arrangements for stopping the test if it causes operational impact. The arrangements should be agreed in writing and the contract should support them.

Further Resources

payment logos