How to Audit ISO 27001 Annex A 8.34

The ultimate audit guide to ISO 27001 Annex A 8.34 Protection of information systems during audit testing

1. Provision Formal Rules of Engagement (ROE) Documents

Verify that every audit or technical test is governed by a signed Rules of Engagement document. This ensures that the scope, methodology, and constraints are legally and operationally defined before any testing begins.

  • Inspect ROE documents for specific exclusions of sensitive technical assets.
  • Confirm that both the auditor and the asset owner have signed the agreement.
  • Verify that the ROE includes emergency contact details for immediate session termination.

2. Formalise Scheduling and Operational Time Windows

Audit the scheduling process to ensure that tests are conducted during periods of low business impact. This prevents technical scans or manual testing from degrading service performance during peak hours.

  • Cross-reference audit logs with the organisational change calendar.
  • Confirm that high-traffic or critical processing windows are explicitly excluded from testing.
  • Check for evidence of coordination between the audit team and the Network Operations Centre (NOC).

3. Audit Restricted Access Levels for Testers

Examine the Identity and Access Management (IAM) roles provisioned for auditors. Testers should only possess the minimum level of access required to satisfy the audit objective, following the principle of least privilege.

  • Verify that auditors are not granted “Global Admin” or “Superuser” status by default.
  • Confirm that MFA is enforced for all temporary auditor accounts.
  • Check the Asset Register to ensure auditor access is limited to the defined scope.

4. Verify Read-Only Permissions for Production Datasets

Assess the technical controls used to protect data integrity during testing. Auditors should typically be restricted to read-only access to prevent accidental modification or deletion of live data.

  • Inspect database permissions for auditor service accounts.
  • Confirm that “Write” or “Delete” permissions are only granted under exceptional, monitored circumstances.
  • Review the use of data masking or anonymisation where live data must be sighted.

5. Monitor System Performance During Active Testing

Evaluate the monitoring tools used to track system health during an audit. Real-time observation ensures that any performance degradation caused by testing is identified and mitigated instantly.

  • Inspect dashboard logs for CPU and memory usage during known testing windows.
  • Verify that automated alerts are configured to trigger if testing activity exceeds performance thresholds.
  • Confirm that the technical team has the authority to suspend testing if stability is compromised.

6. Revoke Temporary Auditor Accounts Post-Testing

Audit the offboarding process for temporary testing credentials. Stale auditor accounts are a significant security risk if they are not decommissioned immediately after the engagement concludes.

  • Sample recent audit completion dates and compare them to account deactivation logs.
  • Verify that temporary VPN or SSH keys have been deleted or rotated.
  • Check the IAM system for any “Auditor” roles that remain active beyond their intended duration.

Annex A 8.34 Audit Execution Framework

Audit StepAudit Execution MethodCommon Examples of Evidence
1. Rules of EngagementReview signed agreements for recent penetration tests or internal audits.Signed ROE PDF, Scope Definition Document.
2. Testing SchedulesCompare audit dates against the corporate holiday and peak-transaction calendar.Outlook Calendar invites, Change Management Logs.
3. Privileged Access ReviewInspect auditor account settings in the IAM console during an active test.IAM Role screenshots, Active Directory group memberships.
4. Read-Only VerificationVerify database role configurations for auditor service accounts.SQL Role definition, “SELECT” only permission logs.
5. Performance MonitoringVerify that a system admin was monitoring the NOC during a vulnerability scan.CloudWatch logs, Datadog dashboards, NOC shift logs.
6. Credential DecommissioningPerform a spot check on accounts created for auditors who finished in the last 30 days.Deactivated account status in Okta/AD, Deleted SSH keys.
7. Data SanitisationInspect the data used in the “Staging” environment to ensure it is not live production data.Anonymisation scripts, Data Masking Policy.
8. Log IntegrityConfirm that auditors do not have “Delete” access to the logs tracking their actions.WORM storage settings, SIEM log integrity reports.
9. Management Sign-offReview board or steering committee minutes where audit plans were approved.ISMS Committee Minutes, Signed Audit Charter.
10. Risk ExclusionConfirm that “Year-End” or “Black Friday” windows were blocked out in the audit tool.Blackout period configuration in Vulnerability Scanners.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top