A.8.34
    Technological Controls

    Protection of information systems during audit testing

    Audit tests and other assurance activities involving assessment of operational systems should be planned and agreed between the tester and appropriate management.

    Purpose

    To minimize disruption to business processes from audit activities.

    Implementation Guidance

    Plan audit activities to minimize impact

    Obtain management approval before testing

    Use read-only access where possible

    Monitor audit activities for unintended effects

    Document all audit testing activities

    Note: ISMS Directory lists external audit firms for independent testing

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.34 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.34 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.34 Protection of information systems during audit testing. Built for compliance professionals.

    Try ISMS Copilot free