ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Annual Security Review Plan

Annual Security Review Plan

1. Purpose

The Annual Security Review Plan defines the organization’s planned information-security reviews for each year.

The plan provides a structured approach for reviewing:

  • Information-security controls
  • ISMS processes
  • Security risks
  • Cloud and infrastructure security
  • Access controls
  • Application security
  • Supplier security
  • Incident management
  • Business continuity
  • Privacy and information protection
  • Compliance obligations
  • Corrective actions
  • Security improvements

The objective is to ensure that security reviews are planned based on risk, business criticality, changes, incidents, and applicable requirements rather than being performed only before an external audit.

Core Principle

Plan → Prioritize → Review → Test → Identify Gaps → Remediate → Verify → Report → Improve


2. Scope

This plan applies to information-security reviews performed during the annual ISMS cycle.

The annual plan may cover:

  • ISMS governance
  • Information-security policies
  • Risk management
  • Statement of Applicability
  • Access control
  • Identity and MFA
  • Privileged access
  • Asset management
  • Information classification
  • Cloud security
  • Network security
  • Application security
  • Secure development
  • Vulnerability management
  • Logging and monitoring
  • Incident management
  • Backup and recovery
  • Business continuity
  • Supplier security
  • Physical security
  • Security awareness
  • Privacy
  • Legal and regulatory compliance
  • Customer security requirements
  • AI security
  • Corrective actions

The actual scope should be adjusted according to the organization’s risk profile.


3. Annual Security Review Objectives

The annual review program should determine whether:

☐ Security risks remain appropriately assessed
☐ Security controls remain relevant
☐ Controls are implemented as intended
☐ Controls operate effectively
☐ Access remains appropriate
☐ Security incidents are addressed
☐ Vulnerabilities are managed
☐ Suppliers remain appropriately assessed
☐ Business continuity arrangements remain effective
☐ Security requirements are being met
☐ Previous findings have been remediated
☐ Security improvements are being implemented


4. Annual Review Information

FieldDetails
Review Year
Plan ID
ISMS Scope
Security Owner
ISMS Manager
Plan Approval Date
Management Approver
Previous Plan
Overall Risk Level
Planned Review Period
Next Annual Review

5. Annual Review Strategy

The organization should determine the review strategy based on:

Risk

  • High-risk systems
  • Sensitive information
  • Privileged access
  • Critical business services
  • Significant supplier dependencies

Change

  • New technology
  • Cloud migration
  • New applications
  • Organizational changes
  • New customers
  • New regulatory requirements

Security Events

  • Security incidents
  • Data breaches
  • Major vulnerabilities
  • Repeated control failures
  • Significant outages

Business Requirements

  • Customer requirements
  • Contractual commitments
  • Certification requirements
  • Regulatory obligations
  • Business continuity requirements

6. Annual Security Review Calendar

A sample annual schedule:

MonthPlanned ReviewPrimary FocusOwnerStatus
JanuaryAnnual Security PlanningRisks, previous findings, objectivesSecurity
FebruaryAccess Control ReviewIAM, MFA, privileged accessIT/Security
MarchCloud Security ReviewAWS configuration, logging, network, IAMCloud/Security
AprilApplication Security ReviewSDLC, vulnerabilities, testingEngineering/Security
MaySupplier Security ReviewCritical suppliers and third partiesSecurity/Procurement
JuneIncident Management ReviewIncidents, response, lessons learnedSecurity
JulyBusiness Continuity ReviewBCP, DR, backup, recoveryIT/BCP
AugustInformation Protection ReviewClassification, access, transfer, retentionSecurity
SeptemberVulnerability & Configuration ReviewVulnerability and secure configurationSecurity/IT
OctoberCompliance & Contract ReviewLegal, regulatory, customer requirementsCompliance/Legal
NovemberIndependent Security ReviewIndependent assessment of selected controlsIndependent Reviewer
DecemberAnnual Security SummaryFindings, risk, improvements, next planManagement/Security

This is an example schedule. The organization should adjust timing according to its risks and business cycle.


7. Annual Review Register

Maintain a central register of planned reviews.

Review IDReview AreaRiskPlanned DateActual DateReviewerStatusFindings

Suggested statuses:

  • Planned
  • Scheduled
  • In Progress
  • Evidence Collection
  • Findings Issued
  • Remediation
  • Follow-Up
  • Completed
  • Deferred
  • Cancelled

8. Security Review Categories

8.1 Governance Review

Review:

☐ Information-security policy
☐ Security roles
☐ Security responsibilities
☐ ISMS objectives
☐ Management oversight
☐ Risk management
☐ Security metrics
☐ Security improvement activities


8.2 Risk Management Review

Review:

☐ Risk register
☐ Risk assessment methodology
☐ New risks
☐ Changed risks
☐ Risk treatment
☐ Residual risk
☐ Risk acceptance
☐ Risk owners
☐ Treatment deadlines

Key Question

Have changes in the business, technology, suppliers, threats, and information created new or changed security risks?


9. Access Control Review

Review:

☐ User accounts
☐ MFA
☐ SSO
☐ Privileged accounts
☐ Administrative access
☐ Contractor access
☐ Supplier access
☐ Temporary access
☐ Former employee accounts
☐ Role changes
☐ Access reviews
☐ Access exceptions

Evidence

  • User access report
  • Privileged access report
  • MFA configuration
  • Access approvals
  • Access review records
  • Offboarding evidence

10. Cloud Security Review

For AWS or other cloud environments:

☐ Cloud accounts
☐ IAM
☐ MFA
☐ Privileged access
☐ Security groups
☐ Network configuration
☐ Public exposure
☐ Encryption
☐ KMS/key management
☐ CloudTrail
☐ Security monitoring
☐ Backup
☐ Vulnerability management
☐ Configuration management
☐ Secrets management

Key Question

Is the production cloud environment still securely configured and appropriately monitored?


11. Application Security Review

Review:

☐ Secure development process
☐ Code review
☐ Branch protection
☐ CI/CD security
☐ Dependency management
☐ Open-source components
☐ Vulnerability scanning
☐ SAST/DAST where appropriate
☐ Penetration testing
☐ Security defect management
☐ Production deployment controls
☐ Secrets in repositories


12. Vulnerability Management Review

Review:

☐ Vulnerability scanning
☐ Vulnerability identification
☐ Risk classification
☐ Remediation SLAs
☐ Critical vulnerabilities
☐ Aging vulnerabilities
☐ Exceptions
☐ Retesting
☐ Patch management
☐ Dependency vulnerabilities

Metrics

MetricResult
Critical vulnerabilities
High vulnerabilities
Average remediation time
Overdue vulnerabilities
Exceptions
Retested vulnerabilities

13. Security Logging and Monitoring Review

Review:

☐ Authentication logging
☐ Privileged activity
☐ Cloud activity
☐ Security alerts
☐ Application logs
☐ Network logs
☐ Monitoring coverage
☐ Alert escalation
☐ Log protection
☐ Log retention
☐ Time synchronization

Key Question

Would the organization have sufficient visibility to detect and investigate a significant security event?


14. Incident Management Review

Review:

☐ Incident register
☐ Incident reporting
☐ Severity classification
☐ Escalation
☐ Response procedures
☐ Evidence preservation
☐ Investigation
☐ Communication
☐ Root cause analysis
☐ Corrective actions
☐ Lessons learned
☐ Incident trends

Annual Incident Summary

Incident TypeNumberHighest SeverityOpen Actions

15. Backup and Recovery Review

Review:

☐ Backup coverage
☐ Backup frequency
☐ Backup protection
☐ Encryption
☐ Access control
☐ Backup monitoring
☐ Restore testing
☐ Recovery evidence
☐ RTO
☐ RPO
☐ Backup exceptions

Key Question

Can critical information and systems actually be recovered within the organization’s required recovery objectives?


16. Business Continuity Review

Review:

☐ Critical services
☐ Business Impact Analysis
☐ MTPD
☐ RTO
☐ RPO
☐ Recovery priorities
☐ Dependencies
☐ Alternate arrangements
☐ Crisis management
☐ Communication
☐ Continuity testing


17. Supplier Security Review

Review critical suppliers and relevant third parties.

☐ Supplier risk
☐ Security questionnaire
☐ Security assurance
☐ Contractual security requirements
☐ Access
☐ Information shared
☐ Subprocessors
☐ Data location
☐ Incidents
☐ Vulnerabilities
☐ Business continuity
☐ Open findings
☐ Exit arrangements

Prioritize suppliers based on risk rather than reviewing every supplier with identical depth.


18. Information Protection Review

Review:

☐ Information classification
☐ Information ownership
☐ Access restrictions
☐ Information transfer
☐ Encryption
☐ Data retention
☐ Data disposal
☐ Customer information
☐ Confidential information
☐ Restricted information
☐ Third-party information


19. Privacy and Personal Data Review

Where applicable:

☐ Personal data inventory
☐ Processing activities
☐ Data processors
☐ Subprocessors
☐ Data retention
☐ Data deletion
☐ Data subject requirements
☐ Data transfers
☐ Privacy notices
☐ Data-processing agreements
☐ Privacy incidents
☐ Customer requirements


20. Security Awareness Review

Review:

☐ Employee security training
☐ New-joiner training
☐ Annual training
☐ Phishing awareness
☐ Incident reporting awareness
☐ Password/MFA awareness
☐ Remote-working security
☐ Data protection awareness
☐ Role-specific training

Training Metrics

MetricResult
Employees requiring training
Completed
Completion percentage
Overdue
Phishing exercise result

21. Physical Security Review

Where applicable:

☐ Office access
☐ Visitor management
☐ Physical access records
☐ Secure areas
☐ Equipment protection
☐ Environmental controls
☐ Media protection
☐ Secure disposal
☐ Remote-working arrangements


22. Legal, Regulatory and Contractual Review

Review:

☐ Legal requirements
☐ Regulatory requirements
☐ Customer contracts
☐ Supplier contracts
☐ Security commitments
☐ Data-protection obligations
☐ Incident notification requirements
☐ Retention requirements
☐ Security assurance commitments
☐ Audit rights

Key Question

Has the organization made any security commitment that is not currently supported by its controls or operational capability?


23. AI Security Review

Where AI systems or AI-enabled services are used:

☐ AI inventory
☐ Approved AI tools
☐ Information shared with AI systems
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ AI supplier assessment
☐ Model/provider risk
☐ Security controls
☐ Human oversight
☐ AI output risks
☐ AI-related incidents
☐ AI contractual requirements


24. Previous Findings Review

Review all significant findings from:

  • Internal audits
  • Independent reviews
  • Customer audits
  • Security assessments
  • Penetration tests
  • Supplier assessments
  • Incident investigations
  • Compliance assessments
FindingSourceRiskActionDue DateStatusVerified

Repeated or overdue findings should receive additional management attention.


25. Control Effectiveness Review

For selected controls, assess:

ControlRequirementEvidenceResultRiskAction

Possible results:

☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Implemented
☐ Not Applicable
☐ Unable to Verify


26. Security Metrics

The annual review should use meaningful security metrics where available.

Examples:

Access

  • Privileged accounts
  • Overdue access reviews
  • Former-user accounts
  • MFA coverage

Vulnerability

  • Critical vulnerabilities
  • High vulnerabilities
  • Average remediation time
  • Overdue vulnerabilities

Incidents

  • Number of incidents
  • Severity
  • Mean time to detect
  • Mean time to respond
  • Recurring incidents

Resilience

  • Backup success rate
  • Restore-test success
  • RTO/RPO results

Supplier

  • Critical suppliers reviewed
  • Overdue assessments
  • Open supplier findings

Metrics should support decisions rather than become reporting for its own sake.


27. Risk-Based Review Prioritization

Use the organization’s risk methodology to prioritize reviews.

Example:

Risk LevelReview Approach
LowPeriodic/basic review
MediumScheduled control review
HighDetailed review and evidence testing
CriticalEnhanced review, independent assurance, and management oversight

The organization should align these categories with its approved risk methodology.


28. Review Planning Criteria

When selecting areas for review, consider:

  • Information sensitivity
  • System criticality
  • Customer impact
  • Regulatory requirements
  • Recent changes
  • Previous findings
  • Security incidents
  • Vulnerabilities
  • Supplier dependency
  • Privileged access
  • Business continuity dependency
  • Technology complexity

29. Independent Review

At least one independent security review may be scheduled where appropriate.

The review may cover:

  • ISMS governance
  • Risk management
  • Selected Annex A controls
  • Cloud security
  • Access control
  • Incident management
  • Supplier security
  • Business continuity

The reviewer should have sufficient independence and competence for the review.

See:

Independent Information Security Review Procedure


30. Review Evidence

For each review, retain appropriate evidence.

Examples:

☐ Review plan
☐ Scope
☐ Review criteria
☐ Evidence request
☐ Evidence reviewed
☐ Test results
☐ Sampling records
☐ Screenshots where appropriate
☐ System reports
☐ Interviews
☐ Findings
☐ Management response
☐ Corrective actions
☐ Follow-up evidence
☐ Closure approval

Evidence should be proportionate to the risk and should not contain unnecessary credentials or secrets.


31. Findings and Corrective Actions

All significant findings should be recorded.

Finding IDReviewFindingRiskOwnerDue DateStatus

Corrective actions should address:

  • Immediate risk
  • Root cause
  • Required control improvement
  • Responsible owner
  • Target date
  • Verification method

32. Deferred Reviews

If a planned review cannot be completed:

☐ Reason documented
☐ Risk assessed
☐ Management notified
☐ Alternative review considered
☐ New date established
☐ Exception approved where required
☐ Register updated

A deferred review should not simply disappear from the annual plan.


33. Annual Security Review Summary

At the end of the year, summarize:

AreaReviews PlannedCompletedFindingsOpen Actions
Governance
Risk
Access
Cloud
Application
Vulnerability
Incident
BCP/DR
Suppliers
Privacy
Compliance
Independent Review

34. Annual Security Risk Summary

At year-end, identify:

New Risks

Risks Increased

Risks Reduced

Accepted Risks

Outstanding High/Critical Risks


35. Annual Security Improvement Plan

Use review results to define improvements for the next year.

ImprovementReasonRiskOwnerTarget DateStatus

Examples:

  • Improve privileged-access management
  • Implement stronger cloud monitoring
  • Improve vulnerability remediation
  • Automate access reviews
  • Improve backup testing
  • Strengthen supplier monitoring
  • Improve incident response
  • Implement security automation

36. Management Review

The annual security review results should be presented to appropriate management.

Management should consider:

  • Significant findings
  • Security risks
  • Incident trends
  • Vulnerability trends
  • Control effectiveness
  • Customer requirements
  • Regulatory changes
  • Supplier risks
  • Business continuity
  • Security objectives
  • Required resources
  • Improvement priorities

Management Review Record

Meeting Date: __________________

Participants: __________________

Key Findings: __________________

Key Decisions: __________________

Resources Approved: __________________

Risk Decisions: __________________

Improvement Priorities: __________________


37. Annual Plan Approval

Prepared By

Name: __________________

Role: __________________

Date: __________________

Reviewed By

Name: __________________

Role: __________________

Date: __________________

Approved By

Name: __________________

Role: __________________

Date: __________________


38. Next-Year Planning

The next annual security review plan should consider:

☐ Previous findings
☐ Open corrective actions
☐ New risks
☐ Security incidents
☐ Major technology changes
☐ New suppliers
☐ New customers
☐ Regulatory changes
☐ Contractual changes
☐ Audit results
☐ Business strategy
☐ Security objectives
☐ Changes to ISMS scope

Next-Year Priorities


39. AWS SaaS Startup Example

A SaaS startup operates its production environment primarily on AWS.

Its annual security review plan includes:

Q1

Access & Identity

  • AWS IAM
  • SSO
  • MFA
  • Privileged access
  • Employee access
  • GitHub access

Q2

Cloud & Application Security

  • AWS configuration
  • Security groups
  • CloudTrail
  • Logging
  • Monitoring
  • Vulnerability management
  • CI/CD

Q3

Resilience & Suppliers

  • Backup
  • Restore testing
  • Disaster recovery
  • Business continuity
  • Critical suppliers
  • Subprocessors

Q4

ISMS & Independent Assurance

  • Risk assessment
  • SoA review
  • Security policies
  • Incident management
  • Customer requirements
  • Independent security review
  • Annual management review

Annual Audit Trail

Annual Plan → Risk Prioritization → Review Schedule → Evidence Collection → Control Testing → Findings → Corrective Actions → Follow-Up → Management Review → Improvement Plan → Next Annual Plan


40. Startup-Friendly Annual Security Model

A small startup can begin with a focused annual cycle.

Monthly

Review critical operational indicators:

  • Critical vulnerabilities
  • Security incidents
  • Privileged access changes
  • Backup failures
  • Major security alerts

Quarterly

Review selected high-risk controls:

  • Access
  • Cloud security
  • Vulnerability management
  • Suppliers
  • Backup

Semi-Annual

Perform deeper reviews of:

  • Incident management
  • Business continuity
  • Application security
  • Information protection

Annual

Perform:

  • Risk review
  • ISMS review
  • Independent security review
  • Security objectives review
  • Management review
  • Improvement planning

The exact schedule should be adapted to the organization’s size, risks, and obligations.


41. Common Mistakes

Avoid:

  • Creating an annual plan but not executing it.
  • Reviewing every control with identical frequency.
  • Focusing only on documentation.
  • Ignoring operational evidence.
  • Ignoring previous findings.
  • Deferring high-risk reviews without risk assessment.
  • Performing reviews only immediately before certification.
  • Failing to review new technology.
  • Ignoring cloud configuration changes.
  • Ignoring supplier changes.
  • Ignoring customer security commitments.
  • Treating security metrics as the objective rather than a decision-support tool.
  • Closing findings without verification.
  • Failing to convert review results into improvement actions.

42. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyDefines overall security direction
Information Security Risk AssessmentIdentifies and evaluates risks
Risk Treatment PlanTracks risk treatment
Statement of ApplicabilityDefines applicable controls
Internal Audit ProcedureDefines formal internal audit
Independent Information Security Review ProcedureDefines independent reviews
Security Control Testing ProcedureDefines control testing
Access Review ChecklistSupports access reviews
Cloud Security ReviewSupports cloud reviews
Supplier Security ReviewSupports supplier reviews
Incident ManagementProvides incident review evidence
BCP/DR PlanSupports resilience reviews
Corrective Action TrackerTracks remediation
Management ReviewReviews ISMS performance
ISMS Improvement LogTracks improvement

43. ISO/IEC 27001 Connection

An annual security review plan supports the organization’s risk-based ISMS by providing a structured mechanism for reviewing security controls, risks, processes, performance, and improvements.

The plan can support activities related to:

  • Risk management
  • Control monitoring
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement
  • Security performance evaluation

The annual schedule itself is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate review frequency and scope based on its:

  • Information-security risks
  • ISMS scope
  • Business requirements
  • Control environment
  • Legal/regulatory obligations
  • Customer requirements
  • Significant changes
  • Previous review results

44. Final Annual Security Review Audit Trail

For each annual cycle, the organization should be able to demonstrate:

What security areas were planned for review?
Why were those areas selected?
What risks were considered?
Which reviews were completed?
What evidence was examined?
Which controls were tested?
What findings were identified?
Which risks remain open?
What corrective actions were assigned?
Were corrective actions verified?
What did management review?
What improvements were approved?
How were the results used to create the next year’s plan?

Final Principle

Risk → Prioritize → Plan → Review → Test → Evidence → Findings → Remediate → Verify → Management Review → Improve → Repeat