ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Information Security Review Checklist

Information Security Review Checklist

1. Purpose

The Information Security Review Checklist provides a structured method for reviewing the organization’s information-security environment, controls, processes, technology, and supporting evidence.

The checklist helps determine whether information-security arrangements:

  • Remain appropriate for identified risks
  • Are implemented as intended
  • Are operating effectively
  • Protect organizational and customer information
  • Support business requirements
  • Address applicable security obligations
  • Continue to meet defined control requirements
  • Have appropriate evidence
  • Require corrective action or improvement

Core Principle

Define Scope → Understand Risk → Review Controls → Verify Evidence → Identify Gaps → Assess Risk → Correct → Verify → Improve


2. When to Use

Use this checklist for:

  • Periodic information-security reviews
  • Annual security reviews
  • Quarterly security reviews
  • Control reviews
  • ISMS readiness reviews
  • Pre-audit assessments
  • Post-incident reviews
  • Technology-change reviews
  • Customer security reviews
  • Supplier/security assurance reviews
  • Management-requested security reviews

The depth and frequency should be proportionate to risk.


3. Review Information

FieldDetails
Review ID
Review Title
Review Date
Review Period
Reviewer
Business Owner
Security Owner
ISMS Scope
Review Scope
Review Criteria
Risk Level
Previous Review
Review Status

4. Review Objective

Define what the review is intended to determine.

Examples:

  • Verify effectiveness of access controls.
  • Review AWS production security.
  • Assess information-security controls.
  • Review compliance with internal security requirements.
  • Verify remediation of previous findings.
  • Assess security following a major technology change.

Objective


5. Review Scope

Included

Excluded

Systems

Business Processes

Information

Locations

Time Period


6. Review Criteria

Identify the requirements against which the review will be performed.

☐ Information-security policies
☐ Security procedures
☐ Risk assessment
☐ Risk treatment plan
☐ Statement of Applicability
☐ Security standards
☐ Technical baselines
☐ Customer requirements
☐ Contractual requirements
☐ Legal requirements
☐ Regulatory requirements
☐ ISO/IEC 27001 requirements
☐ Other: __________________


7. Review Method

Select applicable methods:

☐ Document review
☐ Interviews
☐ Observation
☐ Sampling
☐ Configuration review
☐ Evidence testing
☐ Access review
☐ Technical testing
☐ Log review
☐ System-generated reports
☐ Previous finding verification


8. Information Security Governance

Review whether:

☐ Information-security policy is approved
☐ Policy remains current
☐ Security responsibilities are defined
☐ Security ownership is assigned
☐ Security objectives are defined
☐ Management oversight exists
☐ Security performance is monitored
☐ Security risks are reported
☐ Security decisions are documented
☐ Security exceptions are controlled

Evidence


9. ISMS Scope Review

Verify:

☐ ISMS scope is documented
☐ Scope remains accurate
☐ Business changes considered
☐ New systems considered
☐ New locations considered
☐ New suppliers considered
☐ New services considered
☐ Cloud environments considered
☐ Customer requirements considered
☐ Scope exclusions remain appropriate

Scope Changes


10. Information Security Risk Management

Review:

☐ Risk methodology
☐ Risk register
☐ New risks
☐ Changed risks
☐ Risk owners
☐ Risk treatment
☐ Risk acceptance
☐ Residual risk
☐ Treatment deadlines
☐ Risk monitoring

Key Question

Have business, technology, supplier, threat, or regulatory changes created new or changed information-security risks?


11. Statement of Applicability

Review:

☐ SoA is current
☐ Control applicability reviewed
☐ Control exclusions have rationale
☐ New risks considered
☐ New controls considered
☐ Custom controls considered where necessary
☐ Implementation status accurate
☐ Evidence available
☐ SoA reflects current ISMS scope


12. Asset Management

Review:

☐ Hardware inventory
☐ Software inventory
☐ Cloud resources
☐ Applications
☐ Databases
☐ Information assets
☐ Critical assets
☐ Asset owners
☐ Asset classification
☐ Asset lifecycle
☐ Unsupported assets
☐ Unauthorized assets

Evidence


13. Information Classification

Verify:

☐ Classification scheme exists
☐ Information owners identified
☐ Sensitive information identified
☐ Customer information classified
☐ Personal data identified
☐ Confidential information protected
☐ Restricted information protected
☐ Classification reflected in access controls
☐ Handling requirements defined


14. Access Control

Review:

☐ User accounts
☐ Access approvals
☐ Least privilege
☐ Role-based access
☐ MFA
☐ SSO
☐ Privileged access
☐ Temporary access
☐ Contractor access
☐ Supplier access
☐ Former employee access
☐ Role changes
☐ Periodic access reviews

Evidence


15. Privileged Access

Review:

☐ Administrative accounts identified
☐ Business justification exists
☐ Named accounts used
☐ MFA enabled
☐ Privileges minimized
☐ Privileged activity logged
☐ Privileged access monitored
☐ Periodic review performed
☐ Unused privileges removed
☐ Emergency access controlled


16. Authentication

Review:

☐ Password requirements
☐ MFA
☐ SSO
☐ Authentication controls
☐ Account lockout/rate limiting where appropriate
☐ Session management
☐ Service accounts
☐ API authentication
☐ Token management
☐ Credential rotation


17. Remote Access

Review:

☐ Remote access approved
☐ MFA enabled
☐ Secure connection
☐ VPN/approved remote-access mechanism
☐ Device security
☐ Access restrictions
☐ Logging
☐ Monitoring
☐ Temporary access controls


18. Cloud Security

For AWS or other cloud environments:

☐ Cloud accounts identified
☐ IAM reviewed
☐ MFA reviewed
☐ Privileged roles reviewed
☐ Security groups reviewed
☐ Network exposure reviewed
☐ Public resources reviewed
☐ Encryption reviewed
☐ KMS/key management reviewed
☐ Secrets management reviewed
☐ CloudTrail/logging reviewed
☐ Security monitoring reviewed
☐ Backup reviewed
☐ Vulnerability management reviewed
☐ Configuration management reviewed


19. Network Security

Review:

☐ Network architecture
☐ Segmentation
☐ Firewalls
☐ Security groups
☐ Secure remote access
☐ Internet exposure
☐ Administrative access
☐ Network monitoring
☐ Intrusion detection/prevention where appropriate
☐ Network changes
☐ Unauthorized connections


20. Endpoint Security

Review:

☐ Endpoint inventory
☐ Supported operating systems
☐ Security patching
☐ Malware protection
☐ Device encryption
☐ Device management
☐ Secure configuration
☐ Remote-wipe capability where appropriate
☐ Lost/stolen-device process
☐ BYOD controls where applicable


21. Application Security

Review:

☐ Secure development process
☐ Security requirements
☐ Code review
☐ Branch protection
☐ Dependency management
☐ SAST/DAST where appropriate
☐ Vulnerability management
☐ Penetration testing
☐ Security testing
☐ Secure deployment
☐ Production access
☐ Secrets management
☐ Application logging


22. Source Code Security

Review:

☐ Repository inventory
☐ Repository ownership
☐ Access review
☐ MFA
☐ Branch protection
☐ Pull-request review
☐ Administrative access
☐ Contractor access
☐ Supplier access
☐ CI/CD access
☐ Service accounts
☐ SSH keys
☐ Personal access tokens
☐ OAuth applications
☐ Secret scanning
☐ Repository visibility
☐ Forks and copies


23. Vulnerability Management

Review:

☐ Vulnerability scanning
☐ Vulnerability identification
☐ Risk classification
☐ Critical vulnerabilities
☐ High vulnerabilities
☐ Remediation deadlines
☐ Overdue vulnerabilities
☐ Exceptions
☐ Retesting
☐ Dependency vulnerabilities
☐ Infrastructure vulnerabilities
☐ Application vulnerabilities

Metrics

MetricResult
Critical vulnerabilities
High vulnerabilities
Overdue vulnerabilities
Average remediation time
Exceptions

24. Patch Management

Review:

☐ Patch process
☐ Critical patching
☐ Operating-system updates
☐ Application updates
☐ Cloud updates
☐ Emergency patching
☐ Patch testing
☐ Patch evidence
☐ Unsupported software
☐ Exceptions


25. Malware Protection

Where applicable:

☐ Endpoint protection
☐ Malware detection
☐ Malware alerts
☐ Quarantine
☐ Investigation
☐ Response procedure
☐ Protection coverage
☐ Signature/engine updates
☐ Monitoring


26. Logging and Monitoring

Review:

☐ Authentication logs
☐ Privileged activity
☐ Cloud activity
☐ Security events
☐ Application logs
☐ Network logs
☐ Database activity where appropriate
☐ CI/CD activity
☐ Security alerts
☐ Monitoring coverage
☐ Log protection
☐ Log retention
☐ Time synchronization

Key Question

Can the organization detect and investigate significant security events using available evidence?


27. Security Incident Management

Review:

☐ Incident policy
☐ Incident procedure
☐ Incident reporting
☐ Incident register
☐ Severity classification
☐ Escalation
☐ Investigation
☐ Evidence preservation
☐ Containment
☐ Eradication
☐ Recovery
☐ Communication
☐ Root cause analysis
☐ Corrective actions
☐ Lessons learned


28. Incident Trend Review

Review:

Incident TypeNumberHighest SeverityRecurring?Open Actions

Look for:

  • Recurring incidents
  • Increasing severity
  • Repeated root causes
  • Control failures
  • Delayed response
  • Unresolved corrective actions

29. Backup and Recovery

Review:

☐ Backup coverage
☐ Backup frequency
☐ Backup protection
☐ Encryption
☐ Backup access controls
☐ Backup monitoring
☐ Restore testing
☐ Recovery evidence
☐ RTO
☐ RPO
☐ Backup failures
☐ Backup exceptions


30. Business Continuity

Review:

☐ Critical services identified
☐ Business Impact Analysis
☐ MTPD
☐ RTO
☐ RPO
☐ Recovery priorities
☐ Dependencies
☐ Alternate arrangements
☐ Crisis communication
☐ Continuity testing
☐ Lessons learned


31. Disaster Recovery

Review:

☐ Disaster recovery plan
☐ Recovery environments
☐ Infrastructure recovery
☐ Data recovery
☐ Application recovery
☐ IAM recovery
☐ Network recovery
☐ Secrets recovery
☐ Monitoring recovery
☐ Recovery testing
☐ Actual RTO/RPO measured
☐ Recovery gaps tracked


32. Supplier and Third-Party Security

Review:

☐ Supplier register
☐ Critical supplier register
☐ Supplier risk assessment
☐ Due diligence
☐ Security questionnaire
☐ Security assurance
☐ Contractual requirements
☐ Supplier access
☐ Information shared
☐ Subprocessors
☐ Data location
☐ Supplier incidents
☐ Supplier vulnerabilities
☐ Business continuity
☐ Supplier exit arrangements


33. Information Transfer

Review:

☐ Approved transfer methods
☐ Encryption
☐ Secure file sharing
☐ API security
☐ Recipient verification
☐ Access restrictions
☐ Transfer logging where appropriate
☐ Data minimization
☐ Customer requirements
☐ Third-party transfer controls


34. Data Protection and Privacy

Where applicable:

☐ Personal data identified
☐ Processing purposes identified
☐ Data inventory
☐ Data retention
☐ Data deletion
☐ Data subject requirements
☐ Data processors
☐ Subprocessors
☐ Data locations
☐ International transfers
☐ Privacy incidents
☐ Data-processing agreements


35. Security Awareness

Review:

☐ Security awareness program
☐ New-joiner training
☐ Annual training
☐ Role-specific training
☐ Phishing awareness
☐ Incident reporting awareness
☐ Password/MFA awareness
☐ Remote-working security
☐ Data protection awareness

Training Metrics

MetricResult
Employees requiring training
Completed
Completion percentage
Overdue

36. Physical Security

Where applicable:

☐ Physical access controls
☐ Visitor management
☐ Secure areas
☐ CCTV/security monitoring
☐ Equipment protection
☐ Environmental protection
☐ Media protection
☐ Secure disposal
☐ Office security
☐ Remote-working arrangements


37. Security of Information During Change

Review whether security is considered when changes occur.

☐ Change management process
☐ Security impact assessment
☐ Risk assessment
☐ Approval
☐ Testing
☐ Rollback planning
☐ Emergency change process
☐ Post-change validation
☐ Documentation
☐ Security monitoring


38. Configuration Management

Review:

☐ Approved baselines
☐ Secure configuration
☐ Configuration inventory
☐ Configuration changes
☐ Unauthorized changes
☐ Configuration monitoring
☐ Configuration drift
☐ Infrastructure as Code
☐ Exceptions
☐ Periodic review


39. Secrets and Credential Management

Review:

☐ Password management
☐ API keys
☐ Access tokens
☐ Cloud credentials
☐ SSH keys
☐ Certificates
☐ Encryption keys
☐ Secure secrets storage
☐ Rotation
☐ Revocation
☐ Secret scanning
☐ Compromise response


40. Cryptography and Encryption

Review:

☐ Encryption in transit
☐ Encryption at rest
☐ Key management
☐ Key access controls
☐ Key rotation
☐ Certificate management
☐ Secure cryptographic mechanisms
☐ Customer encryption requirements


41. Information Retention and Disposal

Review:

☐ Retention requirements
☐ Customer requirements
☐ Legal requirements
☐ Data retention periods
☐ Secure disposal
☐ Data deletion
☐ Media disposal
☐ Cloud data deletion
☐ Supplier data deletion
☐ Evidence of disposal where required


42. Intellectual Property Protection

Review:

☐ IP ownership
☐ Source-code protection
☐ Customer IP
☐ Third-party IP
☐ Open-source software
☐ Software licensing
☐ Copyrighted content
☐ Confidential business information
☐ Trade secrets
☐ IP access controls
☐ Employee/contractor IP obligations


43. Software License Compliance

Review:

☐ Software license register
☐ Commercial software
☐ SaaS subscriptions
☐ Open-source software
☐ License obligations
☐ License expiry
☐ Unsupported software
☐ Unauthorized software
☐ License conflicts
☐ Customer distribution requirements


44. AI Security

Where AI is used:

☐ AI inventory
☐ Approved AI services
☐ AI supplier assessment
☐ Data shared with AI
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ AI access controls
☐ Model/provider information
☐ Data retention
☐ Training/use of submitted data
☐ Human oversight
☐ AI-related incidents
☐ AI security risks


45. Security Requirements From Contracts

Review:

☐ Customer security commitments
☐ Supplier security commitments
☐ Security SLAs
☐ Incident notification requirements
☐ Data protection requirements
☐ Encryption requirements
☐ Availability requirements
☐ RTO/RPO commitments
☐ Audit rights
☐ Security testing requirements
☐ Vulnerability remediation requirements
☐ Data deletion requirements
☐ Subprocessor requirements

Key Question

Are contractual security commitments actually supported by implemented controls and operational capability?


46. Legal and Regulatory Compliance

Review:

☐ Legal requirements identified
☐ Regulatory requirements identified
☐ Applicability assessed
☐ Obligations register updated
☐ Requirement owners assigned
☐ Control mapping performed
☐ Evidence available
☐ Regulatory changes monitored
☐ Compliance gaps tracked


47. Security Testing

Review whether appropriate security testing has been performed.

☐ Vulnerability scanning
☐ Penetration testing
☐ Application testing
☐ Cloud security assessment
☐ Configuration assessment
☐ Security control testing
☐ Backup/restore testing
☐ Disaster recovery testing
☐ Phishing testing where appropriate

Review:

  • Scope
  • Date
  • Findings
  • Severity
  • Remediation
  • Retesting

48. Security Exceptions

Review:

☐ Exceptions documented
☐ Business justification
☐ Risk assessed
☐ Compensating controls
☐ Approval
☐ Expiry date
☐ Periodic review
☐ Closure

No significant security exception should remain open indefinitely without review.


49. Previous Findings

Review findings from:

☐ Internal audits
☐ Independent reviews
☐ Penetration tests
☐ Vulnerability assessments
☐ Customer assessments
☐ Supplier reviews
☐ Incidents
☐ Compliance assessments

FindingSourceRiskActionDue DateStatusVerified

50. Control Effectiveness Assessment

For each selected control:

ControlRequirementEvidenceResultRiskAction

Result

☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Implemented
☐ Not Applicable
☐ Unable to Verify


51. Evidence Quality

Assess whether evidence is:

☐ Relevant
☐ Current
☐ Complete
☐ Authentic
☐ Traceable
☐ Sufficient
☐ Consistent
☐ Representative

Evidence should demonstrate actual operation where the control requires ongoing operation.


52. Review Findings

Record identified gaps.

Finding IDAreaRequirementConditionEvidenceRiskSeverity

A finding should clearly distinguish the requirement from the observed condition.


53. Corrective Action

Action IDFindingRoot CauseActionOwnerDue DateStatus

Corrective action should address the underlying cause where appropriate.


54. Risk Treatment

For significant findings:

☐ Reduce
☐ Avoid
☐ Share/Transfer
☐ Accept

Treatment

Residual Risk

Risk acceptance should follow the organization’s approved risk-acceptance process.


55. Review Summary

AreaResultFindingRisk
Governance
Risk Management
Access Control
Cloud Security
Application Security
Vulnerability Management
Incident Management
BCP/DR
Supplier Security
Privacy
Compliance
Physical Security
Overall Security

56. Overall Review Result

☐ Controls operating effectively
☐ Controls generally effective with improvements required
☐ Material weaknesses identified
☐ Significant remediation required
☐ Further assessment required
☐ Unable to conclude due to insufficient evidence

Overall Conclusion

The conclusion should reflect only the defined scope and evidence reviewed.


57. Management Review

Management should review significant results.

Management Review Information

Date: __________________

Participants: __________________

Significant Findings: __________________

Risk Decisions: __________________

Resources Required: __________________

Improvement Decisions: __________________


58. Follow-Up Review

After corrective actions:

☐ Action completed
☐ Evidence received
☐ Control retested
☐ Risk reassessed
☐ Residual risk reviewed
☐ Finding closed
☐ Finding remains open

Follow-Up Result


59. Review Approval

Reviewer

Name: __________________

Role: __________________

Signature/Approval: __________________

Date: __________________

Control/Business Owner

Name: __________________

Role: __________________

Date: __________________

Security/ISMS Owner

Name: __________________

Role: __________________

Date: __________________


60. AWS SaaS Startup Example

A SaaS startup performs an annual information-security review covering its production AWS environment and supporting security processes.

Scope

  • AWS production
  • GitHub
  • IAM
  • Employee access
  • Application security
  • Logging
  • Vulnerability management
  • Backup
  • Incident management
  • Critical suppliers

Evidence Reviewed

  • IAM access report
  • MFA configuration
  • CloudTrail configuration
  • Security-group configuration
  • Vulnerability report
  • Backup evidence
  • Incident register
  • Access-review records
  • Security policies
  • Risk register

Example Finding

Area: Privileged Access

Requirement: Privileged access should be restricted to authorized personnel.

Condition: One inactive administrative permission remained assigned to a user who no longer required the privilege.

Risk: Unnecessary privileged access could increase the potential impact of account compromise.

Action: Remove the unnecessary privilege, review similar permissions, and update the periodic privileged-access review.

Audit Trail

Review Scope → Risk Assessment → Evidence Request → Evidence Review → Control Testing → Finding → Risk Assessment → Corrective Action → Retest → Closure


61. Startup-Friendly Review Model

A startup can simplify the review by prioritizing high-risk areas.

Monthly

Review:

  • Critical vulnerabilities
  • Security incidents
  • Privileged access changes
  • Backup failures
  • Major security alerts

Quarterly

Review:

  • Access control
  • Cloud security
  • Vulnerability management
  • Supplier security
  • Backup

Semi-Annual

Review:

  • Application security
  • Incident management
  • Business continuity
  • Information protection

Annual

Review:

  • ISMS
  • Risk assessment
  • SoA
  • Security policies
  • Legal/regulatory requirements
  • Customer security requirements
  • Independent security review
  • Management review

The frequency should be adjusted based on risk and business requirements.


62. Common Mistakes

Avoid:

  • Treating the checklist as a paperwork exercise.
  • Reviewing policies without testing implementation.
  • Checking only whether documents exist.
  • Ignoring operational evidence.
  • Reviewing every control with identical depth.
  • Failing to consider recent changes.
  • Ignoring previous findings.
  • Ignoring supplier dependencies.
  • Ignoring cloud configuration.
  • Ignoring privileged access.
  • Closing findings without retesting.
  • Accepting evidence that is outdated or incomplete.
  • Collecting unnecessary credentials as evidence.
  • Performing technical testing without authorization.

63. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyDefines overall security requirements
Information Security Risk AssessmentIdentifies security risks
Risk Treatment PlanTracks treatment
Statement of ApplicabilityDefines applicable controls
Annual Security Review PlanDefines planned review schedule
Independent Information Security Review ProcedureDefines independent reviews
Independent Reviewer Assessment ChecklistEvaluates reviewers
Internal Audit ProcedureDefines formal internal audit
Security Control Testing ProcedureDefines detailed control testing
Access Review ChecklistSupports access reviews
Cloud Security ReviewSupports cloud assessment
Supplier Security ReviewSupports supplier assessment
Incident ManagementProvides incident evidence
Corrective Action TrackerTracks remediation
Management ReviewProvides management oversight
ISMS Improvement LogTracks improvement

64. ISO/IEC 27001 Connection

The Information Security Review Checklist supports the organization’s risk-based ISMS assurance and improvement activities.

It can provide evidence relating to:

  • Risk management
  • Security-control implementation
  • Control effectiveness
  • Monitoring and measurement
  • Internal assurance
  • Corrective action
  • Management review
  • Continual improvement

The checklist itself is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate review scope, frequency, evidence, and methodology based on its:

  • ISMS scope
  • Information-security risks
  • Business requirements
  • Applicable controls
  • Legal/regulatory requirements
  • Customer requirements
  • Contractual commitments
  • Previous findings
  • Significant changes

65. Audit Evidence

Retain appropriate evidence such as:

☐ Completed review checklist
☐ Review scope
☐ Review criteria
☐ Evidence request
☐ Evidence reviewed
☐ Sampling records
☐ Test results
☐ Configuration evidence
☐ Findings
☐ Risk assessment
☐ Management response
☐ Corrective actions
☐ Follow-up evidence
☐ Closure approval

Evidence retention should follow the organization’s records-retention requirements.

Do not retain unnecessary passwords, API keys, private keys, tokens, or other authentication secrets.


66. Final Information Security Review Audit Trail

For each significant review, the organization should be able to demonstrate:

What was reviewed?
Why was it reviewed?
What risks were considered?
What requirements were used?
What evidence was examined?
Which controls were tested?
What findings were identified?
What risks resulted from those findings?
Who owns the corrective actions?
Were corrective actions completed?
Were controls retested?
What did management decide?
What improvements were made?

Final Principle

Define → Assess Risk → Review → Test → Evidence → Identify Gaps → Treat Risk → Correct → Retest → Approve → Improve