1. Purpose
The Annual Security Review Plan defines the organization’s planned information-security reviews for each year.
The plan provides a structured approach for reviewing:
- Information-security controls
- ISMS processes
- Security risks
- Cloud and infrastructure security
- Access controls
- Application security
- Supplier security
- Incident management
- Business continuity
- Privacy and information protection
- Compliance obligations
- Corrective actions
- Security improvements
The objective is to ensure that security reviews are planned based on risk, business criticality, changes, incidents, and applicable requirements rather than being performed only before an external audit.
Core Principle
Plan → Prioritize → Review → Test → Identify Gaps → Remediate → Verify → Report → Improve
2. Scope
This plan applies to information-security reviews performed during the annual ISMS cycle.
The annual plan may cover:
- ISMS governance
- Information-security policies
- Risk management
- Statement of Applicability
- Access control
- Identity and MFA
- Privileged access
- Asset management
- Information classification
- Cloud security
- Network security
- Application security
- Secure development
- Vulnerability management
- Logging and monitoring
- Incident management
- Backup and recovery
- Business continuity
- Supplier security
- Physical security
- Security awareness
- Privacy
- Legal and regulatory compliance
- Customer security requirements
- AI security
- Corrective actions
The actual scope should be adjusted according to the organization’s risk profile.
3. Annual Security Review Objectives
The annual review program should determine whether:
☐ Security risks remain appropriately assessed
☐ Security controls remain relevant
☐ Controls are implemented as intended
☐ Controls operate effectively
☐ Access remains appropriate
☐ Security incidents are addressed
☐ Vulnerabilities are managed
☐ Suppliers remain appropriately assessed
☐ Business continuity arrangements remain effective
☐ Security requirements are being met
☐ Previous findings have been remediated
☐ Security improvements are being implemented
4. Annual Review Information
| Field | Details |
|---|---|
| Review Year | |
| Plan ID | |
| ISMS Scope | |
| Security Owner | |
| ISMS Manager | |
| Plan Approval Date | |
| Management Approver | |
| Previous Plan | |
| Overall Risk Level | |
| Planned Review Period | |
| Next Annual Review |
5. Annual Review Strategy
The organization should determine the review strategy based on:
Risk
- High-risk systems
- Sensitive information
- Privileged access
- Critical business services
- Significant supplier dependencies
Change
- New technology
- Cloud migration
- New applications
- Organizational changes
- New customers
- New regulatory requirements
Security Events
- Security incidents
- Data breaches
- Major vulnerabilities
- Repeated control failures
- Significant outages
Business Requirements
- Customer requirements
- Contractual commitments
- Certification requirements
- Regulatory obligations
- Business continuity requirements
6. Annual Security Review Calendar
A sample annual schedule:
| Month | Planned Review | Primary Focus | Owner | Status |
|---|---|---|---|---|
| January | Annual Security Planning | Risks, previous findings, objectives | Security | |
| February | Access Control Review | IAM, MFA, privileged access | IT/Security | |
| March | Cloud Security Review | AWS configuration, logging, network, IAM | Cloud/Security | |
| April | Application Security Review | SDLC, vulnerabilities, testing | Engineering/Security | |
| May | Supplier Security Review | Critical suppliers and third parties | Security/Procurement | |
| June | Incident Management Review | Incidents, response, lessons learned | Security | |
| July | Business Continuity Review | BCP, DR, backup, recovery | IT/BCP | |
| August | Information Protection Review | Classification, access, transfer, retention | Security | |
| September | Vulnerability & Configuration Review | Vulnerability and secure configuration | Security/IT | |
| October | Compliance & Contract Review | Legal, regulatory, customer requirements | Compliance/Legal | |
| November | Independent Security Review | Independent assessment of selected controls | Independent Reviewer | |
| December | Annual Security Summary | Findings, risk, improvements, next plan | Management/Security |
This is an example schedule. The organization should adjust timing according to its risks and business cycle.
7. Annual Review Register
Maintain a central register of planned reviews.
| Review ID | Review Area | Risk | Planned Date | Actual Date | Reviewer | Status | Findings |
|---|---|---|---|---|---|---|---|
Suggested statuses:
- Planned
- Scheduled
- In Progress
- Evidence Collection
- Findings Issued
- Remediation
- Follow-Up
- Completed
- Deferred
- Cancelled
8. Security Review Categories
8.1 Governance Review
Review:
☐ Information-security policy
☐ Security roles
☐ Security responsibilities
☐ ISMS objectives
☐ Management oversight
☐ Risk management
☐ Security metrics
☐ Security improvement activities
8.2 Risk Management Review
Review:
☐ Risk register
☐ Risk assessment methodology
☐ New risks
☐ Changed risks
☐ Risk treatment
☐ Residual risk
☐ Risk acceptance
☐ Risk owners
☐ Treatment deadlines
Key Question
Have changes in the business, technology, suppliers, threats, and information created new or changed security risks?
9. Access Control Review
Review:
☐ User accounts
☐ MFA
☐ SSO
☐ Privileged accounts
☐ Administrative access
☐ Contractor access
☐ Supplier access
☐ Temporary access
☐ Former employee accounts
☐ Role changes
☐ Access reviews
☐ Access exceptions
Evidence
- User access report
- Privileged access report
- MFA configuration
- Access approvals
- Access review records
- Offboarding evidence
10. Cloud Security Review
For AWS or other cloud environments:
☐ Cloud accounts
☐ IAM
☐ MFA
☐ Privileged access
☐ Security groups
☐ Network configuration
☐ Public exposure
☐ Encryption
☐ KMS/key management
☐ CloudTrail
☐ Security monitoring
☐ Backup
☐ Vulnerability management
☐ Configuration management
☐ Secrets management
Key Question
Is the production cloud environment still securely configured and appropriately monitored?
11. Application Security Review
Review:
☐ Secure development process
☐ Code review
☐ Branch protection
☐ CI/CD security
☐ Dependency management
☐ Open-source components
☐ Vulnerability scanning
☐ SAST/DAST where appropriate
☐ Penetration testing
☐ Security defect management
☐ Production deployment controls
☐ Secrets in repositories
12. Vulnerability Management Review
Review:
☐ Vulnerability scanning
☐ Vulnerability identification
☐ Risk classification
☐ Remediation SLAs
☐ Critical vulnerabilities
☐ Aging vulnerabilities
☐ Exceptions
☐ Retesting
☐ Patch management
☐ Dependency vulnerabilities
Metrics
| Metric | Result |
|---|---|
| Critical vulnerabilities | |
| High vulnerabilities | |
| Average remediation time | |
| Overdue vulnerabilities | |
| Exceptions | |
| Retested vulnerabilities |
13. Security Logging and Monitoring Review
Review:
☐ Authentication logging
☐ Privileged activity
☐ Cloud activity
☐ Security alerts
☐ Application logs
☐ Network logs
☐ Monitoring coverage
☐ Alert escalation
☐ Log protection
☐ Log retention
☐ Time synchronization
Key Question
Would the organization have sufficient visibility to detect and investigate a significant security event?
14. Incident Management Review
Review:
☐ Incident register
☐ Incident reporting
☐ Severity classification
☐ Escalation
☐ Response procedures
☐ Evidence preservation
☐ Investigation
☐ Communication
☐ Root cause analysis
☐ Corrective actions
☐ Lessons learned
☐ Incident trends
Annual Incident Summary
| Incident Type | Number | Highest Severity | Open Actions |
|---|---|---|---|
15. Backup and Recovery Review
Review:
☐ Backup coverage
☐ Backup frequency
☐ Backup protection
☐ Encryption
☐ Access control
☐ Backup monitoring
☐ Restore testing
☐ Recovery evidence
☐ RTO
☐ RPO
☐ Backup exceptions
Key Question
Can critical information and systems actually be recovered within the organization’s required recovery objectives?
16. Business Continuity Review
Review:
☐ Critical services
☐ Business Impact Analysis
☐ MTPD
☐ RTO
☐ RPO
☐ Recovery priorities
☐ Dependencies
☐ Alternate arrangements
☐ Crisis management
☐ Communication
☐ Continuity testing
17. Supplier Security Review
Review critical suppliers and relevant third parties.
☐ Supplier risk
☐ Security questionnaire
☐ Security assurance
☐ Contractual security requirements
☐ Access
☐ Information shared
☐ Subprocessors
☐ Data location
☐ Incidents
☐ Vulnerabilities
☐ Business continuity
☐ Open findings
☐ Exit arrangements
Prioritize suppliers based on risk rather than reviewing every supplier with identical depth.
18. Information Protection Review
Review:
☐ Information classification
☐ Information ownership
☐ Access restrictions
☐ Information transfer
☐ Encryption
☐ Data retention
☐ Data disposal
☐ Customer information
☐ Confidential information
☐ Restricted information
☐ Third-party information
19. Privacy and Personal Data Review
Where applicable:
☐ Personal data inventory
☐ Processing activities
☐ Data processors
☐ Subprocessors
☐ Data retention
☐ Data deletion
☐ Data subject requirements
☐ Data transfers
☐ Privacy notices
☐ Data-processing agreements
☐ Privacy incidents
☐ Customer requirements
20. Security Awareness Review
Review:
☐ Employee security training
☐ New-joiner training
☐ Annual training
☐ Phishing awareness
☐ Incident reporting awareness
☐ Password/MFA awareness
☐ Remote-working security
☐ Data protection awareness
☐ Role-specific training
Training Metrics
| Metric | Result |
|---|---|
| Employees requiring training | |
| Completed | |
| Completion percentage | |
| Overdue | |
| Phishing exercise result |
21. Physical Security Review
Where applicable:
☐ Office access
☐ Visitor management
☐ Physical access records
☐ Secure areas
☐ Equipment protection
☐ Environmental controls
☐ Media protection
☐ Secure disposal
☐ Remote-working arrangements
22. Legal, Regulatory and Contractual Review
Review:
☐ Legal requirements
☐ Regulatory requirements
☐ Customer contracts
☐ Supplier contracts
☐ Security commitments
☐ Data-protection obligations
☐ Incident notification requirements
☐ Retention requirements
☐ Security assurance commitments
☐ Audit rights
Key Question
Has the organization made any security commitment that is not currently supported by its controls or operational capability?
23. AI Security Review
Where AI systems or AI-enabled services are used:
☐ AI inventory
☐ Approved AI tools
☐ Information shared with AI systems
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ AI supplier assessment
☐ Model/provider risk
☐ Security controls
☐ Human oversight
☐ AI output risks
☐ AI-related incidents
☐ AI contractual requirements
24. Previous Findings Review
Review all significant findings from:
- Internal audits
- Independent reviews
- Customer audits
- Security assessments
- Penetration tests
- Supplier assessments
- Incident investigations
- Compliance assessments
| Finding | Source | Risk | Action | Due Date | Status | Verified |
|---|---|---|---|---|---|---|
Repeated or overdue findings should receive additional management attention.
25. Control Effectiveness Review
For selected controls, assess:
| Control | Requirement | Evidence | Result | Risk | Action |
|---|---|---|---|---|---|
Possible results:
☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Implemented
☐ Not Applicable
☐ Unable to Verify
26. Security Metrics
The annual review should use meaningful security metrics where available.
Examples:
Access
- Privileged accounts
- Overdue access reviews
- Former-user accounts
- MFA coverage
Vulnerability
- Critical vulnerabilities
- High vulnerabilities
- Average remediation time
- Overdue vulnerabilities
Incidents
- Number of incidents
- Severity
- Mean time to detect
- Mean time to respond
- Recurring incidents
Resilience
- Backup success rate
- Restore-test success
- RTO/RPO results
Supplier
- Critical suppliers reviewed
- Overdue assessments
- Open supplier findings
Metrics should support decisions rather than become reporting for its own sake.
27. Risk-Based Review Prioritization
Use the organization’s risk methodology to prioritize reviews.
Example:
| Risk Level | Review Approach |
|---|---|
| Low | Periodic/basic review |
| Medium | Scheduled control review |
| High | Detailed review and evidence testing |
| Critical | Enhanced review, independent assurance, and management oversight |
The organization should align these categories with its approved risk methodology.
28. Review Planning Criteria
When selecting areas for review, consider:
- Information sensitivity
- System criticality
- Customer impact
- Regulatory requirements
- Recent changes
- Previous findings
- Security incidents
- Vulnerabilities
- Supplier dependency
- Privileged access
- Business continuity dependency
- Technology complexity
29. Independent Review
At least one independent security review may be scheduled where appropriate.
The review may cover:
- ISMS governance
- Risk management
- Selected Annex A controls
- Cloud security
- Access control
- Incident management
- Supplier security
- Business continuity
The reviewer should have sufficient independence and competence for the review.
See:
Independent Information Security Review Procedure
30. Review Evidence
For each review, retain appropriate evidence.
Examples:
☐ Review plan
☐ Scope
☐ Review criteria
☐ Evidence request
☐ Evidence reviewed
☐ Test results
☐ Sampling records
☐ Screenshots where appropriate
☐ System reports
☐ Interviews
☐ Findings
☐ Management response
☐ Corrective actions
☐ Follow-up evidence
☐ Closure approval
Evidence should be proportionate to the risk and should not contain unnecessary credentials or secrets.
31. Findings and Corrective Actions
All significant findings should be recorded.
| Finding ID | Review | Finding | Risk | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
Corrective actions should address:
- Immediate risk
- Root cause
- Required control improvement
- Responsible owner
- Target date
- Verification method
32. Deferred Reviews
If a planned review cannot be completed:
☐ Reason documented
☐ Risk assessed
☐ Management notified
☐ Alternative review considered
☐ New date established
☐ Exception approved where required
☐ Register updated
A deferred review should not simply disappear from the annual plan.
33. Annual Security Review Summary
At the end of the year, summarize:
| Area | Reviews Planned | Completed | Findings | Open Actions |
|---|---|---|---|---|
| Governance | ||||
| Risk | ||||
| Access | ||||
| Cloud | ||||
| Application | ||||
| Vulnerability | ||||
| Incident | ||||
| BCP/DR | ||||
| Suppliers | ||||
| Privacy | ||||
| Compliance | ||||
| Independent Review |
34. Annual Security Risk Summary
At year-end, identify:
New Risks
Risks Increased
Risks Reduced
Accepted Risks
Outstanding High/Critical Risks
Significant Security Trends
35. Annual Security Improvement Plan
Use review results to define improvements for the next year.
| Improvement | Reason | Risk | Owner | Target Date | Status |
|---|---|---|---|---|---|
Examples:
- Improve privileged-access management
- Implement stronger cloud monitoring
- Improve vulnerability remediation
- Automate access reviews
- Improve backup testing
- Strengthen supplier monitoring
- Improve incident response
- Implement security automation
36. Management Review
The annual security review results should be presented to appropriate management.
Management should consider:
- Significant findings
- Security risks
- Incident trends
- Vulnerability trends
- Control effectiveness
- Customer requirements
- Regulatory changes
- Supplier risks
- Business continuity
- Security objectives
- Required resources
- Improvement priorities
Management Review Record
Meeting Date: __________________
Participants: __________________
Key Findings: __________________
Key Decisions: __________________
Resources Approved: __________________
Risk Decisions: __________________
Improvement Priorities: __________________
37. Annual Plan Approval
Prepared By
Name: __________________
Role: __________________
Date: __________________
Reviewed By
Name: __________________
Role: __________________
Date: __________________
Approved By
Name: __________________
Role: __________________
Date: __________________
38. Next-Year Planning
The next annual security review plan should consider:
☐ Previous findings
☐ Open corrective actions
☐ New risks
☐ Security incidents
☐ Major technology changes
☐ New suppliers
☐ New customers
☐ Regulatory changes
☐ Contractual changes
☐ Audit results
☐ Business strategy
☐ Security objectives
☐ Changes to ISMS scope
Next-Year Priorities
39. AWS SaaS Startup Example
A SaaS startup operates its production environment primarily on AWS.
Its annual security review plan includes:
Q1
Access & Identity
- AWS IAM
- SSO
- MFA
- Privileged access
- Employee access
- GitHub access
Q2
Cloud & Application Security
- AWS configuration
- Security groups
- CloudTrail
- Logging
- Monitoring
- Vulnerability management
- CI/CD
Q3
Resilience & Suppliers
- Backup
- Restore testing
- Disaster recovery
- Business continuity
- Critical suppliers
- Subprocessors
Q4
ISMS & Independent Assurance
- Risk assessment
- SoA review
- Security policies
- Incident management
- Customer requirements
- Independent security review
- Annual management review
Annual Audit Trail
Annual Plan → Risk Prioritization → Review Schedule → Evidence Collection → Control Testing → Findings → Corrective Actions → Follow-Up → Management Review → Improvement Plan → Next Annual Plan
40. Startup-Friendly Annual Security Model
A small startup can begin with a focused annual cycle.
Monthly
Review critical operational indicators:
- Critical vulnerabilities
- Security incidents
- Privileged access changes
- Backup failures
- Major security alerts
Quarterly
Review selected high-risk controls:
- Access
- Cloud security
- Vulnerability management
- Suppliers
- Backup
Semi-Annual
Perform deeper reviews of:
- Incident management
- Business continuity
- Application security
- Information protection
Annual
Perform:
- Risk review
- ISMS review
- Independent security review
- Security objectives review
- Management review
- Improvement planning
The exact schedule should be adapted to the organization’s size, risks, and obligations.
41. Common Mistakes
Avoid:
- Creating an annual plan but not executing it.
- Reviewing every control with identical frequency.
- Focusing only on documentation.
- Ignoring operational evidence.
- Ignoring previous findings.
- Deferring high-risk reviews without risk assessment.
- Performing reviews only immediately before certification.
- Failing to review new technology.
- Ignoring cloud configuration changes.
- Ignoring supplier changes.
- Ignoring customer security commitments.
- Treating security metrics as the objective rather than a decision-support tool.
- Closing findings without verification.
- Failing to convert review results into improvement actions.
42. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Defines overall security direction |
| Information Security Risk Assessment | Identifies and evaluates risks |
| Risk Treatment Plan | Tracks risk treatment |
| Statement of Applicability | Defines applicable controls |
| Internal Audit Procedure | Defines formal internal audit |
| Independent Information Security Review Procedure | Defines independent reviews |
| Security Control Testing Procedure | Defines control testing |
| Access Review Checklist | Supports access reviews |
| Cloud Security Review | Supports cloud reviews |
| Supplier Security Review | Supports supplier reviews |
| Incident Management | Provides incident review evidence |
| BCP/DR Plan | Supports resilience reviews |
| Corrective Action Tracker | Tracks remediation |
| Management Review | Reviews ISMS performance |
| ISMS Improvement Log | Tracks improvement |
43. ISO/IEC 27001 Connection
An annual security review plan supports the organization’s risk-based ISMS by providing a structured mechanism for reviewing security controls, risks, processes, performance, and improvements.
The plan can support activities related to:
- Risk management
- Control monitoring
- Internal audit
- Management review
- Corrective action
- Continual improvement
- Security performance evaluation
The annual schedule itself is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate review frequency and scope based on its:
- Information-security risks
- ISMS scope
- Business requirements
- Control environment
- Legal/regulatory obligations
- Customer requirements
- Significant changes
- Previous review results
44. Final Annual Security Review Audit Trail
For each annual cycle, the organization should be able to demonstrate:
What security areas were planned for review?
Why were those areas selected?
What risks were considered?
Which reviews were completed?
What evidence was examined?
Which controls were tested?
What findings were identified?
Which risks remain open?
What corrective actions were assigned?
Were corrective actions verified?
What did management review?
What improvements were approved?
How were the results used to create the next year’s plan?
Final Principle
Risk → Prioritize → Plan → Review → Test → Evidence → Findings → Remediate → Verify → Management Review → Improve → Repeat
