1. Purpose
The Information Security Review Checklist provides a structured method for reviewing the organization’s information-security environment, controls, processes, technology, and supporting evidence.
The checklist helps determine whether information-security arrangements:
- Remain appropriate for identified risks
- Are implemented as intended
- Are operating effectively
- Protect organizational and customer information
- Support business requirements
- Address applicable security obligations
- Continue to meet defined control requirements
- Have appropriate evidence
- Require corrective action or improvement
Core Principle
Define Scope → Understand Risk → Review Controls → Verify Evidence → Identify Gaps → Assess Risk → Correct → Verify → Improve
2. When to Use
Use this checklist for:
- Periodic information-security reviews
- Annual security reviews
- Quarterly security reviews
- Control reviews
- ISMS readiness reviews
- Pre-audit assessments
- Post-incident reviews
- Technology-change reviews
- Customer security reviews
- Supplier/security assurance reviews
- Management-requested security reviews
The depth and frequency should be proportionate to risk.
3. Review Information
| Field | Details |
|---|---|
| Review ID | |
| Review Title | |
| Review Date | |
| Review Period | |
| Reviewer | |
| Business Owner | |
| Security Owner | |
| ISMS Scope | |
| Review Scope | |
| Review Criteria | |
| Risk Level | |
| Previous Review | |
| Review Status |
4. Review Objective
Define what the review is intended to determine.
Examples:
- Verify effectiveness of access controls.
- Review AWS production security.
- Assess information-security controls.
- Review compliance with internal security requirements.
- Verify remediation of previous findings.
- Assess security following a major technology change.
Objective
5. Review Scope
Included
Excluded
Systems
Business Processes
Information
Locations
Time Period
6. Review Criteria
Identify the requirements against which the review will be performed.
☐ Information-security policies
☐ Security procedures
☐ Risk assessment
☐ Risk treatment plan
☐ Statement of Applicability
☐ Security standards
☐ Technical baselines
☐ Customer requirements
☐ Contractual requirements
☐ Legal requirements
☐ Regulatory requirements
☐ ISO/IEC 27001 requirements
☐ Other: __________________
7. Review Method
Select applicable methods:
☐ Document review
☐ Interviews
☐ Observation
☐ Sampling
☐ Configuration review
☐ Evidence testing
☐ Access review
☐ Technical testing
☐ Log review
☐ System-generated reports
☐ Previous finding verification
8. Information Security Governance
Review whether:
☐ Information-security policy is approved
☐ Policy remains current
☐ Security responsibilities are defined
☐ Security ownership is assigned
☐ Security objectives are defined
☐ Management oversight exists
☐ Security performance is monitored
☐ Security risks are reported
☐ Security decisions are documented
☐ Security exceptions are controlled
Evidence
9. ISMS Scope Review
Verify:
☐ ISMS scope is documented
☐ Scope remains accurate
☐ Business changes considered
☐ New systems considered
☐ New locations considered
☐ New suppliers considered
☐ New services considered
☐ Cloud environments considered
☐ Customer requirements considered
☐ Scope exclusions remain appropriate
Scope Changes
10. Information Security Risk Management
Review:
☐ Risk methodology
☐ Risk register
☐ New risks
☐ Changed risks
☐ Risk owners
☐ Risk treatment
☐ Risk acceptance
☐ Residual risk
☐ Treatment deadlines
☐ Risk monitoring
Key Question
Have business, technology, supplier, threat, or regulatory changes created new or changed information-security risks?
11. Statement of Applicability
Review:
☐ SoA is current
☐ Control applicability reviewed
☐ Control exclusions have rationale
☐ New risks considered
☐ New controls considered
☐ Custom controls considered where necessary
☐ Implementation status accurate
☐ Evidence available
☐ SoA reflects current ISMS scope
12. Asset Management
Review:
☐ Hardware inventory
☐ Software inventory
☐ Cloud resources
☐ Applications
☐ Databases
☐ Information assets
☐ Critical assets
☐ Asset owners
☐ Asset classification
☐ Asset lifecycle
☐ Unsupported assets
☐ Unauthorized assets
Evidence
13. Information Classification
Verify:
☐ Classification scheme exists
☐ Information owners identified
☐ Sensitive information identified
☐ Customer information classified
☐ Personal data identified
☐ Confidential information protected
☐ Restricted information protected
☐ Classification reflected in access controls
☐ Handling requirements defined
14. Access Control
Review:
☐ User accounts
☐ Access approvals
☐ Least privilege
☐ Role-based access
☐ MFA
☐ SSO
☐ Privileged access
☐ Temporary access
☐ Contractor access
☐ Supplier access
☐ Former employee access
☐ Role changes
☐ Periodic access reviews
Evidence
15. Privileged Access
Review:
☐ Administrative accounts identified
☐ Business justification exists
☐ Named accounts used
☐ MFA enabled
☐ Privileges minimized
☐ Privileged activity logged
☐ Privileged access monitored
☐ Periodic review performed
☐ Unused privileges removed
☐ Emergency access controlled
16. Authentication
Review:
☐ Password requirements
☐ MFA
☐ SSO
☐ Authentication controls
☐ Account lockout/rate limiting where appropriate
☐ Session management
☐ Service accounts
☐ API authentication
☐ Token management
☐ Credential rotation
17. Remote Access
Review:
☐ Remote access approved
☐ MFA enabled
☐ Secure connection
☐ VPN/approved remote-access mechanism
☐ Device security
☐ Access restrictions
☐ Logging
☐ Monitoring
☐ Temporary access controls
18. Cloud Security
For AWS or other cloud environments:
☐ Cloud accounts identified
☐ IAM reviewed
☐ MFA reviewed
☐ Privileged roles reviewed
☐ Security groups reviewed
☐ Network exposure reviewed
☐ Public resources reviewed
☐ Encryption reviewed
☐ KMS/key management reviewed
☐ Secrets management reviewed
☐ CloudTrail/logging reviewed
☐ Security monitoring reviewed
☐ Backup reviewed
☐ Vulnerability management reviewed
☐ Configuration management reviewed
19. Network Security
Review:
☐ Network architecture
☐ Segmentation
☐ Firewalls
☐ Security groups
☐ Secure remote access
☐ Internet exposure
☐ Administrative access
☐ Network monitoring
☐ Intrusion detection/prevention where appropriate
☐ Network changes
☐ Unauthorized connections
20. Endpoint Security
Review:
☐ Endpoint inventory
☐ Supported operating systems
☐ Security patching
☐ Malware protection
☐ Device encryption
☐ Device management
☐ Secure configuration
☐ Remote-wipe capability where appropriate
☐ Lost/stolen-device process
☐ BYOD controls where applicable
21. Application Security
Review:
☐ Secure development process
☐ Security requirements
☐ Code review
☐ Branch protection
☐ Dependency management
☐ SAST/DAST where appropriate
☐ Vulnerability management
☐ Penetration testing
☐ Security testing
☐ Secure deployment
☐ Production access
☐ Secrets management
☐ Application logging
22. Source Code Security
Review:
☐ Repository inventory
☐ Repository ownership
☐ Access review
☐ MFA
☐ Branch protection
☐ Pull-request review
☐ Administrative access
☐ Contractor access
☐ Supplier access
☐ CI/CD access
☐ Service accounts
☐ SSH keys
☐ Personal access tokens
☐ OAuth applications
☐ Secret scanning
☐ Repository visibility
☐ Forks and copies
23. Vulnerability Management
Review:
☐ Vulnerability scanning
☐ Vulnerability identification
☐ Risk classification
☐ Critical vulnerabilities
☐ High vulnerabilities
☐ Remediation deadlines
☐ Overdue vulnerabilities
☐ Exceptions
☐ Retesting
☐ Dependency vulnerabilities
☐ Infrastructure vulnerabilities
☐ Application vulnerabilities
Metrics
| Metric | Result |
|---|---|
| Critical vulnerabilities | |
| High vulnerabilities | |
| Overdue vulnerabilities | |
| Average remediation time | |
| Exceptions |
24. Patch Management
Review:
☐ Patch process
☐ Critical patching
☐ Operating-system updates
☐ Application updates
☐ Cloud updates
☐ Emergency patching
☐ Patch testing
☐ Patch evidence
☐ Unsupported software
☐ Exceptions
25. Malware Protection
Where applicable:
☐ Endpoint protection
☐ Malware detection
☐ Malware alerts
☐ Quarantine
☐ Investigation
☐ Response procedure
☐ Protection coverage
☐ Signature/engine updates
☐ Monitoring
26. Logging and Monitoring
Review:
☐ Authentication logs
☐ Privileged activity
☐ Cloud activity
☐ Security events
☐ Application logs
☐ Network logs
☐ Database activity where appropriate
☐ CI/CD activity
☐ Security alerts
☐ Monitoring coverage
☐ Log protection
☐ Log retention
☐ Time synchronization
Key Question
Can the organization detect and investigate significant security events using available evidence?
27. Security Incident Management
Review:
☐ Incident policy
☐ Incident procedure
☐ Incident reporting
☐ Incident register
☐ Severity classification
☐ Escalation
☐ Investigation
☐ Evidence preservation
☐ Containment
☐ Eradication
☐ Recovery
☐ Communication
☐ Root cause analysis
☐ Corrective actions
☐ Lessons learned
28. Incident Trend Review
Review:
| Incident Type | Number | Highest Severity | Recurring? | Open Actions |
|---|---|---|---|---|
Look for:
- Recurring incidents
- Increasing severity
- Repeated root causes
- Control failures
- Delayed response
- Unresolved corrective actions
29. Backup and Recovery
Review:
☐ Backup coverage
☐ Backup frequency
☐ Backup protection
☐ Encryption
☐ Backup access controls
☐ Backup monitoring
☐ Restore testing
☐ Recovery evidence
☐ RTO
☐ RPO
☐ Backup failures
☐ Backup exceptions
30. Business Continuity
Review:
☐ Critical services identified
☐ Business Impact Analysis
☐ MTPD
☐ RTO
☐ RPO
☐ Recovery priorities
☐ Dependencies
☐ Alternate arrangements
☐ Crisis communication
☐ Continuity testing
☐ Lessons learned
31. Disaster Recovery
Review:
☐ Disaster recovery plan
☐ Recovery environments
☐ Infrastructure recovery
☐ Data recovery
☐ Application recovery
☐ IAM recovery
☐ Network recovery
☐ Secrets recovery
☐ Monitoring recovery
☐ Recovery testing
☐ Actual RTO/RPO measured
☐ Recovery gaps tracked
32. Supplier and Third-Party Security
Review:
☐ Supplier register
☐ Critical supplier register
☐ Supplier risk assessment
☐ Due diligence
☐ Security questionnaire
☐ Security assurance
☐ Contractual requirements
☐ Supplier access
☐ Information shared
☐ Subprocessors
☐ Data location
☐ Supplier incidents
☐ Supplier vulnerabilities
☐ Business continuity
☐ Supplier exit arrangements
33. Information Transfer
Review:
☐ Approved transfer methods
☐ Encryption
☐ Secure file sharing
☐ API security
☐ Recipient verification
☐ Access restrictions
☐ Transfer logging where appropriate
☐ Data minimization
☐ Customer requirements
☐ Third-party transfer controls
34. Data Protection and Privacy
Where applicable:
☐ Personal data identified
☐ Processing purposes identified
☐ Data inventory
☐ Data retention
☐ Data deletion
☐ Data subject requirements
☐ Data processors
☐ Subprocessors
☐ Data locations
☐ International transfers
☐ Privacy incidents
☐ Data-processing agreements
35. Security Awareness
Review:
☐ Security awareness program
☐ New-joiner training
☐ Annual training
☐ Role-specific training
☐ Phishing awareness
☐ Incident reporting awareness
☐ Password/MFA awareness
☐ Remote-working security
☐ Data protection awareness
Training Metrics
| Metric | Result |
|---|---|
| Employees requiring training | |
| Completed | |
| Completion percentage | |
| Overdue |
36. Physical Security
Where applicable:
☐ Physical access controls
☐ Visitor management
☐ Secure areas
☐ CCTV/security monitoring
☐ Equipment protection
☐ Environmental protection
☐ Media protection
☐ Secure disposal
☐ Office security
☐ Remote-working arrangements
37. Security of Information During Change
Review whether security is considered when changes occur.
☐ Change management process
☐ Security impact assessment
☐ Risk assessment
☐ Approval
☐ Testing
☐ Rollback planning
☐ Emergency change process
☐ Post-change validation
☐ Documentation
☐ Security monitoring
38. Configuration Management
Review:
☐ Approved baselines
☐ Secure configuration
☐ Configuration inventory
☐ Configuration changes
☐ Unauthorized changes
☐ Configuration monitoring
☐ Configuration drift
☐ Infrastructure as Code
☐ Exceptions
☐ Periodic review
39. Secrets and Credential Management
Review:
☐ Password management
☐ API keys
☐ Access tokens
☐ Cloud credentials
☐ SSH keys
☐ Certificates
☐ Encryption keys
☐ Secure secrets storage
☐ Rotation
☐ Revocation
☐ Secret scanning
☐ Compromise response
40. Cryptography and Encryption
Review:
☐ Encryption in transit
☐ Encryption at rest
☐ Key management
☐ Key access controls
☐ Key rotation
☐ Certificate management
☐ Secure cryptographic mechanisms
☐ Customer encryption requirements
41. Information Retention and Disposal
Review:
☐ Retention requirements
☐ Customer requirements
☐ Legal requirements
☐ Data retention periods
☐ Secure disposal
☐ Data deletion
☐ Media disposal
☐ Cloud data deletion
☐ Supplier data deletion
☐ Evidence of disposal where required
42. Intellectual Property Protection
Review:
☐ IP ownership
☐ Source-code protection
☐ Customer IP
☐ Third-party IP
☐ Open-source software
☐ Software licensing
☐ Copyrighted content
☐ Confidential business information
☐ Trade secrets
☐ IP access controls
☐ Employee/contractor IP obligations
43. Software License Compliance
Review:
☐ Software license register
☐ Commercial software
☐ SaaS subscriptions
☐ Open-source software
☐ License obligations
☐ License expiry
☐ Unsupported software
☐ Unauthorized software
☐ License conflicts
☐ Customer distribution requirements
44. AI Security
Where AI is used:
☐ AI inventory
☐ Approved AI services
☐ AI supplier assessment
☐ Data shared with AI
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ AI access controls
☐ Model/provider information
☐ Data retention
☐ Training/use of submitted data
☐ Human oversight
☐ AI-related incidents
☐ AI security risks
45. Security Requirements From Contracts
Review:
☐ Customer security commitments
☐ Supplier security commitments
☐ Security SLAs
☐ Incident notification requirements
☐ Data protection requirements
☐ Encryption requirements
☐ Availability requirements
☐ RTO/RPO commitments
☐ Audit rights
☐ Security testing requirements
☐ Vulnerability remediation requirements
☐ Data deletion requirements
☐ Subprocessor requirements
Key Question
Are contractual security commitments actually supported by implemented controls and operational capability?
46. Legal and Regulatory Compliance
Review:
☐ Legal requirements identified
☐ Regulatory requirements identified
☐ Applicability assessed
☐ Obligations register updated
☐ Requirement owners assigned
☐ Control mapping performed
☐ Evidence available
☐ Regulatory changes monitored
☐ Compliance gaps tracked
47. Security Testing
Review whether appropriate security testing has been performed.
☐ Vulnerability scanning
☐ Penetration testing
☐ Application testing
☐ Cloud security assessment
☐ Configuration assessment
☐ Security control testing
☐ Backup/restore testing
☐ Disaster recovery testing
☐ Phishing testing where appropriate
Review:
- Scope
- Date
- Findings
- Severity
- Remediation
- Retesting
48. Security Exceptions
Review:
☐ Exceptions documented
☐ Business justification
☐ Risk assessed
☐ Compensating controls
☐ Approval
☐ Expiry date
☐ Periodic review
☐ Closure
No significant security exception should remain open indefinitely without review.
49. Previous Findings
Review findings from:
☐ Internal audits
☐ Independent reviews
☐ Penetration tests
☐ Vulnerability assessments
☐ Customer assessments
☐ Supplier reviews
☐ Incidents
☐ Compliance assessments
| Finding | Source | Risk | Action | Due Date | Status | Verified |
|---|---|---|---|---|---|---|
50. Control Effectiveness Assessment
For each selected control:
| Control | Requirement | Evidence | Result | Risk | Action |
|---|---|---|---|---|---|
Result
☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Implemented
☐ Not Applicable
☐ Unable to Verify
51. Evidence Quality
Assess whether evidence is:
☐ Relevant
☐ Current
☐ Complete
☐ Authentic
☐ Traceable
☐ Sufficient
☐ Consistent
☐ Representative
Evidence should demonstrate actual operation where the control requires ongoing operation.
52. Review Findings
Record identified gaps.
| Finding ID | Area | Requirement | Condition | Evidence | Risk | Severity |
|---|---|---|---|---|---|---|
A finding should clearly distinguish the requirement from the observed condition.
53. Corrective Action
| Action ID | Finding | Root Cause | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
Corrective action should address the underlying cause where appropriate.
54. Risk Treatment
For significant findings:
☐ Reduce
☐ Avoid
☐ Share/Transfer
☐ Accept
Treatment
Residual Risk
Risk acceptance should follow the organization’s approved risk-acceptance process.
55. Review Summary
| Area | Result | Finding | Risk |
|---|---|---|---|
| Governance | |||
| Risk Management | |||
| Access Control | |||
| Cloud Security | |||
| Application Security | |||
| Vulnerability Management | |||
| Incident Management | |||
| BCP/DR | |||
| Supplier Security | |||
| Privacy | |||
| Compliance | |||
| Physical Security | |||
| Overall Security |
56. Overall Review Result
☐ Controls operating effectively
☐ Controls generally effective with improvements required
☐ Material weaknesses identified
☐ Significant remediation required
☐ Further assessment required
☐ Unable to conclude due to insufficient evidence
Overall Conclusion
The conclusion should reflect only the defined scope and evidence reviewed.
57. Management Review
Management should review significant results.
Management Review Information
Date: __________________
Participants: __________________
Significant Findings: __________________
Risk Decisions: __________________
Resources Required: __________________
Improvement Decisions: __________________
58. Follow-Up Review
After corrective actions:
☐ Action completed
☐ Evidence received
☐ Control retested
☐ Risk reassessed
☐ Residual risk reviewed
☐ Finding closed
☐ Finding remains open
Follow-Up Result
59. Review Approval
Reviewer
Name: __________________
Role: __________________
Signature/Approval: __________________
Date: __________________
Control/Business Owner
Name: __________________
Role: __________________
Date: __________________
Security/ISMS Owner
Name: __________________
Role: __________________
Date: __________________
60. AWS SaaS Startup Example
A SaaS startup performs an annual information-security review covering its production AWS environment and supporting security processes.
Scope
- AWS production
- GitHub
- IAM
- Employee access
- Application security
- Logging
- Vulnerability management
- Backup
- Incident management
- Critical suppliers
Evidence Reviewed
- IAM access report
- MFA configuration
- CloudTrail configuration
- Security-group configuration
- Vulnerability report
- Backup evidence
- Incident register
- Access-review records
- Security policies
- Risk register
Example Finding
Area: Privileged Access
Requirement: Privileged access should be restricted to authorized personnel.
Condition: One inactive administrative permission remained assigned to a user who no longer required the privilege.
Risk: Unnecessary privileged access could increase the potential impact of account compromise.
Action: Remove the unnecessary privilege, review similar permissions, and update the periodic privileged-access review.
Audit Trail
Review Scope → Risk Assessment → Evidence Request → Evidence Review → Control Testing → Finding → Risk Assessment → Corrective Action → Retest → Closure
61. Startup-Friendly Review Model
A startup can simplify the review by prioritizing high-risk areas.
Monthly
Review:
- Critical vulnerabilities
- Security incidents
- Privileged access changes
- Backup failures
- Major security alerts
Quarterly
Review:
- Access control
- Cloud security
- Vulnerability management
- Supplier security
- Backup
Semi-Annual
Review:
- Application security
- Incident management
- Business continuity
- Information protection
Annual
Review:
- ISMS
- Risk assessment
- SoA
- Security policies
- Legal/regulatory requirements
- Customer security requirements
- Independent security review
- Management review
The frequency should be adjusted based on risk and business requirements.
62. Common Mistakes
Avoid:
- Treating the checklist as a paperwork exercise.
- Reviewing policies without testing implementation.
- Checking only whether documents exist.
- Ignoring operational evidence.
- Reviewing every control with identical depth.
- Failing to consider recent changes.
- Ignoring previous findings.
- Ignoring supplier dependencies.
- Ignoring cloud configuration.
- Ignoring privileged access.
- Closing findings without retesting.
- Accepting evidence that is outdated or incomplete.
- Collecting unnecessary credentials as evidence.
- Performing technical testing without authorization.
63. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Defines overall security requirements |
| Information Security Risk Assessment | Identifies security risks |
| Risk Treatment Plan | Tracks treatment |
| Statement of Applicability | Defines applicable controls |
| Annual Security Review Plan | Defines planned review schedule |
| Independent Information Security Review Procedure | Defines independent reviews |
| Independent Reviewer Assessment Checklist | Evaluates reviewers |
| Internal Audit Procedure | Defines formal internal audit |
| Security Control Testing Procedure | Defines detailed control testing |
| Access Review Checklist | Supports access reviews |
| Cloud Security Review | Supports cloud assessment |
| Supplier Security Review | Supports supplier assessment |
| Incident Management | Provides incident evidence |
| Corrective Action Tracker | Tracks remediation |
| Management Review | Provides management oversight |
| ISMS Improvement Log | Tracks improvement |
64. ISO/IEC 27001 Connection
The Information Security Review Checklist supports the organization’s risk-based ISMS assurance and improvement activities.
It can provide evidence relating to:
- Risk management
- Security-control implementation
- Control effectiveness
- Monitoring and measurement
- Internal assurance
- Corrective action
- Management review
- Continual improvement
The checklist itself is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate review scope, frequency, evidence, and methodology based on its:
- ISMS scope
- Information-security risks
- Business requirements
- Applicable controls
- Legal/regulatory requirements
- Customer requirements
- Contractual commitments
- Previous findings
- Significant changes
65. Audit Evidence
Retain appropriate evidence such as:
☐ Completed review checklist
☐ Review scope
☐ Review criteria
☐ Evidence request
☐ Evidence reviewed
☐ Sampling records
☐ Test results
☐ Configuration evidence
☐ Findings
☐ Risk assessment
☐ Management response
☐ Corrective actions
☐ Follow-up evidence
☐ Closure approval
Evidence retention should follow the organization’s records-retention requirements.
Do not retain unnecessary passwords, API keys, private keys, tokens, or other authentication secrets.
66. Final Information Security Review Audit Trail
For each significant review, the organization should be able to demonstrate:
What was reviewed?
Why was it reviewed?
What risks were considered?
What requirements were used?
What evidence was examined?
Which controls were tested?
What findings were identified?
What risks resulted from those findings?
Who owns the corrective actions?
Were corrective actions completed?
Were controls retested?
What did management decide?
What improvements were made?
Final Principle
Define → Assess Risk → Review → Test → Evidence → Identify Gaps → Treat Risk → Correct → Retest → Approve → Improve
