Question group
Operations, logging and vulnerability
Logging, patching, penetration testing, endpoint protection, secure development, network segmentation and physical security: the running of the service, and the section with the most requests for reports.
The families
7 families| Family and a typical question | ISO 27001 | Evidence expected |
|---|---|---|
| Logging and monitoringDo you centrally log and monitor security events? | 8.15, 8.16 | The logging standard naming what is logged and for how long, the monitoring and alerting set-up, and a sample of the review record. |
| Vulnerability and patch managementHow quickly are critical security patches applied to production systems? | 8.8 | The vulnerability management procedure with remediation windows by severity, the latest scan summary, and patch compliance figures for production. |
| Penetration testingDo you commission an independent penetration test of the service at least once a year? | 8.8 | The latest penetration test summary (tester, date, scope, findings by severity) and the remediation status of each finding. |
| Malware protection and endpointsIs anti-malware software installed on all laptops and servers? | 8.7 | The endpoint protection standard, coverage figures across laptops and servers, and the device management baseline. |
| Secure development and changeDo you follow a secure software development lifecycle, including code review before release? | 8.25 | The secure development standard, a sample of recent changes with review and approval records, and the security testing run in the pipeline. |
| Network security and segmentationAre production networks segmented and protected by firewalls? | 8.20 | The network diagram for the service, the segmentation between environments, and the last firewall rule review. |
| Physical securityDescribe the physical security controls at the data centres that host our data. | 7.1 | The physical security standard for offices and hosting sites, and for hosted services the provider's attestation covering its data centres. |