Security Questionnaire Mapper
Governance and policy · question family

Independent audit and certification: the clause the question tests

Whether someone independent has examined the controls, against what, and when.

How the customer usually asks it

example

"Is your organisation independently audited against a recognised security standard?"

Read this question

Anchor clauses

2 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.35 Independent review of information security · clause 9.2 Internal audit (named, not quoted)
SOC 2 (Trust Services Criteria)CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The current certificate or attestation report with its scope statement and period, and the latest internal audit summary.

The clauses, with what an assessor asks for

ISO 27001 5.35 Independent review of information security

Have the security approach and its implementation reviewed independently on a cadence and after significant change.

Evidence an assessor expects: Review schedule; Review reports; Reviewer independence; Change trigger log
Where answers usually fall short: Reviews performed by internal staff only; Infrequent or ad-hoc review cadence
Source: ISO/IEC 27001:2022
SOC 2 CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The plan for ongoing and separate evaluations, showing scope, type, frequency and who performs them; Results of evaluations performed in the period, such as internal audit reports, control self assessments, vulnerability assessments and penetration tests; Evidence evaluators are objective and knowledgeable, and independent of the activity evaluated; Evidence a baseline understanding of the control system exists and is used to scope evaluations; Evidence of the mix and rate of change, showing evaluations are adjusted as risk changes
Where answers usually fall short: Only one annual assessment performed, with no ongoing evaluation between times; Evaluations performed by the people who operate the controls, so objectivity fails
Source: SOC 2 (Trust Services Criteria)

Other families in governance and policy