ISO 27001A.8 — Protection of information systems during audit testing
A.8.34
Protection of information systems during audit testing
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Plan and protect audit tests and other assurance activities that could affect operational systems.
Points of focus
- Authorize and scope tests
- Notify operations
- Use non-destructive methods where possible
- Monitor for impact
Implementation notes
Require written authorization and scope for pen tests. Prefer staging for destructive tests. Give auditors time-bound least-privilege access. Watch error budgets during scans. Assign a named owner in the SoA, tie operating evidence to pen test authorization letter / roe, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show ROE for the last pen test and how access was revoked afterward.
Evidence auditors typically request:
- Pen test authorization letter / ROE
- Change/maintenance window tickets
- Monitoring during tests
- Post-test reports
Common gaps
- Surprise scans knocking over prod
- Auditors given standing admin
- No contact path during test
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.34 | This control |
| SOC 2 | CC4.1, CC7.1 | Related SOC 2 themes (CC4.1, CC7.1) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.34)
Frequently Asked Questions
Yes — document cadence, ownership, and prod impact controls.
Prefer time-bound access and evidence exports.
A.8.8 is ongoing vuln management; A.8.34 is protecting ops during assurance activities.
Even without owned data centers, protection of information systems during audit testing still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with pen test authorization letter / roe, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.