Expert Advice Community


List of evidences / artefacts

Guest user Created:   Mar 10, 2018 Last commented:   Mar 10, 2018

List of evidences / artefacts

I need list of evidence/ artifacts to be asked client while doing risk assessment , it should include all the 114 controls, please provide all the 114 controls evidence to be asked client.
0 0

Assign topic to the user


List of questions to ask during the ISO 27001 audit.


List of questions to ask during the ISO 27001 audit.

Rhand Leal Mar 10, 2018

Example: HR security domain :-
Evidence required : Approved HR policy document, Roles and responsibility in the table in ISMS, Last 5 onboarded resources with training completed list and offboarded 5 resources list with offboard checklist and data removable certificate, access revoked mail confirmation. etc

Answer: It seems to me that you are making a mistake here.

When performing risk assessment there is no need to list evidences /artefacts. In this step you have to identify which risks are relevant considering the scope of the assessment.

Evidences and/or artefacts regarding the 114 controls from ISO 27001 Annex A are used when you perform either a gap analysis (to identify how many controls you already have implemented) or an audit (to evidence the controls implementation and performance).

For a list of questions regarding gap analysis, I suggest y ou to take a look at our free ISO 27001 Gap Analysis Tool at this link:

Its question-and-answer format allows you to visualize which specific elements of an information security management system are already implemented, and what still needs to be done.

For a list of questions regarding internal audit, I suggest you to take a look at the free demo of our Internal Audit Checklist at this link:

For each clause or control from the standard the checklist provides one or more questions which should be asked during the audit in order to verify the implementation.

These articles will provide you further explanation about gap analysis, internal audit, risk assessment and checklists:
- ISO 27001 gap analysis vs. risk assessment
- Risk assessment vs. internal audit in ISO 27001 and ISO 22301
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301

0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 09, 2018

Mar 09, 2018