A.8.34 Technological
Protection of information systems during audit testing
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-6mostlyaligns with — Both emphasize monitoring, logging, and review of all access performed for audit or testing purposes.
- CA-8mostlyaligns with — Both controls require explicit authorization, scope control, and safeguards when performing technical testing that could affect live systems.
- AC-3partialaligns with — Both enforce controlled, authorized access to systems and data, including restrictions to read-only where feasible.
- AC-6partialaligns with — Both limit privileges granted to auditors or testers to the minimum necessary to complete their tasks.
- CM-3partialaligns with — Both require management approval and controlled execution of changes or tests that could impact system configuration or availability.
- SI-2partialaligns with — Both address the need to schedule and isolate testing activities so they do not disrupt operational systems or introduce unapproved changes.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-01mostlyaligns with — The control restricts and monitors all audit-related access to production systems, directly supporting the CSF outcome of protecting networks and environments from unauthorized logical access.
- PR.PS-04mostlyaligns with — By requiring monitoring and logging of every audit access and test activity, the control ensures log records are generated and available for continuous monitoring.
- DE.CM-09partialaligns with — Requiring that audit tests run outside business hours and that all access is logged supports continuous monitoring of computing environments to detect potentially adverse events.
- ID.RA-01partialaligns with — The control enables controlled, read-only or supervised access so that vulnerabilities and configuration issues can be identified and recorded without introducing new risks.
- PR.AA-05partialaligns with — The control enforces explicit management approval, scope limitation, and device-security verification before any elevated access is granted, aligning with policy-driven access authorization and review.
Related OWASP ASVS 5.0 requirements (8)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.2.4partialaligns with — The ISO guidance to identify and agree on external or special processing requests (such as audit tools) maps to the ASVS requirement that an allowlist defines the external resources or systems the application is permitted to communicate with.
- V13.4.2partialaligns with — Limiting audit tests to read-only access or isolated copies and deleting them afterward supports the ASVS requirement to disable debug modes in production to prevent exposure of debugging features.
- V13.4.5partialaligns with — The ISO control's requirement to agree audit scope and limit access to read-only copies or isolated environments directly supports the ASVS mandate that internal documentation and monitoring endpoints must not be exposed unless explicitly intended.
- V16.3.3partialaligns with — Requiring that all audit-related access be monitored and logged aligns with the ASVS requirement to log attempts to bypass security controls and any security events defined in documentation.
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialfinds — Requiring pre-verified, hardened devices and logging every access reduces the chance that sensitive data will be exposed to an untrusted endpoint or observer.
- CWE-284partialfinds — Requiring management approval and explicit scope limits for audit access stops unauthorized actors from obtaining privileges they should never receive.
- CWE-862partialfinds — Mandating read-only access or proxy execution by an authorized administrator ensures every requested operation is explicitly authorized before it occurs.
- CWE-1244nonemitigates — Audit testing protection may limit debug access during audits but does not cover the underlying weakness.
- CWE-400nonenone — Scheduling availability-impacting tests outside business hours and controlling special processing requests lowers the likelihood that audit activity will exhaust system resources.
- CWE-532nonenone — Requiring comprehensive logging of all audit access creates an auditable trail that makes it harder for sensitive information to be written into unprotected log files without detection.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.