A.8.34 Technological
Protection of information systems during audit testing
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-6mostlyaligns with — Both emphasize monitoring, logging, and review of all access performed for audit or testing purposes.
- CA-8mostlyaligns with — Both controls require explicit authorization, scope control, and safeguards when performing technical testing that could affect live systems.
- AC-3partialaligns with — Both enforce controlled, authorized access to systems and data, including restrictions to read-only where feasible.
- AC-6partialaligns with — Both limit privileges granted to auditors or testers to the minimum necessary to complete their tasks.
- CM-3partialaligns with — Both require management approval and controlled execution of changes or tests that could impact system configuration or availability.
- SI-2partialaligns with — Both address the need to schedule and isolate testing activities so they do not disrupt operational systems or introduce unapproved changes.
- AC-3covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- AC-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- CA-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SI-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (17)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-01mostlyaligns with — The control restricts and monitors all audit-related access to production systems, directly supporting the CSF outcome of protecting networks and environments from unauthorized logical access.
- PR.PS-04mostlyaligns with — By requiring monitoring and logging of every audit access and test activity, the control ensures log records are generated and available for continuous monitoring.
- DE.CM-09partialaligns with — Requiring that audit tests run outside business hours and that all access is logged supports continuous monitoring of computing environments to detect potentially adverse events.
- ID.RA-01partialaligns with — The control enables controlled, read-only or supervised access so that vulnerabilities and configuration issues can be identified and recorded without introducing new risks.
- PR.AA-05partialaligns with — The control enforces explicit management approval, scope limitation, and device-security verification before any elevated access is granted, aligning with policy-driven access authorization and review.
- DE.CM-09implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (8)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.2.4partialaligns with — The ISO guidance to identify and agree on external or special processing requests (such as audit tools) maps to the ASVS requirement that an allowlist defines the external resources or systems the application is permitted to communicate with.
- V13.4.2partialaligns with — Limiting audit tests to read-only access or isolated copies and deleting them afterward supports the ASVS requirement to disable debug modes in production to prevent exposure of debugging features.
- V13.4.5partialaligns with — The ISO control's requirement to agree audit scope and limit access to read-only copies or isolated environments directly supports the ASVS mandate that internal documentation and monitoring endpoints must not be exposed unless explicitly intended.
- V16.3.3partialaligns with — Requiring that all audit-related access be monitored and logged aligns with the ASVS requirement to log attempts to bypass security controls and any security events defined in documentation.
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1244nonemitigates — Audit testing protection may limit debug access during audits but does not cover the underlying weakness.
- CWE-200finds — Requiring pre-verified, hardened devices and logging every access reduces the chance that sensitive data will be exposed to an untrusted endpoint or observer.
- CWE-284finds — Requiring management approval and explicit scope limits for audit access stops unauthorized actors from obtaining privileges they should never receive.
- CWE-862finds — Mandating read-only access or proxy execution by an authorized administrator ensures every requested operation is explicitly authorized before it occurs.
Mitigated MITRE ATT&CK techniques (94)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003detects — A.8.34.h explicitly requires monitoring and logging of all access granted for audit and test purposes, which would surface the specific access patterns and tools (ntdsutil, Volume Shadow Copy, Invoke-NinjaCopy, etc.) used by an adversary performing T1003.003 under the guise of an audit or test.
- T1003.007detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access for audit and test purposes, which would surface the distinctive /proc filesystem reads (especially root-level or browser-context patterns) performed by this technique when it occurs during an audit/test window; this is only a slice of the technique's possible executions, not its dominant paths.
- T1003.008detects — A.8.34 point h) explicitly requires monitoring and logging all access for audit and test purposes, which would surface an adversary's read of /etc/passwd and /etc/shadow when performed under the guise of an audit/test activity; this is only a slice of the technique's possible executions (any non-audit read goes unmonitored by this control).
- T1007detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface the specific commands and tools (sc query, tasklist /svc, systemctl, schtasks, crontab -l) when they are executed as part of an authorized audit — but the control's scope is deliberately limited to audit/testing activity only, leaving all other (non-audit) instances of T1007 undetected.
- T1021.006detects — A.8.34.h explicitly requires monitoring and logging of all access granted for audit and test purposes, which would surface adversary use of valid accounts via WinRM when that use occurs in the context of an approved audit/test activity; this is a genuine but narrowly scoped slice of the technique (most adversary WinRM use is not audit-related).
- T1046detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface the use of port/vulnerability scanning tools brought in during an authorized audit (the dominant method named for T1046); this does not reach native Bonjour/mDNS queries, adversary-controlled scans outside an audit window, or scans that avoid triggering the audit-specific monitoring.
- T1047detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface legitimate WMI use by auditors but only incidentally surface adversary abuse of WMI when it occurs in the context of an approved audit/test activity; the control does not require general monitoring of WMI abuse outside that narrow slice.
- T1049detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which surfaces the execution of discovery commands (netstat, lsof, who, etc.) when they are performed under an authorized audit/test session, but does not require monitoring of the same commands when performed by an adversary outside any audit context.
- T1057detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes; this surfaces the specific legitimate use of process-enumeration commands (ps, tasklist, Get-Process, CreateToolhelp32Snapshot, show processes, etc.) when they are invoked inside an authorized audit/test session, which is a genuine but narrowly scoped slice of the broad T1057 technique that also occurs in non-audit adversarial contexts.
- T1059.008detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access granted for audit and test purposes, which surfaces CLI abuse performed under the cover of an authorized audit/test session on the network device.
- T1078detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which surfaces anomalous or unauthorized use of valid accounts during those activities (a slice of the technique).
- T1127.001detects — A.8.34 clause h) explicitly requires monitoring and logging of all access for audit and test purposes, which would surface anomalous or unauthorized use of MSBuild during an audit engagement; this is a genuine but minority slice of the technique's overall attack surface (most T1127.001 abuse occurs outside any audit context).
- T1216detects — A.8.34.h explicitly requires monitoring and logging of all access for audit and test purposes, which would surface use of trusted scripts (e.g. LOLBAS proxies) when performed as part of an audit/test activity, but the control is narrowly scoped to audit/testing contexts and does not address general/non-audit abuse of the technique.
- T1218.005detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface mshta.exe abuse when that abuse occurs inside an authorized audit/test window; this is a genuine but narrowly scoped slice of the technique (most real-world T1218.005 abuse is not performed under the cover of an approved audit).
- T1218.008detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface abuse of odbcconf.exe when that binary is invoked as part of an authorized audit/test activity; this does not cover non-audit abuse of the same signed binary.
- T1218.014detects — A.8.34 point h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface legitimate-but-abused MMC.exe invocations that match the technique's observable command-line and process patterns; this is only a slice of the full technique surface (adversary use outside any declared audit/test activity is unseen).
- T1486recovers — A.8.34 requires monitoring/logging of audit access plus isolated/test copies and off-hours execution that can limit blast radius or enable rollback of test-induced encryption, but does not restore data encrypted by a real T1486 adversary
- T1491.001detects — A.8.34 point h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which surfaces anomalous or unauthorized activity that could realize internal defacement during or immediately after an audit window.
- T1496.001detects — A.8.34 clause h) explicitly requires monitoring and logging of all access granted for audit and test purposes, which surfaces anomalous compute usage by authorized audit tooling or test processes that could be (or be mistaken for) hijacking, but the control's narrow audit-only scope leaves the dominant vectors (unauthorized malware, exposed APIs, container escapes) untouched.
- T1538detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access for audit and test purposes, which surfaces the use of a cloud dashboard (including by an adversary with stolen credentials) when that use occurs in an audit/testing context; this is a genuine but minority slice of T1538, which is not scoped to audit activity.
- T1546.007detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface anomalous or unauthorized netsh helper DLL registration/execution when that activity occurs as part of (or is mispresented as) an audit test.
- T1546.011detects — h) requires monitoring and logging of all access for audit and test purposes, which can surface anomalous shim-related activity (e.g. unexpected sdbinst.exe use or registry changes) during an audit but does not broadly instrument or detect the technique itself outside that scoped context
- T1547.012detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface anomalous or unauthorized activity (e.g. registry changes, AddPrintProcessor calls, spoolsv restarts) performed under the guise of an audit
- T1552.006detects — A.8.34 h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface the reconnaissance commands (dir /s *.xml on SYSVOL, execution of gpp tools) when they are performed as part of an authorized audit/test — but the control is silent on unauthorized adversary use of the same techniques outside any audit context.
- T1555.004detects — A.8.34 clause h) explicitly requires monitoring and logging of all access granted for audit and test purposes, which would surface anomalous or unauthorized use of mechanisms such as vaultcmd.exe, CredEnumerateA, or direct file reads against Credential Manager during an audit window; this is only a slice of the technique's full attack surface (most T1555.004 activity is unrelated to any audit/test context), so the detection is genuine but limited.
- T1563.002detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface anomalous or unauthorized RDP hijacking attempts conducted under the guise of an audit/test activity.
- T1578detects — A.8.34 clause h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface the use of audit-driven access that an adversary could abuse to perform T1578 modifications.
- T1578.003detects — A.8.34 item h explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface the adversary's access that precedes (and enables) the delete-cloud-instance action on IaaS; this is genuine detection of a slice of the technique but does not address the deletion act itself or instances outside the audit/test context.
- T1578.004detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access for audit and test purposes, which would surface the use of cloud management dashboard or APIs to perform a revert/snapshot restore during an authorized test window
- T1602.001detects — A.8.34 clause h) explicitly requires monitoring and logging of all access for audit and test purposes, which would surface SNMP queries performed as part of an authorized audit/test (the only form of access the control governs), but the control is silent on unauthorized adversary SNMP queries outside any audit context.
- T1602.002detects — A.8.34 item h explicitly requires monitoring and logging of all access granted for audit and test purposes, which would surface the use of management tools/protocols (SNMP/SMI) when those are exercised as part of an authorized audit, but the control is silent on unauthorized adversary access outside any audit process.
- T1613detects — A.8.34 clause (h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface T1613 discovery activity when it is performed as part of (or under the guise of) an audit/test engagement; this is only a slice of the technique's possible executions, not its dominant form.
- T1654detects — A.8.34 point h) explicitly requires monitoring and logging of all access performed for audit and test purposes, which would surface T1654 when the enumeration uses an audit/test context or approved access path; this is only a slice of the technique (most T1654 occurs outside any declared audit activity), so partial per the A.8.16 vs T1055 event-lane precedent.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.