EvidenceSheet

ISO/IEC 27701:2019: the evidence behind every control

108 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

5.1General hard5.2.1Understanding the organization and its context moderate5.2.2Understanding the needs and expectations of interested parties hard5.2.3Determining the scope of the information security management system hard5.2.4Information security management system hard5.3.1Leadership and commitment hard5.3.2Policy hard5.3.3Organizational roles, responsibilities and authorities hard5.4.1Actions to address risks and opportunities moderate5.4.2Information security objectives and planning to achieve them moderate5.5.1Resources hard5.5.2Competence hard5.5.3Awareness hard5.5.4Communication hard5.5.5Documented information moderate5.6.1Operational planning and control moderate5.6.2Information security risk assessment hard5.6.3Information security risk treatment hard5.7.1Monitoring, measurement, analysis and evaluation hard5.7.2Internal audit hard5.7.3Management review hard5.8.1Nonconformity and corrective action hard5.8.2Continual improvement hard

PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

6.1General hard6.2.1Management direction for information security hard6.3.1Internal organization hard6.3.2Mobile devices and teleworking hard6.4.1Prior to employment hard6.4.2During employment hard6.4.3Termination and change of employment hard6.5.1Responsibility for assets hard6.5.2Information classification hard6.5.3Media handling hard6.6.1Business requirements of access control hard6.6.2User access management hard6.6.3User responsibilities hard6.6.4System and application access control easy6.7.1Cryptographic controls hard6.8.1Secure areas hard6.8.2Equipment hard6.9.1Operational procedures and responsibilities hard6.9.2Protection from malware hard6.9.3Backup hard6.9.4Logging and monitoring easy6.9.5Control of operational software hard6.9.6Technical vulnerability management hard6.9.7Information systems audit considerations hard6.10.1Network security management moderate6.10.2Information transfer hard6.11.1Security requirements of information systems hard6.11.2Security in development and support processes hard6.11.3Test data hard6.12.1Information security in supplier relationships hard6.12.2Supplier service delivery management hard6.13.1Management of information security incidents and improvements hard6.14.1Information security continuity hard6.14.2Redundancies hard6.15.1Compliance with legal and contractual requirements hard6.15.2Information security reviews hard

Additional ISO/IEC 27002 guidance for PII controllers, ISO 27701:2019

7.2.1Identify and document purpose hard7.2.2Identify lawful basis hard7.2.3Determine when and how consent is to be obtained hard7.2.4Obtain and record consent hard7.2.5Privacy impact assessment hard7.2.6Contracts with PII processors hard7.2.7Joint PII controller hard7.2.8Records related to processing PII hard7.3.1Determining and fulfilling obligations to PII principals moderate7.3.2Determining information for PII principals hard7.3.3Providing information to PII principals hard7.3.4Providing mechanism to modify or withdraw consent hard7.3.5Providing mechanism to object to PII processing hard7.3.6Access, correction and/or erasure hard7.3.7PII controllers' obligations to inform third parties hard7.3.8Providing copy of PII processed moderate7.3.9Handling requests hard7.3.10Automated decision making easy7.4.1Limit collection moderate7.4.2Limit processing hard7.4.3Accuracy and quality hard7.4.4PII minimization objectives hard7.4.5PII de-identification and deletion at the end of processing hard7.4.6Temporary files easy7.4.7Retention hard7.4.8Disposal hard7.4.9PII transmission controls moderate7.5.1Identify basis for PII transfer between jurisdictions hard7.5.2Countries and international organizations to which PII can be transferred hard7.5.3Records of transfer of PII moderate7.5.4Records of PII disclosure to third parties easy

Additional ISO/IEC 27002 guidance for PII processors, ISO 27701:2019

8.2.1Customer agreement hard8.2.2Organization’s purposes hard8.2.3Marketing and advertising use hard8.2.4Infringing instruction hard8.2.5Customer obligations hard8.2.6Records related to processing PII hard8.3.1Obligations to PII principals moderate8.4.1Temporary files hard8.4.2Return, transfer or disposal of PII hard8.4.3PII transmission controls hard8.5.1Basis for PII transfer between jurisdictions hard8.5.2Countries and international organizations to which PII can be transferred hard8.5.3Records of PII disclosure to third parties easy8.5.4Notification of PII disclosure requests hard8.5.5Legally binding PII disclosures hard8.5.6Disclosure of subcontractors used to process PII hard8.5.7Engagement of a subcontractor to process PII hard8.5.8Change of subcontractor to process PII hard