Skip to content
arrow_back
search
Annex A 8.34 verified ISO/IEC 27001:2022

Protection of information systems during audits

Ensure audit activities are planned and agreed with management to prevent system disruptions.

record_voice_over

Plain language

This control is about making sure that when audits are conducted on your business's IT systems, they don't disrupt operations or expose sensitive information. It's important because unplanned audits can cause system crashes, data breaches, or loss of important information, which can seriously affect the business.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and management.
verified ISO/IEC 27001:2022 Annex A 8.34
priority_high

Why it matters

Unplanned audit testing on live systems can disrupt critical services, causing outages or data loss and harming business performance and reputation.

settings

Operational notes

Plan and agree audit tests for operational systems in advance with management; schedule like a change, define scope/window, obtain approvals and monitor for disruption.

Mapping detail

Mapping

Direction

Controls