SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.35Independent review of information security

Have your security approach reviewed independently at planned intervals and after significant changes, so blind spots get caught by fresh eyes.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0008Risk assessment · ProcessrelatedRunning risk assessments on a regular cycle produces the input an independent reviewer checks against, though risk assessment itself is a separate activity from the review.RCF-0019Metrics & reporting · PolicysupportsDefining a small set of security indicators, what each measures and what triggers action, gives independent reviewers something concrete to check against.RCF-0020Metrics & reporting · ProcessrelatedReviewing agreed security indicators with leadership on schedule is management oversight, feeding the same risk picture an independent reviewer later examines. That routine reporting rhythm does not substitute for the independent review A.5.35 requires, so the link stays at related rather than supports.RCF-0022Internal audit · PolicysupportsA documented internal audit approach defining what gets checked, how often and by whom sets up this control's independence and cadence expectations, but a written approach alone does not perform the review itself.RCF-0023Internal audit · ProcesssupportsTracking every audit finding to closure with escalation for overdue items supports this control by closing the loop after a review, though the review itself must still be independent and at planned intervals.RCF-0031Control testing program · PolicysupportsDefining which controls get tested, how often and by whom turns independent review from an occasional exercise into a planned obligation.RCF-0032Control testing program · ProcesssupportsRecording what passed and failed in scheduled control tests, with tracked remediation, is the evidence base an independent review draws on.RCF-0382Audit readiness · PolicysupportsA commitment to continuous audit readiness, with defined scope and named response roles, makes this control's independent reviews easier to run without scrambling to prepare each time.RCF-0383Audit readiness · ProcesssupportsPeriodic internal spot-checks that confirm evidence is current keep the company ready for the independent review this control requires at any time.RCF-0384Audit readiness · TechnicalenablesA live dashboard of control status and evidence completeness gives independent reviewers visibility without a manual evidence hunt before each review.RCF-0398Executive briefings · ProcesssupportsLeadership security briefings that feed into budget and priority decisions are where the findings from this control's independent reviews change what the company does.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Internal audit report
The output of the internal reviews the company runs on its own security controls, with findings and improvement actions.
From the Sekit evidence catalog

In practice

Independent review only works if the reviewer has no stake in the outcome, which small companies often get wrong by having the same person who built the control also test it. A credible internal audit function defines what gets checked, how often, and gives the reviewer enough separation from daily operations to say a control failed. Findings need a closure date and an escalation path for overdue ones, otherwise the review becomes a document nobody revisits. Security metrics reported to leadership on a schedule, not only when something goes wrong, is what shows independent oversight is a standing practice rather than a reaction to a bad audit result.

Common gaps

The same person who configured the access controls also performs the internal review that is supposed to test them independently.
Internal audit findings are documented but sit open for over a year with no escalation when deadlines are missed.
Security metrics are compiled for a board meeting once a year instead of being reviewed on a regular schedule that could catch a trend early.

Questions your auditor will ask

Who performs the independent review, and are they separate from the team being reviewed?
Internal audit is performed by staff or an external party with no operational responsibility for the controls under review, documented in the audit approach.
What happens when an internal audit finding is not fixed on time?
Overdue findings escalate to leadership automatically past their agreed deadline, tracked in the same log used to record the original finding.
How often are security metrics reported to leadership?
Security indicators are produced and reviewed with leadership on a fixed schedule, with results feeding budget and priority decisions.

Where regulation demands it

NIS2 2.3 requires an independent review of information security, the exact requirement this control describes.
NIS2 7.3 requires regular review and update of security measures, matching this control's requirement for reviews at planned intervals.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.35?”
Also via MCP, free with account