SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.34Protection of information systems during audit testing

Plan and agree audit tests that touch live systems so the testing itself does not disrupt operations or compromise the systems being checked.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Internal audit report
The output of the internal reviews the company runs on its own security controls, with findings and improvement actions.
From the Sekit evidence catalog

In practice

Audit testing that touches live systems needs the same care as any other change to production: a defined scope agreed in advance, a qualified tester, and safeguards that keep the systems being tested available throughout. Auditors want to see penetration tests scoped deliberately rather than run against production with no isolation plan, and every finding tracked to closure or formal acceptance rather than left in a report nobody revisits. Automating evidence collection where possible reduces the risk that the audit activity itself becomes disruptive, since pulling data from system logs is safer than an auditor querying a live production database directly.

Common gaps

A penetration test was run against production with no documented scoping agreement, so the tester's access and test windows were never formally bounded.
Findings from the last internal audit report remain open with no owner assigned for remediation and no target date set when they were logged.
Evidence for the audit was collected by manually querying the production database rather than through the automated collection tooling already available.

Questions your auditor will ask

How do you make sure a penetration test doesn't disrupt production operations?
The technical environment is prepared with isolated targets where needed and safeguards that keep production available, and the test is scoped deliberately with a qualified tester before it starts.
Are audit findings tracked to resolution?
Every finding is tracked to closure or formal acceptance rather than left open, recorded in the internal audit report.
How is evidence collected for internal audits without disrupting live systems?
Audit evidence collection is automated where possible, pulling from system data instead of manual screenshots or direct queries against live systems.

Where regulation demands it

NIS2 art. 7.2 requires security assessments and testing of the organization's systems, and ENS org.4 requires a formal authorization process before such testing activity can start.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.34?”
Also via MCP, free with account