{"description":"Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.","edges":[{"id":"e-assess-organizational-controls-approve-annex-a-conclusion","source":"assess-organizational-controls","target":"approve-annex-a-conclusion"},{"id":"e-assess-people-controls-approve-annex-a-conclusion","source":"assess-people-controls","target":"approve-annex-a-conclusion"},{"id":"e-assess-physical-controls-approve-annex-a-conclusion","source":"assess-physical-controls","target":"approve-annex-a-conclusion"},{"id":"e-assess-technological-controls-approve-annex-a-conclusion","source":"assess-technological-controls","target":"approve-annex-a-conclusion"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"approvalAssignment":"Before execution, map declared roles to named tenant approvers, verify native counts after assignment, and verify reviewer independence. The library declares roles and counts; it does not automatically assign people or enforce role separation.","capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{"UC-ACCESS-02":"tests","UC-ACCESS-03":"tests","UC-ACCESS-04":"tests","UC-ACCESS-05":"tests","UC-ACCESS-06":"tests","UC-ACCESS-08":"tests","UC-ACCESS-09":"tests","UC-ACCESS-18":"tests","UC-ASSET-01":"tests","UC-ASSET-03":"tests","UC-ASSET-04":"tests","UC-ASSET-06":"tests","UC-ASSET-07":"tests","UC-ASSET-08":"tests","UC-AUDIT-23":"tests","UC-AUDIT-24":"tests","UC-AUDIT-25":"tests","UC-BCDR-01":"tests","UC-BCDR-03":"tests","UC-BCDR-04":"tests","UC-CONFIG-01":"tests","UC-CONFIG-02":"tests","UC-CONFIG-03":"tests","UC-CONFIG-05":"tests","UC-CRYPTO-02":"tests","UC-DATA-09":"tests","UC-DATA-11":"tests","UC-DATA-12":"tests","UC-DATA-13":"tests","UC-GOV-03":"tests","UC-GOV-06":"tests","UC-GOV-07":"tests","UC-GOV-08":"tests","UC-GOV-14":"tests","UC-GOV-22":"tests","UC-GOV-23":"tests","UC-HR-01":"tests","UC-HR-02":"tests","UC-HR-03":"tests","UC-HR-04":"tests","UC-HR-05":"tests","UC-HR-07":"tests","UC-IR-01":"tests","UC-IR-03":"tests","UC-IR-04":"tests","UC-IR-06":"tests","UC-IR-07":"tests","UC-IR-10":"tests","UC-LOG-01":"tests","UC-LOG-02":"tests","UC-LOG-04":"tests","UC-LOG-08":"tests","UC-NET-01":"tests","UC-NET-13":"tests","UC-PHYS-01":"tests","UC-PHYS-02":"tests","UC-PHYS-03":"tests","UC-PHYS-04":"tests","UC-PHYS-05":"tests","UC-PHYS-06":"tests","UC-PHYS-08":"tests","UC-PHYS-09":"tests","UC-RISK-02":"tests","UC-RISK-17":"tests","UC-SDLC-01":"tests","UC-SDLC-03":"tests","UC-SDLC-04":"tests","UC-SDLC-05":"tests","UC-SDLC-10":"tests","UC-SDLC-14":"tests","UC-TPRM-01":"tests","UC-TPRM-04":"tests","UC-TPRM-07":"tests","UC-TPRM-08":"tests","UC-TRAIN-01":"tests","UC-VULN-03":"tests","UC-VULN-04":"tests","UC-VULN-05":"tests"},"controls":["UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-04","UC-ACCESS-05","UC-ACCESS-06","UC-ACCESS-08","UC-ACCESS-09","UC-ACCESS-18","UC-ASSET-01","UC-ASSET-03","UC-ASSET-04","UC-ASSET-06","UC-ASSET-07","UC-ASSET-08","UC-AUDIT-23","UC-AUDIT-24","UC-AUDIT-25","UC-BCDR-01","UC-BCDR-03","UC-BCDR-04","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-03","UC-CONFIG-05","UC-CRYPTO-02","UC-DATA-09","UC-DATA-11","UC-DATA-12","UC-DATA-13","UC-GOV-03","UC-GOV-06","UC-GOV-07","UC-GOV-08","UC-GOV-14","UC-GOV-22","UC-GOV-23","UC-HR-01","UC-HR-02","UC-HR-03","UC-HR-04","UC-HR-05","UC-HR-07","UC-IR-01","UC-IR-03","UC-IR-04","UC-IR-06","UC-IR-07","UC-IR-10","UC-LOG-01","UC-LOG-02","UC-LOG-04","UC-LOG-08","UC-NET-01","UC-NET-13","UC-PHYS-01","UC-PHYS-02","UC-PHYS-03","UC-PHYS-04","UC-PHYS-05","UC-PHYS-06","UC-PHYS-08","UC-PHYS-09","UC-RISK-02","UC-RISK-17","UC-SDLC-01","UC-SDLC-03","UC-SDLC-04","UC-SDLC-05","UC-SDLC-10","UC-SDLC-14","UC-TPRM-01","UC-TPRM-04","UC-TPRM-07","UC-TPRM-08","UC-TRAIN-01","UC-VULN-03","UC-VULN-04","UC-VULN-05"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","contentDigest":"sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Markdown per-control workpapers, applicability and exclusions, evidence references, findings and independent conclusions.","id":"step-results"},{"description":"Restricted source evidence, four theme workpapers, reliance mapping, Annex A report and finding register.","id":"step-documents"},{"description":"Named specialist approvals followed by a different independent lead assessor’s native approval of the four theme conclusions and report; tenant assignments must be verified before execution.","id":"native-approvals"},{"description":"Existing Audit anchor, linked Issues/Controls and linked Remediation actions using the verified tenant schema.","id":"audit-issue-control-links"}],"handoffs":[{"direction":"input","name":"Approved Statement of Applicability, risk treatment plan, scope, review period, responsible roles, resource-reference index and prior Stage 1 findings where applicable."},{"direction":"output","name":"Reviewed Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners.","roleId":"independent-lead-assessor"}],"roles":[{"contribution":"expertise","description":"Organizational controls assessor: qualified assessor independent of control operation; contributes expertise on governance, asset/access lifecycle, suppliers, incidents, continuity and legal/assurance obligations. Assign and verify the named person as the native approver for this node before execution.","id":"organizational-controls-assessor","nodeIds":["assess-organizational-controls"]},{"contribution":"expertise","description":"People controls assessor: qualified assessor independent of control operation; contributes expertise on personnel lifecycle, training, remote working and event reporting. Assign and verify the named person as the native approver for this node before execution.","id":"people-controls-assessor","nodeIds":["assess-people-controls"]},{"contribution":"expertise","description":"Physical controls assessor: qualified assessor independent of control operation; contributes expertise on direct premises and workspace controls, equipment lifecycle and provider attestation reliance. Assign and verify the named person as the native approver for this node before execution.","id":"physical-controls-assessor","nodeIds":["assess-physical-controls"]},{"contribution":"expertise","description":"Technology controls assessor: qualified assessor independent of control operation; contributes expertise on endpoint/access safeguards, operations, networks, cryptography and secure development. Assign and verify the named person as the native approver for this node before execution.","id":"technological-controls-assessor","nodeIds":["assess-technological-controls"]},{"contribution":"approval","description":"Independent lead assessor: must differ from all specialist assessors and control owners and must not prepare any of the assessments. Review and sign all four theme conclusions and the Annex A report. Assign and verify the named person as this node’s native approver before execution; portable role metadata does not enforce assignment or independence.","id":"independent-lead-assessor","nodeIds":["approve-annex-a-conclusion"]}],"status":"declared","systems":[{"capabilities":["read-approved-statement-of-applicability","read-risk-treatment-plan","read-restricted-control-evidence","read-provider-attestations"],"id":"isms-evidence-sources"}]},"provenance":[{"source":"workflow-library","sourceTemplateId":"workflow-library:audit-iso27001-stage2-organizational-controls","url":"https://workflow-library.com/releases/audit-iso27001-stage2-organizational-controls/d9bfcae7b763554db003503355933f0bb4230c306af0ff51e91c08186b29ebfa.json"},{"source":"workflow-library","sourceTemplateId":"workflow-library:audit-iso27001-stage2-people-controls","url":"https://workflow-library.com/releases/audit-iso27001-stage2-people-controls/68593bc4f5dbf04691c3b3ec5d1d40bc424ea1a980d353c2cdfa02e827d56fc9.json"},{"source":"workflow-library","sourceTemplateId":"workflow-library:audit-iso27001-stage2-physical-controls","url":"https://workflow-library.com/releases/audit-iso27001-stage2-physical-controls/9f801cdb45fa0cd757ec7f92cad65ae78c64a134f62c0b5dc5668d99c13bd634.json"},{"source":"workflow-library","sourceTemplateId":"workflow-library:audit-iso27001-stage2-technological-controls","url":"https://workflow-library.com/releases/audit-iso27001-stage2-technological-controls/883bed4a131f6eec6b2a7f84e82ae6277b2364533e92f3e73b85cc5912ccd437.json"}],"releaseId":"sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-iso27001-stage2-controls-audit","supersedes":["workflow-library:audit-iso27001-stage2-organizational-controls","workflow-library:audit-iso27001-stage2-people-controls","workflow-library:audit-iso27001-stage2-physical-controls","workflow-library:audit-iso27001-stage2-technological-controls"]},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.","slug":"audit-iso27001-stage2-controls-audit","source":"coworkcanvas-gallery","standards":["iso-27001"],"teams":["internal-audit"]},"name":"ISO 27001 Stage 2 Annex A Controls Audit","nodes":[{"data":{"controls":["UC-GOV-03","UC-GOV-22","UC-DATA-13","UC-AUDIT-23","UC-AUDIT-24","UC-AUDIT-25","UC-GOV-06","UC-GOV-07","UC-GOV-08","UC-GOV-14","UC-GOV-23","UC-RISK-02","UC-RISK-17","UC-ASSET-01","UC-ASSET-03","UC-ASSET-06","UC-ASSET-07","UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-06","UC-ACCESS-08","UC-ASSET-08","UC-HR-05","UC-TPRM-01","UC-TPRM-04","UC-TPRM-07","UC-TPRM-08","UC-IR-01","UC-IR-04","UC-IR-06","UC-IR-07","UC-IR-10","UC-BCDR-01"],"description":"Organizational controls assessor applies specialist judgment to governance, asset/access lifecycle, suppliers, incidents, continuity and legal/assurance obligations and approves the evidence-supported A.5 assessment for independent review.","instructions":"**Objective**\nOrganizational controls assessor applies specialist judgment to governance, asset/access lifecycle, suppliers, incidents, continuity and legal/assurance obligations and approves the evidence-supported A.5 assessment for independent review.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\n\n\n- The linked consolidated controls implementing this group, with their operating evidence in AssureSwarm\n- The policy register with approval, communication, and review records\n- Role definitions, the segregation-of-duties matrix, and the compensating controls documented for a small team\n- Threat intelligence feeds and their analysis records; a recent project with its security involvement trail\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The asset inventory with owners; the classification scheme and its application to data stores\n- the workforce identity and collaboration platform, cloud identity and access management, and the source-control platform access exports with the joiner-mover-leaver record\n- Authenticator handling rules: password standards, MFA enrollment, and secrets storage practice\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The vendor register with tiering, agreements, and assessment records\n- Supplier attestations (SOC 2 / ISO certificates) and the reliance mapping\n- Transfer rules and agreements covering data moving to processors and external parties\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The incident response plan with roles, severity criteria, and communication paths\n- The event and incident log for the recent period, with postmortems\n- Business continuity and disaster recovery plans with the latest test results\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The legal and contractual obligations register with owners and review dates\n- License and IP records for the codebase; the records retention schedule\n- Independent review artifacts: internal audit reports, external assessments, and the compliance-check records against policies\n\n- Approved Statement of Applicability, risk treatment plan, prior Stage 1 findings where applicable, and the existing Audit item’s scope and review period. Stage 1 and readiness work remain separate.\n- Before execution, assign and verify the named qualified organizational controls assessor as this step’s native approver. The assessor must be independent of the controls assessed. Verify a different independent lead assessor is assigned to approve-annex-a-conclusion; that reviewer must not prepare or approve any of the four specialist assessments. Imported role declarations do not assign people or enforce independence. Verify the native approval count after assignment.\n\n**Procedure**\n*Agent retrieval, testing preparation and filing absorb the complete procedures from “ISO 27001 Stage 2 Organizational Controls Audit” (step-5); the organizational controls assessor contributes expertise here. The independent lead assessor reviews and signs all four theme conclusions together at approve-annex-a-conclusion.*\n\n1. Assessment scope for Audit Governance, Policy & Organizational Roles: Assess implementation of the organizational governance controls: policies for information security defined, approved, communicated, and reviewed (A.5.1) with documented operating procedures (A.5.37); roles and responsibilities allocated (A.5.2); conflicting duties segregated (A.5.3); management requiring security per policy (A.5.4); contact with authorities (A.5.5) and special interest groups (A.5.6) maintained; threat intelligence collected and analyzed (A.5.7); and information security integrated into project management (A.5.8).\n\n2. Sample policies for the A.5.1 lifecycle - approved by management, published to the right audience, acknowledged, and reviewed at planned intervals - and confirm A.5.37 operating procedures exist where the policy promises them.\n3. Test A.5.2 and A.5.4 by walking two security responsibilities from role definition to an actual performed duty recorded in a process run.\n4. Probe A.5.3 where headcount is thin: verify the documented segregations and compensations operate - reviewer independence in the source-control platform, the immutable audit trail, and the documented separation of any assurance and management services.\n5. Verify A.5.5 and A.5.6 contact routes are current and exercised, not just listed.\n6. Inspect A.5.7 threat intelligence outputs feeding decisions, and A.5.8 security checkpoints inside a sampled project.\n\n7. Assessment scope for Audit Asset, Classification & Access Management: Assess implementation of the asset and access management controls: the inventory of information and associated assets (A.5.9), acceptable use rules (A.5.10), return of assets on exit (A.5.11), classification (A.5.12) and labelling (A.5.13) of information, access control rules (A.5.15), identity management across the lifecycle (A.5.16), authentication information handling (A.5.17), and provisioning, review, and revocation of access rights (A.5.18).\n\n8. Test A.5.9 inventory completeness by reverse-tracing: pick two production assets from the cloud provider estate and confirm each appears with an owner; pick two inventory rows and confirm they still exist.\n9. Verify A.5.10 acceptable-use communication and A.5.11 return-of-assets execution for a sampled leaver, including endpoint recovery and account revocation timing.\n10. Check A.5.12 and A.5.13 by inspecting classified data stores - PII fields carry their classification and the promised handling (masking, restricted export) is configured.\n11. Test A.5.15, A.5.16, and A.5.18 as one lifecycle: sampled joiners got least-privilege access through the documented flow, a periodic review happened with remediations, and leavers lost access within the committed window.\n12. Verify A.5.17 authentication handling: enrollment, reset, and storage of authenticators match the documented rules, MFA enforced for the sampled population.\n\n13. Assessment scope for Audit Supplier, Cloud & Information Transfer Security: Assess implementation of the supplier and transfer controls: information transfer rules and agreements (A.5.14), information security in supplier relationships (A.5.19), security requirements within supplier agreements (A.5.20), management of the ICT supply chain (A.5.21), monitoring, review, and change management of supplier services (A.5.22), and information security for use of cloud services (A.5.23). For a platform built on the cloud provider with the workforce identity and collaboration platform and the source-control platform as principal suppliers, this group is where the ISMS's external boundary is proven.\n\n14. Verify A.5.14 transfer rules cover the real flows - customer data into the platform, exports out, and data shared with processors - with agreements in place for each external counterpart.\n15. Test A.5.19 and A.5.20 by sampling two active suppliers: risk assessment on file, security clauses present in the agreement, and obligations mapped to who verifies them.\n16. Assess A.5.21 supply chain depth: component provenance and the attestation chain behind the platform's critical dependencies.\n17. Test A.5.22 monitoring: review records for supplier service changes and attestation renewals across the period, with actions where reports raised exceptions.\n18. Verify A.5.23 cloud-use governance: the documented rules for adopting and configuring cloud services, applied to one recently adopted or changed service.\n\n19. Assessment scope for Audit Incident Management & Continuity Readiness: Assess implementation of the incident and continuity controls: incident management planning and preparation (A.5.24), assessment and decision on security events (A.5.25), response to incidents (A.5.26), learning from incidents (A.5.27), collection of evidence (A.5.28), information security during disruption (A.5.29), and ICT readiness for business continuity (A.5.30).\n\n20. Verify A.5.24 preparation: the plan assigns roles and severities, responders can be shown to know it, and the reporting channel from the workforce works.\n21. Test A.5.25 and A.5.26 by sampling events from the log: each assessed against the criteria, decisions recorded, and declared incidents contained per the plan with timestamps that hold up.\n22. Check A.5.27 learning: postmortems produced actions that landed in the corrective-action machinery and demonstrably closed.\n23. Assess A.5.28 evidence handling in one sampled incident - identification, collection, and preservation adequate for disciplinary or legal use.\n24. Verify A.5.29 and A.5.30 continuity: security requirements hold during disruption scenarios, and the ICT readiness test on the cloud provider estate - restore, failover, or region exercise - met its objectives with gaps fed back into the plan.\n\n25. Assessment scope for Audit Legal, Records & Independent Review: Assess implementation of the legal and assurance controls closing the organizational theme: identification of legal, statutory, regulatory, and contractual requirements (A.5.31), intellectual property rights (A.5.32), protection of records (A.5.33), privacy and protection of PII (A.5.34), independent review of information security (A.5.35), and compliance with policies, rules, and standards (A.5.36) - then consolidate the A.5 theme conclusion.\n\n26. Verify A.5.31: the obligations register is current, each item names an owner, and changes in obligations traceably updated controls or policies.\n27. Test A.5.32 by checking license compliance for the shipped software components and the handling of third-party IP in the repository.\n28. Assess A.5.33 records protection: retention schedule applied, records protected against loss and unauthorized change, and disposal executed on schedule.\n29. Verify A.5.34 PII protection against the privacy commitments: lawful basis records, data subject request handling, and the technical safeguards on PII stores.\n30. Check A.5.35 and A.5.36: independent reviews happened at planned intervals with findings tracked to closure, compliance checks against the policy set are performed, and consolidate all A.5 assessment results into the theme conclusion, preparing the theme conclusion for independent lead-assessor sign-off at the final checkpoint.\n\n31. Apply these procedures to each applicable A.5 control in the approved Statement of Applicability. For every excluded control, retain its identifier, rationale, authorization and risk-treatment reference in the theme workpaper. Missing evidence remains a gap; an exclusion or provider inheritance never implies that a control operated. Treat the declared-control exit criteria below as applying to the approved scope, with exclusions reconciled separately.\n32. The organizational controls assessor challenges sample coverage, evidence sufficiency, control operation and nonconformity classification using their specialist knowledge. Record unresolved matters and evidence limits in the theme workpaper. Submit the exact workpaper version for the assessor’s native approval; send that approved version to the final checkpoint for independent lead-assessor sign-off.\n\n**Record in AssureSwarm**\nRecord per-control conformity conclusions with sampled evidence referenced. Nonconformities are raised on the existing audit engagement with the Annex id and classification.\n\nRecord per-control conclusions with the reverse-trace and lifecycle samples attached. Access-lifecycle exceptions cite the specific account and date.\n\nRecord per-control conclusions with sampled supplier files referenced. Gaps between contractual promises and observed monitoring are cited by supplier and clause.\n\nRecord per-control conclusions with sampled incidents and the continuity test cited. Response-time or preservation failures cite the specific event.\n\nRecord per-control conclusions and attach the consolidated A.5 theme summary with the finding register. The assessor approves the theme workpaper in the native approval record; the independent lead assessor signs the theme conclusion with date and capacity at the final checkpoint.\n\n- Step result: markdown assessment with each A.5 control’s applicability, tests, sample identifiers, evidence references, conclusion, exclusion or reliance rationale, and classified findings with owners.\n- Step documents: restricted evidence files, the A.5 theme workpaper and finding register; preserve personnel identifiers and access restrictions.\n- Item create/relationship: after verifying the tenant schema, raise each finding as an Issue with issue_type, source, severity and issue_owner, linked to the existing Audit and affected Control items. Preserve corrective actions as linked Remediation items with plan, action_owner and target_date when those fields exist; retain the action plan, owners and target dates in the workpaper until durable records are verified.\n- Native approval: the named specialist assessor’s dated approval of the exact theme workpaper version. The final checkpoint retains independent lead-assessor sign-off.\n\n**Exit criteria**\nAll nine declared controls carry a conformity conclusion supported by sampled evidence, and any nonconformity is classified with a named owner. All nine declared controls carry a conformity conclusion supported by sampled evidence, and access exceptions are classified with owners. All six declared controls carry a conformity conclusion supported by sampled evidence, and supplier-side gaps are classified with owners. All seven declared controls carry a conformity conclusion supported by sampled evidence, and incident or continuity gaps are classified with owners. All six declared controls carry a conformity conclusion, the A.5 theme summary is attached with every nonconformity classified and owned, and the assessor’s native approval is recorded; independent lead-assessor sign-off is required at the final checkpoint.\nThe specialist’s expertise review resolves or explicitly qualifies evidence and classification questions; each applicable control has a traceable conclusion, each exclusion has a documented basis, and the approved theme workpaper is ready for independent review. No executor form is required.","kind":"task","label":"Assess organizational controls (A.5)","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]},"requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Organizational controls assessor","ermPhase":"assess","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"assess-organizational-controls"},{"data":{"controls":["UC-HR-07","UC-IR-03","UC-TRAIN-01","UC-HR-01","UC-HR-02","UC-HR-03","UC-HR-04"],"description":"People controls assessor applies specialist judgment to personnel lifecycle, training, remote working and event reporting and approves the evidence-supported A.6 assessment for independent review.","instructions":"**Objective**\nPeople controls assessor applies specialist judgment to personnel lifecycle, training, remote working and event reporting and approves the evidence-supported A.6 assessment for independent review.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\n\n\n- The linked consolidated controls and their operating evidence in AssureSwarm\n- The joiner and leaver population for the assessment window with role-risk designations\n- Employment agreement templates and the executed agreements for sampled personnel, including contractors\n- Disciplinary procedure and any enforcement records; the NDA register\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- Training assignments and completion records for the assessment window, including role-based content for privileged staff\n- The remote working provisions and the technical posture they promise: device requirements, screen-lock, and network rules for personnel working remotely where applicable\n- The event-reporting channel definition and the reported-event log\n\n- Approved Statement of Applicability, risk treatment plan, prior Stage 1 findings where applicable, and the existing Audit item’s scope and review period. Stage 1 and readiness work remain separate.\n- Before execution, assign and verify the named qualified people controls assessor as this step’s native approver. The assessor must be independent of the controls assessed. Verify a different independent lead assessor is assigned to approve-annex-a-conclusion; that reviewer must not prepare or approve any of the four specialist assessments. Imported role declarations do not assign people or enforce independence. Verify the native approval count after assignment.\n\n**Procedure**\n*Agent retrieval, testing preparation and filing absorb the complete procedures from “ISO 27001 Stage 2 People Controls Audit” (step-2); the people controls assessor contributes expertise here. The independent lead assessor reviews and signs all four theme conclusions together at approve-annex-a-conclusion.*\n\n1. Assessment scope for Audit Employment Lifecycle Security: Assess implementation of the employment lifecycle controls: background verification proportional to role risk (A.6.1), security responsibilities embedded in terms and conditions of employment (A.6.2), a disciplinary process for violations (A.6.4), responsibilities that survive termination or change of employment (A.6.5), and confidentiality or non-disclosure agreements signed and retained (A.6.6).\n\n2. Sample joiners across employee and contractor populations and verify A.6.1 screening was completed before access grant, at the depth the role's risk designation requires.\n3. Inspect A.6.2 terms for the same sample: security responsibilities, acceptable-use commitments, and consequences stated in the signed agreement.\n4. Verify A.6.4 by inspecting the disciplinary procedure and, where any violation occurred in the window, the record of proportionate handling; where none occurred, test workforce awareness that the procedure exists.\n5. Test A.6.5 for sampled leavers and role-changers: post-employment duties communicated at exit, and continuing obligations documented.\n6. Check A.6.6 coverage: NDAs executed for everyone with access to confidential information - including third-party personnel - retained and current.\n\n7. Assessment scope for Audit Awareness, Remote Work & Event Reporting: Assess implementation of the workforce operating controls: information security awareness, education, and training delivered and refreshed (A.6.3), remote working protected by policy and technical measures (A.6.7), and a channel through which personnel report observed or suspected security events (A.6.8) - then consolidate the A.6 theme conclusion.\n\n8. Test A.6.3 by sampling the workforce for completed awareness training in the window, verifying content covers the policy set and the follow-up that chased any miss to completion.\n9. Verify role-based depth: personnel holding the cloud provider or the source-control platform privileged access received training proportionate to that access.\n10. Assess A.6.7 in practice for personnel working remotely where applicable: sampled endpoints meet the documented baseline, and the promised safeguards - disk encryption, screen lock, MFA on remote access - are verifiably enforced rather than requested.\n11. Test A.6.8 end to end: a workforce member can name the reporting channel, sampled reports reached triage within the committed time, and the reporter received feedback.\n12. Consolidate the A.6 assessment results across both people assessments into the theme conclusion and prepare the theme conclusion for independent lead-assessor sign-off at the final checkpoint.\n\n13. Apply these procedures to each applicable A.6 control in the approved Statement of Applicability. For every excluded control, retain its identifier, rationale, authorization and risk-treatment reference in the theme workpaper. Missing evidence remains a gap; an exclusion or provider inheritance never implies that a control operated. Treat the declared-control exit criteria below as applying to the approved scope, with exclusions reconciled separately.\n14. The people controls assessor challenges sample coverage, evidence sufficiency, control operation and nonconformity classification using their specialist knowledge. Record unresolved matters and evidence limits in the theme workpaper. Submit the exact workpaper version for the assessor’s native approval; send that approved version to the final checkpoint for independent lead-assessor sign-off.\n\n**Record in AssureSwarm**\nRecord per-control conclusions with the sampled personnel files referenced by identifier, not name, in the workpapers. Exceptions cite the specific lifecycle event.\n\nRecord per-control conclusions, attach the consolidated A.6 theme summary with its finding register, and capture the assessor’s native approval with date and capacity, with independent lead-assessor sign-off on the theme conclusion at the final checkpoint.\n\n- Step result: markdown assessment with each A.6 control’s applicability, tests, sample identifiers, evidence references, conclusion, exclusion or reliance rationale, and classified findings with owners.\n- Step documents: restricted evidence files, the A.6 theme workpaper and finding register; preserve personnel identifiers and access restrictions.\n- Item create/relationship: after verifying the tenant schema, raise each finding as an Issue with issue_type, source, severity and issue_owner, linked to the existing Audit and affected Control items. Preserve corrective actions as linked Remediation items with plan, action_owner and target_date when those fields exist; retain the action plan, owners and target dates in the workpaper until durable records are verified.\n- Native approval: the named specialist assessor’s dated approval of the exact theme workpaper version. The final checkpoint retains independent lead-assessor sign-off.\n\n**Exit criteria**\nAll five declared controls carry a conformity conclusion supported by lifecycle samples, and exceptions are classified with owners. All three declared controls carry a conformity conclusion supported by sampled evidence, the A.6 theme summary is attached with nonconformities owned, and the assessor’s native approval is recorded; independent lead-assessor sign-off is required at the final checkpoint.\nThe specialist’s expertise review resolves or explicitly qualifies evidence and classification questions; each applicable control has a traceable conclusion, each exclusion has a documented basis, and the approved theme workpaper is ready for independent review. No executor form is required.","kind":"task","label":"Assess people controls (A.6)","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]},"requiredApprovals":1,"roleIntegrity":{"decisionOwner":"People controls assessor","ermPhase":"assess","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"assess-people-controls"},{"data":{"controls":["UC-ASSET-04","UC-PHYS-05","UC-PHYS-06","UC-PHYS-08","UC-PHYS-01","UC-PHYS-02","UC-ASSET-06","UC-PHYS-03","UC-PHYS-04","UC-PHYS-09"],"description":"Physical controls assessor applies specialist judgment to direct premises and workspace controls, equipment lifecycle and provider attestation reliance and approves the evidence-supported A.7 assessment for independent review.","instructions":"**Objective**\nPhysical controls assessor applies specialist judgment to direct premises and workspace controls, equipment lifecycle and provider attestation reliance and approves the evidence-supported A.7 assessment for independent review.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\n\n\n- The linked consolidated controls and their operating evidence in AssureSwarm\n- The cloud provider attestation set covering data-center perimeter, entry, and monitoring controls, with the reliance mapping\n- The inventory of directly controlled spaces: any office or storage location holding equipment or records\n- Entry and visitor records for directly controlled spaces in the window\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The remote working and clear desk provisions with their acknowledgment records\n- the cloud provider attestation coverage for environmental threat protection at the data-center layer\n- Endpoint posture evidence: screen-lock enforcement, disk encryption, and device-management state for sampled devices\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The media handling rules and the asset inventory's device and media records\n- the cloud provider attestation coverage for utilities, cabling, and media destruction at the data-center layer\n- Endpoint lifecycle records: issuance, maintenance, and disposal or return events in the window\n\n- Approved Statement of Applicability, risk treatment plan, prior Stage 1 findings where applicable, and the existing Audit item’s scope and review period. Stage 1 and readiness work remain separate.\n- Before execution, assign and verify the named qualified physical controls assessor as this step’s native approver. The assessor must be independent of the controls assessed. Verify a different independent lead assessor is assigned to approve-annex-a-conclusion; that reviewer must not prepare or approve any of the four specialist assessments. Imported role declarations do not assign people or enforce independence. Verify the native approval count after assignment.\n\n**Procedure**\n*Agent retrieval, testing preparation and filing absorb the complete procedures from “ISO 27001 Stage 2 Physical Controls Audit” (step-3); the physical controls assessor contributes expertise here. The independent lead assessor reviews and signs all four theme conclusions together at approve-annex-a-conclusion.*\n\n1. Assessment scope for Audit Perimeters, Entry & Secure Areas: Assess implementation of the perimeter and entry controls: physical security perimeters defined and used (A.7.1), physical entry controlled (A.7.2), offices, rooms, and facilities secured (A.7.3), physical security monitoring in place (A.7.4), and rules for working in secure areas (A.7.6). Define which physical controls are directly operated and which are inherited from service providers. Assess the inherited controls through the approved reliance method and assess directly operated spaces where workforce or records exposure exists.\n\n2. Verify the A.7.1 perimeter analysis identifies every location where in-scope information or equipment exists, and that locations delegated to the cloud provider are covered by current attestations mapped control-for-control.\n3. For directly controlled spaces, test A.7.2 and A.7.3: entry restricted to authorized persons, visitor handling recorded, and securing measures appropriate to what the space holds.\n4. Inspect A.7.4 monitoring for those spaces - alarms or surveillance proportional to risk, with records retained and reviewed.\n5. Verify A.7.6 rules exist for any secure-area work and are known to the personnel who would perform it.\n6. Where a control is fully inherited, record the reliance conclusion explicitly with the attestation reference; record the scope and evidence supporting that conclusion.\n\n7. Assessment scope for Audit Environmental Protection & Workspace Hygiene: Assess implementation of the environmental and workspace controls: protection against physical and environmental threats (A.7.5), clear desk and clear screen rules (A.7.7), equipment siting and protection (A.7.8), and security of assets off-premises (A.7.9). Cover every in-scope workspace, including remote locations where applicable. Evaluate A.7.5 and A.7.8 across the direct and inherited responsibilities recorded in the scope.\n\n8. Verify A.7.5 for directly controlled spaces (fire, water, and power exposure appropriate to what they hold) and confirm the data-center layer's environmental protections through the mapped attestations.\n9. Test A.7.7 through technical enforcement rather than assertion: screen-lock timeouts pushed to managed endpoints, and print or physical-output handling rules for anyone processing customer data on paper - expected to be rare and said so.\n10. Assess A.7.8 guidance for home offices: equipment positioned against shoulder-surfing and environmental damage, and the guidance actually communicated.\n11. Test A.7.9 off-premises rules across the sampled fleet: devices tracked in the asset inventory, encrypted, remotely lockable, and covered by loss-reporting duties the workforce can restate.\n12. Reconcile any workspace exception against the acceptable-use and remote-working acknowledgments to determine whether it is an individual lapse or a control gap.\n\n13. Assessment scope for Audit Media, Utilities & Equipment Lifecycle: Assess implementation of the media and equipment controls: storage media managed through their lifecycle (A.7.10), supporting utilities protected (A.7.11), cabling secured (A.7.12), equipment maintained (A.7.13), and equipment securely disposed of or re-used with data removed (A.7.14) - then consolidate the A.7 theme conclusion.\n\n14. Test A.7.10 across the real media surface: cloud-side storage governed under the inherited layer, and any local media - laptops, removable drives if permitted at all - tracked, encrypted, and restricted per the rules.\n15. Confirm A.7.11 and A.7.12 through the mapped cloud provider attestations for the data-center layer, and for directly controlled spaces verify power and network arrangements do not undermine availability commitments.\n16. Verify A.7.13 maintenance: managed endpoints patched and serviced per schedule, with records; anything serviced by third parties handled under data-protection safeguards.\n17. Test A.7.14 with sampled disposal or re-use events: cryptographic erasure or destruction evidenced before equipment left control, including customer-environment teardown data destruction on the cloud side.\n18. Consolidate the A.7 assessment results across the perimeter, workspace, and equipment assessments into the theme conclusion and prepare the theme conclusion for independent lead-assessor sign-off at the final checkpoint.\n\n19. Apply these procedures to each applicable A.7 control in the approved Statement of Applicability. For every excluded control, retain its identifier, rationale, authorization and risk-treatment reference in the theme workpaper. Missing evidence remains a gap; an exclusion or provider inheritance never implies that a control operated. Treat the declared-control exit criteria below as applying to the approved scope, with exclusions reconciled separately.\n20. The physical controls assessor challenges sample coverage, evidence sufficiency, control operation and nonconformity classification using their specialist knowledge. Record unresolved matters and evidence limits in the theme workpaper. Submit the exact workpaper version for the assessor’s native approval; send that approved version to the final checkpoint for independent lead-assessor sign-off.\n\n**Record in AssureSwarm**\nRecord per-control conclusions distinguishing directly operated evidence from attestation reliance, with references for both. Coverage gaps in the attestation mapping are findings.\n\nRecord per-control conclusions with endpoint posture exports and attestation references attached. Individual lapses versus systemic gaps are distinguished explicitly.\n\nRecord per-control conclusions, attach the consolidated A.7 theme summary with its finding register, and capture the assessor’s native approval with date and capacity, with independent lead-assessor sign-off on the theme conclusion at the final checkpoint.\n\n- Step result: markdown assessment with each A.7 control’s applicability, tests, sample identifiers, evidence references, conclusion, exclusion or reliance rationale, and classified findings with owners.\n- Step documents: restricted evidence files, the A.7 theme workpaper and finding register; preserve personnel identifiers and access restrictions.\n- Item create/relationship: after verifying the tenant schema, raise each finding as an Issue with issue_type, source, severity and issue_owner, linked to the existing Audit and affected Control items. Preserve corrective actions as linked Remediation items with plan, action_owner and target_date when those fields exist; retain the action plan, owners and target dates in the workpaper until durable records are verified.\n- Native approval: the named specialist assessor’s dated approval of the exact theme workpaper version. The final checkpoint retains independent lead-assessor sign-off.\n\n**Exit criteria**\nAll five declared controls carry a conformity or reliance conclusion with references, and mapping gaps are classified with owners. All four declared controls carry a conformity or reliance conclusion supported by evidence, and exceptions are classified with owners. All five declared controls carry a conformity or reliance conclusion, the A.7 theme summary is attached with nonconformities owned, and the assessor’s native approval is recorded; independent lead-assessor sign-off is required at the final checkpoint.\nThe specialist’s expertise review resolves or explicitly qualifies evidence and classification questions; each applicable control has a traceable conclusion, each exclusion has a documented basis, and the approved theme workpaper is ready for independent review. No executor form is required.","kind":"task","label":"Assess physical controls (A.7)","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]},"requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Physical controls assessor","ermPhase":"assess","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"assess-physical-controls"},{"data":{"controls":["UC-CONFIG-03","UC-VULN-04","UC-SDLC-01","UC-SDLC-03","UC-SDLC-04","UC-SDLC-05","UC-SDLC-10","UC-SDLC-14","UC-ASSET-06","UC-ACCESS-04","UC-ACCESS-05","UC-ACCESS-09","UC-DATA-09","UC-DATA-11","UC-DATA-12","UC-ACCESS-18","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-VULN-03","UC-VULN-05","UC-BCDR-03","UC-BCDR-04","UC-CRYPTO-02","UC-LOG-01","UC-LOG-02","UC-LOG-04","UC-LOG-08","UC-NET-01","UC-NET-13"],"description":"Technology controls assessor applies specialist judgment to endpoint/access safeguards, operations, networks, cryptography and secure development and approves the evidence-supported A.8 assessment for independent review.","instructions":"**Objective**\nTechnology controls assessor applies specialist judgment to endpoint/access safeguards, operations, networks, cryptography and secure development and approves the evidence-supported A.8 assessment for independent review.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\n\n\n- The linked consolidated controls and their operating evidence in AssureSwarm\n- Endpoint management state and baselines for the workforce fleet\n- cloud identity and access management and the source-control platform permission exports isolating privileged roles, with the SSO and MFA configuration\n- Data lifecycle evidence: deletion runs, masking rules on PII fields, and transfer restrictions\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- Monitoring and capacity dashboards for the application hosting services and the managed database service instances\n- The vulnerability management record: scans, findings, and remediation timestamps\n- Backup schedules with completion and restore-test evidence; the change record for the window\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- the cloud audit logging service configuration, retention, and the immutable sink arrangement\n- Network topology for the cloud provider estate: VPC layout, firewall rules, and customer environment segregation\n- The cryptography standard, the key management service key inventory, and TLS configuration evidence\n\nThe linked consolidated controls and their operating evidence in AssureSwarm\n- The development standards: SDLC gates, secure coding rules, and architecture principles\n- the source-control platform pipeline definitions showing the testing and approval gates on the path to the application hosting service\n- Environment inventory with data-handling rules for non-production\n\n- Approved Statement of Applicability, risk treatment plan, prior Stage 1 findings where applicable, and the existing Audit item’s scope and review period. Stage 1 and readiness work remain separate.\n- Before execution, assign and verify the named qualified technological controls assessor as this step’s native approver. The assessor must be independent of the controls assessed. Verify a different independent lead assessor is assigned to approve-annex-a-conclusion; that reviewer must not prepare or approve any of the four specialist assessments. Imported role declarations do not assign people or enforce independence. Verify the native approval count after assignment.\n\n**Procedure**\n*Agent retrieval, testing preparation and filing absorb the complete procedures from “ISO 27001 Stage 2 Technological Controls Audit” (step-4); the technology controls assessor contributes expertise here. The independent lead assessor reviews and signs all four theme conclusions together at approve-annex-a-conclusion.*\n\n1. Assessment scope for Audit Endpoints, Privileged Access & Data Protection: Assess implementation of the endpoint, access, and data-protection controls: user endpoint devices protected (A.8.1), privileged access rights restricted (A.8.2) and privileged utility programs controlled (A.8.18), information access restricted (A.8.3) including access to source code (A.8.4), secure authentication enforced (A.8.5), information deleted when no longer required (A.8.10), data masking applied (A.8.11), and data leakage prevention operated (A.8.12).\n\n2. Test A.8.1 endpoint posture for a workforce sample: managed, encrypted, screen-locked, and running the required protections.\n3. Verify A.8.2 and A.8.18: privileged cloud provider and the source-control platform roles enumerated and justified, owner-level protections in force, break-glass documented, and privileged utilities restricted to the roles that need them.\n4. Test A.8.3 and A.8.4 through the tenancy model: customer data reachable only through authorized paths per tenant, and source code access in the source-control platform restricted and reviewed.\n5. Verify A.8.5 authentication: SSO with MFA enforced across the sampled population including remote and API paths.\n6. Test the data trio - A.8.10 deletion executed per retention schedule including customer-environment teardown, A.8.11 masking verified on classified fields, A.8.12 leakage controls on exports and external sharing - against live configuration.\n\n7. Assessment scope for Audit Operations: Configuration, Malware, Capacity & Backup: Assess implementation of the operational resilience controls: capacity managed to meet requirements (A.8.6), protection against malware (A.8.7), technical vulnerabilities managed within defined timeframes (A.8.8), configurations established and maintained (A.8.9), information backed up and restorable (A.8.13), processing facilities redundant to availability requirements (A.8.14), software installation on operational systems controlled (A.8.19), and changes subject to change management (A.8.32).\n\n8. Verify A.8.6 capacity management through the monitoring evidence: utilization tracked against thresholds with scaling actions recorded where thresholds were approached.\n9. Test A.8.7 malware protection across endpoints and the build chain, including dependency and image scanning in CI.\n10. Test A.8.8 with the remediation clock: sampled vulnerabilities closed within the defined timeframes per severity, breaches escalated and accepted formally.\n11. Verify A.8.9 and A.8.19: baselines defined in infrastructure-as-code and enforced, drift detected and corrected, and production software installation restricted to the pipeline path.\n12. Test A.8.13 and A.8.14: sampled backups completed per schedule, the restore test met its recovery objectives, and redundancy configuration matches the availability commitments; then verify A.8.32 by tracing sampled changes through review, approval, and deployment under the change-management discipline.\n\n13. Assessment scope for Audit Logging, Network Security & Cryptography: Assess implementation of the visibility and network controls: logs produced, protected, and analyzed (A.8.15), monitoring for anomalous behaviour (A.8.16), clocks synchronized (A.8.17), networks secured (A.8.20) and network services' security managed (A.8.21), networks segregated (A.8.22), web filtering applied (A.8.23), and cryptography used effectively with key management (A.8.24).\n\n14. Verify A.8.15 across the estate: security-relevant events logged from the application hosting service, the managed database service, the workforce identity and collaboration platform, and the source-control platform, logs protected against tampering through the immutable sink, and retention meeting the documented periods.\n15. Test A.8.16 monitoring: alerting rules cover the anomaly classes the risk assessment names, and sampled alerts show triage within committed times.\n16. Confirm A.8.17 clock synchronization is inherited platform-wide and log timestamps correlate across sources in a sampled incident.\n17. Test A.8.20, A.8.21, and A.8.22 through configuration: firewall rules default-deny, exposed network services enumerated with security settings managed, and customer environment segregation preventing cross-tenant network reach.\n18. Verify A.8.23 web filtering per the endpoint policy and mobile-code restrictions, then A.8.24 cryptography: approved algorithms in the standard, TLS enforced in transit, KMS-managed keys at rest with rotation and access control on the keys themselves.\n\n19. Assessment scope for Audit Secure Development & Test Environments: Assess implementation of the secure development controls: a secure development life cycle (A.8.25), application security requirements defined (A.8.26), secure architecture and engineering principles applied (A.8.27), secure coding enforced (A.8.28), security testing in development and acceptance (A.8.29), outsourced development directed and monitored (A.8.30), development, test, and production environments separated (A.8.31), test information protected (A.8.33), and information systems protected during audit testing (A.8.34) - then consolidate the A.8 theme conclusion.\n\n20. Verify A.8.25 through A.8.27 by sampling a delivered feature: security requirements recorded, architecture decisions documented against the principles, and the SDLC gates passed in order.\n21. Test A.8.28 and A.8.29 in the pipeline: linting and security checks enforced as merge gates, security test results acted on, and acceptance testing covering the security requirements before release.\n22. Assess A.8.30 for any outsourced or third-party-contributed development: direction, review, and the same gates applied.\n23. Verify A.8.31 and A.8.33: development and test environments separated from production with distinct credentials and projects, and production data absent from test - masked or synthetic data demonstrated where realistic data shapes are needed.\n24. Verify A.8.34: audit and assessment activities against production - including this engagement’s own testing - operate through read paths with protections agreed in advance; then consolidate the A.8 results across all four technological assessments into the theme conclusion and prepare the theme conclusion for independent lead-assessor sign-off at the final checkpoint.\n\n25. Apply these procedures to each applicable A.8 control in the approved Statement of Applicability. For every excluded control, retain its identifier, rationale, authorization and risk-treatment reference in the theme workpaper. Missing evidence remains a gap; an exclusion or provider inheritance never implies that a control operated. Treat the declared-control exit criteria below as applying to the approved scope, with exclusions reconciled separately.\n26. The technology controls assessor challenges sample coverage, evidence sufficiency, control operation and nonconformity classification using their specialist knowledge. Record unresolved matters and evidence limits in the theme workpaper. Submit the exact workpaper version for the assessor’s native approval; send that approved version to the final checkpoint for independent lead-assessor sign-off.\n\n**Record in AssureSwarm**\nRecord per-control conclusions with exports and configuration captures referenced. Privileged-access exceptions cite the specific binding.\n\nRecord per-control conclusions with dashboards, scan records, and change traces referenced. Timeframe breaches cite the finding and its acceptance or escalation.\n\nRecord per-control conclusions with configuration captures and sampled alerts referenced. Segregation findings cite the specific rule or path.\n\nRecord per-control conclusions, attach the consolidated A.8 theme summary with its finding register, and capture the assessor’s native approval with date and capacity, with independent lead-assessor sign-off on the theme conclusion at the final checkpoint.\n\n- Step result: markdown assessment with each A.8 control’s applicability, tests, sample identifiers, evidence references, conclusion, exclusion or reliance rationale, and classified findings with owners.\n- Step documents: restricted evidence files, the A.8 theme workpaper and finding register; preserve personnel identifiers and access restrictions.\n- Item create/relationship: after verifying the tenant schema, raise each finding as an Issue with issue_type, source, severity and issue_owner, linked to the existing Audit and affected Control items. Preserve corrective actions as linked Remediation items with plan, action_owner and target_date when those fields exist; retain the action plan, owners and target dates in the workpaper until durable records are verified.\n- Native approval: the named specialist assessor’s dated approval of the exact theme workpaper version. The final checkpoint retains independent lead-assessor sign-off.\n\n**Exit criteria**\nAll nine declared controls carry a conformity conclusion supported by sampled evidence, and exceptions are classified with owners. All eight declared controls carry a conformity conclusion supported by sampled evidence, and exceptions are classified with owners. All eight declared controls carry a conformity conclusion supported by configuration and sampled evidence, and exceptions are classified with owners. All nine declared controls carry a conformity conclusion supported by sampled evidence, the A.8 theme summary is attached with nonconformities owned, and the assessor’s native approval is recorded; independent lead-assessor sign-off is required at the final checkpoint.\nThe specialist’s expertise review resolves or explicitly qualifies evidence and classification questions; each applicable control has a traceable conclusion, each exclusion has a documented basis, and the approved theme workpaper is ready for independent review. No executor form is required.","kind":"task","label":"Assess technological controls (A.8)","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]},"requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Technology controls assessor","ermPhase":"assess","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"assess-technological-controls"},{"data":{"controls":["UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-04","UC-ACCESS-05","UC-ACCESS-06","UC-ACCESS-08","UC-ACCESS-09","UC-ACCESS-18","UC-ASSET-01","UC-ASSET-03","UC-ASSET-04","UC-ASSET-06","UC-ASSET-07","UC-ASSET-08","UC-AUDIT-23","UC-AUDIT-24","UC-AUDIT-25","UC-BCDR-01","UC-BCDR-03","UC-BCDR-04","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-03","UC-CONFIG-05","UC-CRYPTO-02","UC-DATA-09","UC-DATA-11","UC-DATA-12","UC-DATA-13","UC-GOV-03","UC-GOV-06","UC-GOV-07","UC-GOV-08","UC-GOV-14","UC-GOV-22","UC-GOV-23","UC-HR-01","UC-HR-02","UC-HR-03","UC-HR-04","UC-HR-05","UC-HR-07","UC-IR-01","UC-IR-03","UC-IR-04","UC-IR-06","UC-IR-07","UC-IR-10","UC-LOG-01","UC-LOG-02","UC-LOG-04","UC-LOG-08","UC-NET-01","UC-NET-13","UC-PHYS-01","UC-PHYS-02","UC-PHYS-03","UC-PHYS-04","UC-PHYS-05","UC-PHYS-06","UC-PHYS-08","UC-PHYS-09","UC-RISK-02","UC-RISK-17","UC-SDLC-01","UC-SDLC-03","UC-SDLC-04","UC-SDLC-05","UC-SDLC-10","UC-SDLC-14","UC-TPRM-01","UC-TPRM-04","UC-TPRM-07","UC-TPRM-08","UC-TRAIN-01","UC-VULN-03","UC-VULN-04","UC-VULN-05"],"description":"Independent lead assessor reviews all four specialist assessments and signs each theme conclusion and the scoped Annex A report.","instructions":"**Objective**\nThe independent lead assessor approves the four theme conclusions and the evidence-supported Stage 2 Annex A Controls Audit report for the existing Audit engagement.\n\n**Inputs**\n- Approved theme workpapers, evidence references and native specialist approvals from assess-organizational-controls (A.5), assess-people-controls (A.6), assess-physical-controls (A.7) and assess-technological-controls (A.8). This checkpoint needs all four reviewed outputs.\n- Approved Statement of Applicability, risk treatment plan, scope and period, source-reference index, exclusion rationales, provider reliance mapping, finding registers and prior Stage 1 findings where applicable, attached to the Audit or its steps.\n- A named independent lead assessor assigned and verified as this step’s native approver before execution, with requiredApprovals verified as 1 after assignment. The lead assessor must differ from all four specialist assessors and from management responsible for the controls; they must not have prepared any of these assessments. Imported role declarations do not assign people or enforce independence.\n\n**Procedure**\n1. Reconcile the four approved theme workpapers against the Statement of Applicability: account for A.5.1–A.5.37 (37), A.6.1–A.6.8 (8), A.7.1–A.7.14 (14) and A.8.1–A.8.34 (34). Preserve all 93 control identifiers; retain each applicable conclusion and each authorized exclusion with rationale. Challenge unsupported scope exclusions and missing evidence.\n2. Review the samples, source-period coverage, sufficiency of evidence, classification and ownership of every nonconformity, and the basis for each theme conclusion. Reconcile shared evidence across themes, including joiner/leaver access, remote-work endpoints, incident reporting, supplier inheritance, backup/continuity and development change controls. Assess cross-theme contradictions and aggregate weaknesses without replacing the per-control results.\n3. For inherited physical and other supplier controls, review the approved reliance method, attestation issuer and period, scope, exceptions, control-for-control mapping, customer responsibilities and remaining direct responsibilities. Distinguish conformity conclusions based on directly tested evidence from qualified reliance conclusions. Record coverage gaps as findings; provider certificates and unified-control links alone cannot support a conclusion.\n4. Resolve questions with the responsible specialist. Keep an unsupported theme or overall conclusion unapproved; return the affected workpaper for correction and renewed specialist approval before this checkpoint is approved. Preserve earlier versions, review comments and the version used for every approval.\n5. Approve each of the A.5, A.6, A.7 and A.8 theme conclusions explicitly in the review result, preserving the original lead-assessor sign-off requirement for every source assessment. Sign the exact four-workpaper package and Annex A report once using the native approval record with date and capacity. Record evidence limitations, exclusions, reliance and unresolved findings in the report and any qualified conclusion.\n6. Attach the Stage 2 Annex A Controls Audit report, per-control matrix, four signed theme conclusions and combined finding register to this step. Link approved findings to the existing Audit and affected Controls and hand the reviewed report to the engagement owner and remediation owners within the existing authorization. Record handoff references in this approval’s result. Stage 1 and readiness remain separate; broader ISMS conformity requires the other engagement work. Any certification decision remains with the authorized certification body.\n\n**Record in AssureSwarm**\n- Step result: the independent lead assessor’s review of A.5, A.6, A.7 and A.8, the exact approved document versions, overall scoped conclusion, exclusions, reliance limits, open findings, review resolutions, date and capacity.\n- Step documents: Stage 2 Annex A Controls Audit report, per-control matrix, four theme conclusions and combined finding register with source evidence references and access restrictions.\n- Native approval: independent lead-assessor approval of all four theme conclusions and the Annex A report, tied to the reviewed versions.\n- Item relationship: link the report’s existing Issues and affected Controls to the existing Audit; retain issue_owner on the Issue and corrective action plan, action_owner and target_date on linked Remediation items after checking the tenant schema.\n\n**Exit criteria**\nAll four specialist assessments have native approvals and their reviewed outputs are available. The independent lead assessor has explicitly signed each theme conclusion and the overall scoped Annex A report with date and capacity. All 93 Annex A controls have an applicability disposition; every applicable conclusion, exclusion, reliance decision and classified finding traces to the workpapers. The approved package and handoff references are retained on the Audit’s workflow. This assessment does not independently establish full ISMS conformity or issue certification.","kind":"task","label":"Approve Annex A assessment conclusion","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Independent lead assessor","ermPhase":"report","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"approve-annex-a-conclusion"}],"sourceTemplateId":"workflow-library:audit-iso27001-stage2-controls-audit"}
