SOX Change Log Checker
Clause text

ISO/IEC 27001:2022: the clauses the checker cites

The 8 ISO/IEC 27001:2022 clauses behind the findings, each with the evidence an auditor asks for where it is held.

Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.

8 clauses

ISO 27001 8.32 Change management

Put changes to facilities and systems through change management procedures.

Evidence an auditor expects: Change requests; Change approvals; Implementation testing; Post implementation reviews
Where it usually falls short: Missing formal approval; No rollback plan documented
Source: ISO/IEC 27001:2022
ISO 27001 5.3 Segregation of duties

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

Evidence an auditor expects: Role separation matrix; Approval workflow records; Access rights review reports; Segregation conflict log
Where it usually falls short: Combining conflicting roles in small teams; Lack of documented exceptions
Source: ISO/IEC 27001:2022
ISO 27001 8.25 Secure development life cycle

Establish and apply rules for secure development of software and systems.

Evidence an auditor expects: Secure dev policy; Threat modeling artifacts; Code review logs; Security testing reports
Where it usually falls short: Policy exists but not enforced; Threat models not updated for new features
Source: ISO/IEC 27001:2022
ISO 27001 8.31 Separation of development, test and production environments

Separate and secure development, test and production environments.

Evidence an auditor expects: Environment separation policy; Network segmentation diagram; Access control matrix; Change and deployment logs
Where it usually falls short: Policies exist but are not enforced; Shared credentials across environments
Source: ISO/IEC 27001:2022
ISO 27001 8.4 Access to source code

Appropriately manage read and write access to source code, development tools and libraries.

Evidence an auditor expects: Repository access controls; Development tool access; Library dependency controls; Change approval records
Where it usually falls short: Shared accounts used for source code repositories; Permissions not reviewed on a regular basis
Source: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

Evidence an auditor expects: Baseline configurations; Change control records; Configuration audit reports; Secure hardening guidelines; Deviation approvals
Where it usually falls short: Outdated baselines; Missing change approvals
Source: ISO/IEC 27001:2022
ISO 27001 8.19 Installation of software on operational systems

Securely manage software installation on production systems.

Evidence an auditor expects: Installation requests; Approval evidence; Implementation logs; Verification reports
Where it usually falls short: Missing formal approval for installations; No evidence of post‑install verification
Source: ISO/IEC 27001:2022
ISO 27001 8.29 Security testing in development and acceptance

Define and run security testing across the development life cycle.

Evidence an auditor expects: Security test plan; Test execution reports; Vulnerability remediation log; Acceptance criteria records
Where it usually falls short: Testing only after release; Inconsistent test coverage across modules
Source: ISO/IEC 27001:2022