The engagement is performed where the outcome is to be submitted to a third party. The client is the organisation; the addressee of the conclusion is a regulator, a parent company, a group auditor, a lender or an international development institution.
What distinguishes this service from the others is not the depth of the examination but its form and the requirements that follow from it. The conclusion must be expressed against criteria settled in advance, supported by sufficient evidence and set out so that the addressee may rely upon it without knowledge of how the work was conducted.
Hence the sequence: the criteria are agreed before work begins and are not thereafter varied, the extent of procedures follows from the degree of assurance required, and every statement in the report has a traceable basis in the working papers.
To obtain a preliminary estimate of scope, timing and fees, please complete the questionnaire. A response is provided within several business days.
External review of the information security management system
With effect from 1 November 2025, banks, branches of non-resident banks and organisations carrying on certain types of banking operation are required to procure an external review of the state of their information security management system against the national standard ST ISO/IEC 27001. The extent of that review is determined by the executive body of the organisation.
Determining the extent is a task in its own right and is settled before work begins. A review covering only part of the areas of the standard does not demonstrate compliance in subsequent dealings with the regulator. A review covering every area without regard to the actual composition of the organisation’s information assets increases effort without a commensurate result.
A defensible scope follows from the information assets the organisation has classified as critical, from the manner in which they are processed, and from the results of previous reviews. A proposal as to scope, with its justification, is prepared before the engagement contract is signed and agreed with the executive body, since it is that body which approves the scope.
The outcome is a report on the state of the information security management system identifying the areas of the standard reviewed, the non-conformities found and the recommendations made, suitable for submission to the governing bodies of the organisation and to the regulator.
Circumstances of engagement
|
Regulatory requirement
|
Group requirement
|
Lender or donor requirement
|
|
An organisation supervised by a financial regulator must procure an examination within a prescribed period and submit its results. The form of the report and the areas covered follow from the requirements of the regulator. |
A parent company or group auditor sets its own expectations as to the control environment of a subsidiary. The examination is performed against those expectations and the report is ordinarily prepared in English. |
A bank, investor or international development institution makes financing conditional upon confirmation of the state of information technology and information protection. The criteria follow from the terms of the agreement. |
Areas covered
The areas covered follow from the criteria agreed. A typical scope comprises:
- governance of information technology: allocation of authority and accountability, planning, and interaction with the governing bodies of the organisation
- access management: granting, amendment and withdrawal of rights, segregation of privileged accounts, and periodic recertification
- change management: initiation, approval, testing and migration of changes into production, and separation of environments
- operations management: job scheduling, incident handling, monitoring, and maintenance of equipment and system software
- backup and recovery, including confirmation of restorability in practice
- business continuity: plans, allocation of roles, test results and alternate sites
- information protection: perimeter and endpoint security, malware controls, vulnerability management and event response
- physical security of premises where information is processed and stored, and supporting engineering systems
- management of relationships with service providers and contractors, including oversight of performance and access by supplier personnel
- processing and protection of restricted information, including personal data
Each control is considered in two respects: whether it is capable of achieving its stated objective by design, and whether it was in fact performed at the established frequency throughout the period under examination.
The place of technical security testing
Technical procedures — vulnerability scanning, configuration benchmarking and penetration testing — form part of the toolkit and are applied where they yield evidence bearing on the agreed criteria.
Their standalone value is limited. The result is a snapshot as at the date of testing. In an organisation where change, access and vulnerability management are not established, the state alters faster than the report can be issued, and repeat scanning after a short interval yields a different list. Technical procedures are therefore applied once it has been established how the organisation manages change and vulnerabilities, and their results are interpreted in that light.
Organisations seeking solely a list of technical vulnerabilities, without regard to the underlying processes, will wish to weigh that limitation when framing their request.
Course of the engagement
|
1
|
Agreement of criteria and scope
The requirements against which the conclusion is to be expressed, the degree of assurance required and the period under examination are settled. The controls to be examined follow from the criteria selected. The scope is recorded in the engagement contract; any subsequent change is documented by an addendum. |
|
2
|
Request for materials and planning of procedures
A structured schedule of requested documents, extracts and logs is issued. On the basis of the materials received, the procedures, sample sizes and interview timetable are determined. |
|
3
|
Fieldwork
Inspection of documents, interviews, observation, analysis of configurations and extracts, reperformance of control procedures, sample testing of operating effectiveness, analytical procedures and, where required, technical testing are applied. |
|
4
|
Evaluation and discussion
Findings are related to the criteria, supported by evidence and assessed for significance. Preliminary results are discussed with the responsible members of staff before inclusion in the report. |
|
5
|
Report and presentation of results
A signed report is delivered. By arrangement, the results are presented to the board of directors, the audit committee or another body, and explanatory materials are prepared for the addressee of the conclusion. |
Deliverables
- a report setting out the scope, the procedures applied and the conclusion expressed against the agreed criteria
- a schedule of findings identifying the criterion contravened, the supporting evidence and the risk assessment
- a register of recommendations with an indication of priority and of expected remediation timescales
- a management letter setting out observations that do not bear on the conclusion but merit attention
- where required, materials for submission to the governing bodies and to the addressee of the conclusion
Timescales
Fieldwork on a comprehensive engagement ordinarily takes six to twelve weeks, depending on the number of systems, sites and legal entities. Preparation of the report takes a further two to three weeks after fieldwork concludes.
A scheduling lead time of four to eight weeks is additional. Where the engagement is tied to a deadline set by a regulator, please indicate this at first contact: the timetable is built backwards from the date on which the results are to be submitted.
Related services
Where an examination of a single system or a single rule is required, without covering the organisation as a whole, a different service applies: Information systems examination →.
Frequently asked questions
What extent of external review should the executive body determine
The scope follows from the information assets the organisation has classified as critical, from the manner in which they are processed, and from the results of previous reviews. A proposal as to scope, with its justification, is prepared before the engagement contract is signed; approval remains with the executive body.
Does the external review replace certification to the international standard
No. An external review of the state of an information security management system and certification of a management system differ in purpose and in the manner in which they are conducted. The review confirms the state of affairs as at the date of performance and is addressed to the governing bodies of the organisation and to the regulator.
How often is the external review performed
The frequency follows from the requirements in force as at the date of performance and from the internal documents of the organisation. Planning is best begun well in advance: the lead time for fieldwork is four to eight weeks.
What distinguishes a review engagement from one expressing an independent conclusion
The extent of procedures and the form of the conclusion. A review engagement affords limited assurance and is expressed as a statement that nothing has come to attention indicating non-compliance. An engagement expressing an independent conclusion requires substantially more work and concludes with a direct statement of compliance or non-compliance.
What happens if significant divergences are identified
They are included in the report, identifying the criterion, the evidence and the risk assessment, and are accompanied by recommendations. The organisation may submit explanations and information on the measures being taken, which are reflected in the report. Suppressing matters identified is incompatible with the nature of the engagement.
May the engagement be confined to selected areas
Yes, provided the limitation is agreed with the addressee of the conclusion and reflected in the description of scope. Any limitation of scope is stated expressly in the report.
Is remediation subsequently verified
Yes, under a separate engagement. Such verification is performed against the findings previously raised and concludes with a statement on the state of their remediation.
In what language is the report prepared
In Russian or English, at the choice of the organisation. Reports prepared for a parent company or an international development institution ordinarily require English.