ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)
The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.
What a reviewer asks to see: Statement of Applicability entry for control A.5.34, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific privacy and PII protection policy and its communication to relevant parties; Privacy procedures communicated to everyone who processes PII; Appointment of a privacy officer or equivalent with documented responsibilities; A record of processing or PII inventory mapping which laws apply to each processing activity
Where monitoring plans usually fall short: Privacy is treated as a legal matter only, with no link to security controls; No one is formally responsible for guiding staff and providers on PII handling; Cross-border transfers of PII occur without checking applicable restrictions; Privacy impact assessments are not performed for new processing
ISO/IEC 27001 A.7.4Physical security monitoring
Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.
What a reviewer asks to see: Statement of Applicability entry for control A.7.4, showing inclusion or justified exclusion, implementation status and the risks it treats; Coverage plans for CCTV and intruder detection over sensitive areas, external doors, accessible windows and unoccupied zones; Alarm and detector installation certificates to applicable standards and periodic test records, including battery-powered components; Monitoring logs or monitoring-provider reports showing alarms raised and responses; Access restrictions and hardening of CCTV and alarm systems, including protection of video feeds and remote management
Where monitoring plans usually fall short: CCTV records but nobody reviews footage or responds to alerts; Detectors are installed but never tested, with flat batteries unnoticed; Video systems are exposed on the network with default credentials; Video is retained longer than local law permits