GOV-020 Independent Security Review
Description
An independent assessment report on the information security posture exists for each defined interval and after each significant change to the estate or the operating model. The report names the assessor, who is either an internal audit function separate from the security function or an external third party. It carries a management response recording, for each finding, an owner and a target date.
Rationale
Self-assessment by the team that built the controls cannot give management or a customer the assurance they are asking for, because the blind spots are shared. Independence is the property under test, so the report names the assessor and the reporting line that keeps them clear of the function assessed. GOV-011 is the internal audit cycle and GOV-021 the policy that governs both; independent assessment of an AI system specifically is AIG-008.
Applicability (9 profiles)
The independent assessment is what a financial entity reads under Art. 28(4), point (d) and RTS 2024/1773 Art. 6(3). Art. 8(3) then bars it from relying on that report alone over time, so the report is the entry ticket rather than the whole answer.
164.308(a)(8) has a second trigger the periodic audit does not answer: an environmental or operational change affecting the security of the data. GOV-020's change-driven independent assessment is what carries it.
Annex point 2.3.2 defines independence by line of authority rather than by employment and requires the reviewers to hold appropriate audit competence, with alternative impartiality measures where the entity is too small to separate the line. Point 2.3.3 routes results to the management bodies and resolves each one to corrective action or to a residual risk accepted against the entity risk acceptance criteria.
Framework Mappings (21)
| A&A-02 | Independent Assessments | full |
| A&A-03 | Risk Based Planning Assessment | partial |
| A&A-02 | Independent Assessments | full |
| A&A-03 | Risk Based Planning Assessment | partial |
| DORA-Art.28.4 | Assessments before entering a contractual arrangement | informative |
| DORA-Art.28.5 | Information security standards of the ICT third-party service provider | informative |
| DORA-Art.28.6 | Exercise of access, inspection and audit rights | informative |
| DORA-RTS-2024/1773-Art.6.1 | Due diligence assessment of the prospective provider | informative |
| DORA-RTS-2024/1773-Art.6.3 | Assurance elements used in due diligence | informative |
| COP-S-7.4 | External reports | informative |
| HIPAA-164.306.e | Maintenance | informative |
| HIPAA-164.308.a.8 | Evaluation | full |
| 5.35 | Independent review of information security | full |
| NIS2-CIR-2.3 | Independent Review of Information and Network Security | partial |
| NIS2-CIR-7 | Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measures | informative |
| CA-1 | Policy and Procedures | informative |
| CA-2 | Control Assessments | informative |
| CA-2(1) | Control Assessments | Independent Assessors | full |
| CA-7(1) | Continuous Monitoring | Independent Assessment | full |
| GV-3.2-001 | Human-AI Configuration Roles | GV-3.2-001 | informative |
| MEASURE 1.3 | Independent AI Risk Assessment | informative |
Evidence (2)
Third-party assessment report or external audit report providing independent assurance of the organisation's information security controls.
Example: SOC 2 Type II report, ISO 27001 audit report, penetration test report, or third-party security assessment report (PDF), issued within the last 12 months by an accredited or qualified independent assessor.
Test: Request the most recent independent security assessment report. Verify: (1) the assessor is independent of the security function being assessed (different team or external firm), (2) the report is dated within the defined assessment interval, (3) scope covers the organisation's production environment and key controls, (4) findings are addressed to management and include a management response.
Management response record showing findings from the independent review are tracked to remediation.
Example: Management letter responses (PDF) or remediation tracker (Jira / GRC platform) linked to the assessment report findings, with named owners and target dates.
Test: Request the management response or remediation tracker for the most recent independent assessment. Verify: (1) all findings from the report are represented, (2) each finding has a named owner and target remediation date, (3) critical or high findings are assigned the shortest target dates, (4) closed items have documented evidence of remediation.
Questions (2)
Does your organisation undergo independent security assessments (internal audit teams independent of the security function, or external third-party assessors) at defined intervals?
The assessor must be independent of the function being assessed. Reports should be dated within the defined interval and addressed to management.
What form does your most recent independent security assessment take?
A SOC 2 Type II report or ISO 27001 audit provides the strongest third-party assurance for enterprise customers. All options above should include a management response to findings.