Observation and Technical Verification
In an ISO/IEC 27001 audit, Observation and Technical Verification are two key methods for collecting objective audit evidence, alongside interviews and document review, as described in ISO 19011 and taught in Lead Auditor training. Observation means the auditor directly watches activities, processe… In an ISO/IEC 27001 audit, Observation and Technical Verification are two key methods for collecting objective audit evidence, alongside interviews and document review, as described in ISO 19011 and taught in Lead Auditor training. Observation means the auditor directly watches activities, processes, and physical conditions as they happen to confirm that documented practices are actually followed. Examples include checking that visitors are registered and escorted, employees wear badges, screens lock when unattended, clean desk rules are respected, server rooms are access controlled, and backup or change management procedures are carried out as described. Observation gives strong evidence because the auditor sees reality firsthand. However, it shows only a snapshot in time, and people may behave differently when watched, so auditors should combine it with other evidence. Technical Verification means examining information systems and technical controls to confirm they are configured and operating effectively. Examples include reviewing firewall rules, access rights and privileged accounts, password and lockout settings, patch levels, antivirus status, encryption settings, logging and monitoring, and vulnerability scan results. A common technique is sampling, such as comparing the HR list of leavers with active user accounts to verify timely access removal. Auditors usually ask the auditee to demonstrate or extract the information rather than operate systems themselves, use read-only access where possible, avoid disrupting operations, and protect the confidentiality of the data they see. Technical verification may require a technical expert on the audit team if the auditor lacks specific competence. Both methods support triangulation: what people say in interviews and what documents state is confirmed by what the auditor sees and verifies. Evidence must be recorded accurately in working papers, noting what was observed or tested, where, when, and with whom, so that conclusions and any nonconformities against clauses or Annex A controls are traceable, verifiable, and defensible.
Observation and Technical Verification in ISO/IEC 27001 Audits: A Complete Lead Auditor Guide
Introduction
In an ISO/IEC 27001 audit, auditors collect evidence in three main ways: interviews (what people say), document and record review (what is written), and observation and technical verification (what is actually happening). This guide covers the third method. It explains what observation and technical verification are, why they matter, how they are done in practice, and how to answer exam questions on the topic in Lead Auditor certification exams such as PECB, IRCA/CQI, BSI and Exemplar Global.
1. What Is Observation and Technical Verification?
Observation means watching activities, processes, the physical environment and people's behaviour as they happen. It confirms that controls are actually used, not just described. Examples include:
- Watching a receptionist check visitor IDs and issue badges.
- Seeing whether staff lock their screens when they leave their desks (clear screen policy).
- Checking whether sensitive documents are left on desks or printers (clear desk policy).
- Watching a data centre access process, including tailgating behaviour.
- Observing a change being approved and deployed by the change advisory process.
Technical verification means examining the configuration, settings, logs and outputs of information systems and security tools. It confirms that technical controls are set up and working as the ISMS requires. Examples include:
- Reviewing firewall rule sets against the approved network security policy.
- Checking password complexity and account lockout settings in Active Directory.
- Verifying that backups run, and asking for evidence of a successful restore test.
- Examining SIEM logs to confirm that logging and monitoring are active (Annex A 8.15 and 8.16 in ISO/IEC 27001:2022).
- Confirming that encryption is enabled on laptops and mobile devices.
- Sampling user accounts to check that leavers' access was removed on time (A 5.18 Access rights).
- Checking patch status reports against vulnerability management procedures (A 8.8).
ISO 19011:2018 (Guidelines for auditing management systems) lists observation as a recognised method for collecting information. Its Annex A.15 and related guidance cover gathering objective evidence by sampling and verification. ISO/IEC 27007 (guidelines for ISMS auditing) and ISO/IEC TS 27008 (guidelines for assessing information security controls) give further, ISMS-specific guidance, including on technical assessment of controls.
2. Why Is It Important?
a) It provides strong objective evidence. Objective evidence is data that supports the existence or truth of something. Seeing a control work directly is usually more reliable than being told it works. Evidence reliability is often ranked as follows: direct observation or independent technical verification first, then records and documents, then interviews.
b) It closes the gap between documentation and reality. Many organisations have well-written policies that are not followed. A password policy may require 12 characters while the system is set to 8. Only technical verification reveals this.
c) It tests effectiveness, not just existence. ISO/IEC 27001 clause 9.1 requires the organisation to evaluate information security performance and ISMS effectiveness. Auditors must determine whether controls are implemented and effective, not just designed.
d) It supports the Statement of Applicability (SoA). The SoA claims which Annex A controls are implemented. Observation and technical verification confirm whether those claims are true.
e) It reduces audit risk. Relying only on interviews raises the risk of reaching a wrong conclusion. Corroborating evidence from several sources (triangulation) strengthens audit findings.
f) It supports credible nonconformity statements. A nonconformity must be based on verifiable evidence. A screenshot, configuration export or observed event gives a solid, factual basis.
3. How It Works in Practice
Step 1: Planning (Stage 2 audit or surveillance)
- Identify high-risk controls from the risk assessment, the SoA and previous audit results.
- Decide which processes to observe and which technical controls to verify.
- Agree access requirements in advance, such as escorts, system read-only access and confidentiality arrangements.
- Make sure the audit team has the competence needed. If not, include a technical expert, as allowed by ISO 19011 and ISO/IEC 17021-1. Note that a technical expert supports the auditor but does not act as an auditor.
Step 2: Agreeing rules of engagement
- In certification audits, the auditor should not personally operate production systems or run intrusive tests such as penetration tests or vulnerability scans. The auditee demonstrates; the auditor watches and examines. This protects the auditee's systems and keeps the auditor independent.
- ISO/IEC 27007 and ISO/IEC TS 27008 note that technical testing must be authorised, planned and controlled to avoid disrupting operations.
- Respect confidentiality. Avoid recording personal data or sensitive information beyond what is needed. Follow the auditee's rules on photographs and screenshots.
Step 3: Sampling
- The auditor cannot check everything, so sampling is used, either judgement-based or statistical.
- Example: from 120 leavers in the past year, select 15 and verify in the system that their accounts were disabled within the defined timeframe.
- The sample should be representative, and the method should be recorded so the work can be repeated.
Step 4: Performing the observation or verification
- Ask the system owner to display the configuration, logs or reports live, rather than accepting pre-prepared printouts that could be altered.
- Compare what you see against the audit criteria: the organisation's policies, procedures, the SoA, ISO/IEC 27001 requirements and legal or contractual obligations.
- Walk the floor at different times and areas to observe behaviour, such as physical security, clear desk and visitor control.
Step 5: Recording the evidence
- Note exactly what was seen: the system name, setting values, date and time, sample identifiers and who demonstrated it.
- Good example: "On 12 March, the IT administrator J. Smith displayed the Active Directory Default Domain Policy, which showed a minimum password length of 8 characters. The Access Control Policy v3.1, section 4.2, requires 12 characters."
Step 6: Corroborating and evaluating
- Cross-check observations with interviews and documents.
- Decide whether the evidence shows conformity, nonconformity (major or minor), an opportunity for improvement or simply an observation.
Step 7: Reporting
- Findings should be factual and traceable to evidence and criteria. Communicate them at the closing meeting.
4. Limitations and Considerations
- Observer effect: people may behave better when watched. Use unannounced walk-throughs within agreed limits, and combine them with records.
- Point in time: an observation shows only that moment. Records such as logs show performance over time, so use both.
- Technical competence: auditors must understand enough to interpret configurations, or bring in a technical expert.
- Scope: verify only systems and locations within the ISMS scope.
- Not a penetration test: a certification audit is a conformity assessment, not a security test. Technical verification checks whether controls match the ISMS requirements.
- Impartiality: auditors must not fix problems or advise on how to configure systems. Doing so would amount to consultancy.
5. Linking to ISO/IEC 27001:2022 Annex A
Typical controls verified by observation include:
- A 7.1 to 7.14 (physical controls), such as secure areas, entry controls, clear desk and clear screen, and equipment siting.
- A 6.7 Remote working practices.
Typical controls verified technically include:
- A 8.2 Privileged access rights and A 8.5 Secure authentication.
- A 8.7 Protection against malware.
- A 8.8 Management of technical vulnerabilities.
- A 8.9 Configuration management.
- A 8.13 Information backup.
- A 8.15 Logging, A 8.16 Monitoring activities and A 8.17 Clock synchronisation.
- A 8.20 Networks security and A 8.24 Use of cryptography.
6. Exam Tips: Answering Questions on Observation and Technical Verification
Tip 1: Know the hierarchy of evidence. When a question asks which evidence is most reliable, direct observation or technical verification usually beats an interview statement. Be careful, though: an independent record covering a period of time can be stronger than a single observation for demonstrating ongoing effectiveness.
Tip 2: Never accept "the auditor runs the scan". If an option suggests the auditor personally changes configurations, runs vulnerability scans or performs penetration tests during a certification audit, it is usually wrong. The correct approach is to ask the auditee to demonstrate, or to review existing test results.
Tip 3: Watch for the documentation-versus-reality trap. Scenario: "The policy requires quarterly access reviews. The IT manager says they are done. What should the auditor do next?" The best answer is to request records or system evidence of a sample of completed reviews and verify them. Accepting the verbal statement is wrong.
Tip 4: Use sampling language. Strong answers mention selecting a representative sample, recording the sample and comparing against criteria. For instance: "Select a sample of leavers from HR records and verify in the identity management system that their access was revoked within the time defined in the policy."
Tip 5: Write precise nonconformity statements. In essay or scenario exams such as PECB, structure findings in three parts: (1) the requirement, for example clause or control plus the organisation's policy; (2) the evidence, meaning what was observed or verified, specifically and factually; and (3) the statement of nonconformity. Avoid opinions such as "security is poor".
Tip 6: Mention competence and technical experts. If a scenario involves complex technology the auditor does not understand, the correct response is usually to involve a technical expert, under the guidance of the audit team leader. Guessing or skipping the control is not acceptable.
Tip 7: Respect confidentiality and authorisation. Questions may ask about photographing screens or copying logs. The correct answer usually involves obtaining permission, minimising sensitive data and following the auditee's security rules.
Tip 8: Triangulate. Examiners reward answers that combine interviews, documents and observation to reach a conclusion. Say explicitly: "I would corroborate the interview with technical evidence."
Tip 9: Distinguish design from operating effectiveness. A firewall policy document shows design. The live rule set and change logs show implementation and operation. Questions about effectiveness require operational evidence.
Tip 10: Read scenario details carefully. Exams often hide clues, such as "the admin showed a printed report from last month" or "the auditor noticed an unlocked server room door". Recognise whether the evidence is current, reliable and within scope, and whether something observed in passing should be followed up.
Tip 11: Observations made by chance still count. If an auditor notices a security weakness while walking through, it is valid objective evidence if it relates to the scope and criteria. It should be verified and recorded.
Tip 12: Know the standards. Be able to cite ISO 19011 (methods of collecting evidence), ISO/IEC 27007 (ISMS audit guidance), ISO/IEC TS 27008 (technical assessment of controls) and ISO/IEC 17021-1 (certification body requirements, including technical experts).
7. Sample Exam Questions
Q1 (multiple choice): During a Stage 2 audit, the IT manager states that all laptops are encrypted. What is the BEST way for the auditor to confirm this?
A) Accept the statement because the IT manager is responsible.
B) Review the encryption policy.
C) Request a demonstration of the endpoint management console showing encryption status for a sample of devices.
D) Remove a laptop hard drive and try to read it.
Answer: C. This is technical verification by sampling. Option D is intrusive and inappropriate. Options A and B do not show implementation.
Q2 (scenario): While walking through the office, the auditor sees several unlocked, unattended workstations showing customer data. How should this be handled?
Model answer: Record the facts: location, time, number of workstations and the type of data visible, without recording the data itself. Compare against the clear desk and clear screen policy and Annex A 7.7. Check whether technical controls such as automatic screen lock exist and how they are configured. Interview staff about awareness (clause 7.3). Then raise a nonconformity, graded according to whether it is an isolated case or a systemic failure.
Q3 (essay): Explain how you would verify the effectiveness of the backup control.
Model answer: Review the backup policy and schedule. Ask the administrator to display the backup software job logs for a sample period and confirm that jobs succeeded and failures were handled. Request evidence of recent restore tests and their results. Check that backup storage is protected, for example by encryption and offsite or offline copies, in line with the policy. Compare all of this to the criteria and record the sample details.
Summary
Observation and technical verification turn an audit from a paper exercise into a real assessment of whether information security works. They provide strong objective evidence, expose gaps between policy and practice, and support credible findings. In exams, always favour answers that verify rather than trust, use sampling, respect authorisation and impartiality, involve technical experts when needed, and record findings precisely against clear criteria.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!