ISO 27001 for IT Companies: Access, Logging, and Backup Evidence
Introduction
"ISO for IT companies" arrives at the audit as three folders, not as a speech about the standard. The auditor asks who gets on the server, what was recorded when they did, and whether the backup comes back. The rest of Annex A matters only after those three exist.
The 2022 edition of ISO/IEC 27001 puts that in numbered controls, not in a book chapter:
A.5.15 access control A.8.15 logging A.8.13 information backup
This article is what I put in the folder. The policy lives in the governance article. If the company also runs AI, the model that never leaves the machine is in the local RAG and ISO article. Here it is the ordinary server: access, log, and restore.
Access: who has a shell today
A stale access spreadsheet loses to what the system says right now. I generate the list on the spot and attach the file with the date in the name.
getent passwd | awk -F: '$3>=1000 && $3<65534 {print $1}' > /var/audit/access/users-$(date -I).txt
getent group sudo wheel 2>/dev/null
awk -F: '$2!~/^(\|!)/ {print $1}' /etc/shadow
last -F | head -n 30
The first line is human accounts. The second is who administers. The third shows a password that is still active (a hash is present). last is the sample of who signed in.
Control A.5.15 does not ask that nobody has sudo. It asks that the list matches the job. If the intern shows up in sudo and is not on the access matrix, the evidence already failed before the firewall question.
A service account does not belong on that human list. It has its own user, no interactive password, and its name appears in the unit file, not in sudo.
Logging: one event you can find
A.8.15 asks for a record someone can read months later. A syslog that rotates in seven days does not qualify. I show a search for a real event, with a time and a host.
ausearch -k sudo-exec --start today -i | head -n 20
logger -t iso-evidence "CHG-1108 alex checked the weekly backup"
grep "CHG-1108" /var/log/syslog /var/log/messages 2>/dev/null | tail
If ausearch returns nothing, the auditd rule for sudo execve is not active. No rule, no evidence. The minimum rule:
auditctl -w /usr/bin/sudo -p x -k sudo-exec
That does not replace the rule persisted in /etc/audit/rules.d/. auditctl alone dies on reboot and next year's audit opens a mute host. Write the rule to disk and confirm with auditctl -l after a restart.
The same habit applies to the ticket. The SLA Grafana reads from OTRS is other operational evidence, in the Grafana and OTRS article. It does not mix with the sudo log, but the audit asks for both.
Backup: the restore, not the policy
A.8.13 is not proved by "we have a daily backup" written in the SOP. It is proved by a restored file whose hash matches.
install -d -m 750 /var/audit/restore
tar -C /etc -czf /var/audit/restore/etc-$(date -I).tar.gz ssh sudoers.d
sha256sum /var/audit/restore/etc-$(date -I).tar.gz \
| tee /var/audit/restore/etc-$(date -I).sha256
sha256sum -c /var/audit/restore/etc-$(date -I).sha256
rm -rf /tmp/restore-test && mkdir /tmp/restore-test
tar -C /tmp/restore-test -xzf /var/audit/restore/etc-$(date -I).tar.gz
test -f /tmp/restore-test/ssh/sshd_config && echo "restore ok"
sha256sum -c checks the archive against the hash stored on the backup day, before it is opened. Only then tar extracts and test shows that sshd_config came back. Opening the file without -c proves it is not corrupt. It does not prove it is the archive from that date.
For application data, the same path: a dump, a checksum, a restore into another directory, a query that returns a row you picked beforehand. On HANA that restore is the BACKUP DATA from the SAP Business One on AWS article. The principle is the same on a local disk.
Keep the checksum off the machine that creates the backup. In the same folder, whoever deletes the tar deletes the proof.
The folder that goes into the room
On audit day I do not open the standard. I open three files:
users-YYYY-MM-DD.txt, compared with the access matrix.- One line from
ausearchor syslog with that week's change. - The
.sha256and the test-restore log.
If one of the three is missing, the ISO 27001 speech does not survive the next question. The other controls exist. These three are what separate an IT company that operates the standard from one that printed the certificate.
Related Articles
How to Implement Generative AI and Local RAG in Compliance with ISO 27001 and ISO 9001
Local RAG with Ollama on CPU, aligned with ISO 27001, ISO 9001, and the access control a SOC 2 audit also asks for.
Multi-cloud for Banks: Separating the Core, Data, and the Audit Trail
Multi-cloud architecture for banks: a locked region, a core isolated from the lab, and an audit trail nobody can delete. SCP, CloudTrail, and Object Lock commands.