ISO 27001 Effectiveness Assessment Checklist Form
Use this form to assess the effectiveness of ISO 27001 information security controls, record evidence, identify gaps, and track follow-up actions.
Assessment Scope and Context
Organization / Business Unit or Site in Scope
*
Assessment Period / Review Timeframe
*
Quarterly
Semi-Annual
Annual
Ad Hoc
Other
Assessment Area
*
Please Select
Access Control
Asset Management
Incident Management
Risk Management
Awareness and Training
Supplier Security
Business Continuity
Other
Scope Notes and Key Context
Effectiveness Review
Control Domain Effectiveness Review
*
Rows
Effectiveness Level
Evidence Available
Comments
Context of the organization
1
2
Leadership and policy
3
4
Risk assessment and treatment
5
6
Information security objectives
7
8
Operational controls
9
10
Internal audit
11
12
Management review
13
14
Corrective actions
15
16
Overall Control Effectiveness
*
Not Effective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Not Effective, 10 is Highly Effective
Overall Control Status
*
Fully effective
Partially effective
Ineffective
Evidence Summary / Supporting Observations
Findings and Follow-up
Identified Gaps / Nonconformities / Improvement Opportunities
*
Corrective Action Priority
*
Low
Medium
High
Critical
Target Completion Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Action Owner / Responsible Team
*
Additional Remarks / Recommendations
Submit
Should be Empty: