Catalog / ISO 27001
ISO 27001 ISO/IEC 27001:2022 · ISMS
Management clauses 4–10 plus the four Annex A themes — organizational, people, physical, and technological controls — assessed against the evidence you upload.
- 5
- domains
- 123
- controls
- 269
- tests the agent runs
Control catalog
ISMS Management System
-
4.1Understanding the organization and its context
Internal/external issues affecting the ISMS are identified, documented, and kept current.
-
4.2Understanding the needs and expectations of interested parties
Interested parties and their security-relevant requirements are identified, and those addressed by the ISMS are determined.
-
4.3Determining the scope of the ISMS
ISMS scope is documented, justified, and accounts for interfaces and dependencies.
-
4.4Information security management system
The ISMS operates as a system of interacting, maintained processes.
-
5.1Leadership and commitment
Top management demonstrably leads, resources, and integrates the ISMS into the business.
-
5.2Policy
An approved, communicated, available information security policy exists and frames objectives.
-
5.3Organizational roles, responsibilities and authorities
Responsibilities and authorities for ISMS conformance and performance reporting are assigned and communicated.
-
6.1.1Actions to address risks and opportunities — General
ISMS-level risks and opportunities are determined and actions planned and integrated.
-
6.1.2Information security risk assessment
A documented, repeatable risk assessment process produces consistent, valid results.
-
6.1.3Information security risk treatment
Risks are treated via selected controls, compared to Annex A, with an SoA and approved treatment plan.
-
6.2Information security objectives and planning to achieve them
Measurable security objectives are set, consistent with policy, with plans to achieve them.
-
6.3Planning of changes
Changes to the ISMS are planned rather than made ad hoc.
-
7.1Resources
Resources required for the ISMS are determined and provided.
-
7.2Competence
Persons affecting security performance are competent; gaps are closed and recorded.
-
7.3Awareness
Relevant persons are aware of the policy, their role, and the implications of noncompliance.
-
7.4Communication
Internal and external ISMS communications are determined (what, when, with whom, how).
-
7.5.1Documented information — General
All documentation required by the standard, plus that needed for effectiveness, exists.
-
7.5.2Creating and updating
Documents are properly identified, formatted, reviewed, and approved.
-
7.5.3Control of documented information
Documented information is available, protected, and controlled across its lifecycle.
-
8.1Operational planning and control
Processes meeting security requirements and treatment actions are planned, implemented, and controlled.
-
8.2Information security risk assessment
Risk assessments are performed at planned intervals and on significant change, with results retained.
-
8.3Information security risk treatment
The risk treatment plan is implemented and results are documented.
-
9.1Monitoring, measurement, analysis and evaluation
ISMS performance and effectiveness are monitored and evaluated using defined methods.
-
9.2.1Internal audit — General
Internal audits confirm the ISMS conforms to requirements and is effectively implemented.
-
9.2.2Internal audit programme
An audit programme is planned and run with impartial auditors; results are reported and retained.
-
9.3.1Management review — General
Top management reviews the ISMS at planned intervals for suitability, adequacy, and effectiveness.
-
9.3.2Management review inputs
Management reviews consider all required inputs.
-
9.3.3Management review results
Reviews produce documented decisions on improvement and any needed ISMS changes.
-
10.1Continual improvement
The ISMS is demonstrably and continually improved.
-
10.2Nonconformity and corrective action
Nonconformities are reacted to, root-caused, corrected, and the corrective action's effectiveness is reviewed.
A.5 Organizational Controls
-
A.5.1Policies for information security
An approved, communicated, reviewed set of security policies exists.
-
A.5.2Information security roles and responsibilities
Security roles are defined, assigned to named owners, and accepted.
-
A.5.3Segregation of duties
Conflicting duties are identified and segregated, with compensating controls where segregation is impractical.
-
A.5.4Management responsibilities
Management requires and reinforces adherence to security policies across personnel.
-
A.5.5Contact with authorities
Relevant authorities are identified and a procedure governs when and how to contact them.
-
A.5.6Contact with special interest groups
Contact with relevant security interest groups and forums is maintained.
-
A.5.7Threat intelligence
Threat information is collected, analyzed, and turned into action.
-
A.5.8Information security in project management
Security is integrated into project management regardless of project type.
-
A.5.9Inventory of information and other associated assets
An accurate, owned, maintained inventory of information and associated assets exists.
-
A.5.10Acceptable use of information and other associated assets
Rules for acceptable use and handling of assets exist and are communicated.
-
A.5.11Return of assets
Assets are recovered on termination or role change.
-
A.5.12Classification of information
Information is classified per a defined scheme reflecting CIA and stakeholder needs.
-
A.5.13Labelling of information
Labelling procedures implement the classification scheme in practice.
-
A.5.14Information transfer
Transfer rules and agreements protect information across all channels.
-
A.5.15Access control
Access control rules are established and enforced on need-to-know/least-privilege.
-
A.5.16Identity management
Identities are uniquely assigned and managed across their full lifecycle.
-
A.5.17Authentication information
Allocation and management of authentication information (passwords, secrets) is controlled.
-
A.5.18Access rights
Access rights are provisioned on approval, reviewed periodically, and revoked promptly.
-
A.5.19Information security in supplier relationships
Processes manage security risks arising from supplier products and services.
-
A.5.20Addressing information security within supplier agreements
Relevant security requirements are established and agreed in supplier contracts.
-
A.5.21Managing information security in the ICT supply chain
ICT supply chain security risks, including sub-suppliers, are managed.
-
A.5.22Monitoring, review and change management of supplier services
Supplier services are regularly reviewed against agreements and service changes are managed.
-
A.5.23Information security for use of cloud services
Cloud acquisition, use, management, and exit are governed against security requirements.
-
A.5.24Information security incident management planning and preparation
Incident management is planned with defined processes, roles, and responsibilities.
-
A.5.25Assessment and decision on information security events
Security events are assessed and classified into incidents consistently.
-
A.5.26Response to information security incidents
Incidents are responded to per documented procedures.
-
A.5.27Learning from information security incidents
Lessons from incidents drive control improvements.
-
A.5.28Collection of evidence
Procedures preserve evidence related to events with chain of custody.
-
A.5.29Information security during disruption
Security is maintained at an appropriate level during disruption.
-
A.5.30ICT readiness for business continuity
ICT readiness is planned, maintained, and tested against continuity objectives.
-
A.5.31Legal, statutory, regulatory and contractual requirements
Applicable legal, regulatory, and contractual requirements are identified, documented, and current.
-
A.5.32Intellectual property rights
Procedures protect IP rights and ensure licensing compliance.
-
A.5.33Protection of records
Records are protected from loss, falsification, and unauthorized access/release per retention needs.
-
A.5.34Privacy and protection of PII
PII privacy and protection requirements are identified and implemented.
-
A.5.35Independent review of information security
The security approach is independently reviewed at planned intervals and on significant change.
-
A.5.36Compliance with policies, rules and standards for information security
Compliance with internal security policies, rules, and standards is regularly reviewed and remediated.
-
A.5.37Documented operating procedures
Operating procedures for processing facilities are documented and available.
A.6 People Controls
-
A.6.1Screening
Background checks are proportionate to role risk and performed before access.
-
A.6.2Terms and conditions of employment
Security responsibilities are stated in employment terms.
-
A.6.3Information security awareness, education and training
Role-relevant security training is provided, updated, and tracked.
-
A.6.4Disciplinary process
A formal, communicated disciplinary process for security violations exists.
-
A.6.5Responsibilities after termination or change of employment
Post-employment security duties are defined, communicated, and enforced.
-
A.6.6Confidentiality or non-disclosure agreements
NDA/confidentiality requirements are identified, in place, and reviewed.
-
A.6.7Remote working
Security measures for remote work are defined and enforced.
-
A.6.8Information security event reporting
Personnel can report security events promptly via a known channel.
A.7 Physical Controls
-
A.7.1Physical security perimeters
Physical perimeters protect areas holding information and associated assets.
-
A.7.2Physical entry
Entry controls protect secure areas and access is logged.
-
A.7.3Securing offices, rooms and facilities
Offices, rooms, and facilities are physically secured appropriate to contents.
-
A.7.4Physical security monitoring
Premises are continuously monitored for unauthorized access and alerts are reviewed.
-
A.7.5Protecting against physical and environmental threats
Protection against natural and human-made environmental threats is designed in.
-
A.7.6Working in secure areas
Rules for working in secure areas are defined and applied.
-
A.7.7Clear desk and clear screen
Clear-desk and clear-screen rules are defined and enforced.
-
A.7.8Equipment siting and protection
Equipment is sited and protected to reduce environmental and access risk.
-
A.7.9Security of assets off-premises
Off-premises assets are protected.
-
A.7.10Storage media
Storage media is controlled through its lifecycle, including secure disposal.
-
A.7.11Supporting utilities
Facilities are protected from disruption due to utility failures.
-
A.7.12Cabling security
Power and telecom cabling is protected from interception and damage.
-
A.7.13Equipment maintenance
Equipment is maintained per schedule and maintenance is controlled.
-
A.7.14Secure disposal or re-use of equipment
Data and licensed software are removed and verified before disposal or re-use.
A.8 Technological Controls
-
A.8.1User endpoint devices
Information on or accessed via endpoints is protected and policy is enforced.
-
A.8.2Privileged access rights
Privileged access is restricted, approved, logged, and reviewed.
-
A.8.3Information access restriction
Access to information and assets is restricted per the access control policy.
-
A.8.4Access to source code
Access to source code, tools, and libraries is controlled and reviewed.
-
A.8.5Secure authentication
Authentication strength is matched to risk and secure procedures are applied.
-
A.8.6Capacity management
Resource use is monitored, forecast, and adjusted proactively.
-
A.8.7Protection against malware
Malware protection is deployed, current, and reinforced by user awareness.
-
A.8.8Management of technical vulnerabilities
Vulnerabilities are identified, assessed, and remediated within risk-based SLAs.
-
A.8.9Configuration management
Secure configurations are baselined, monitored for drift, and reviewed.
-
A.8.10Information deletion
Information is deleted per retention when no longer required, across all stores.
-
A.8.11Data masking
Masking or pseudonymization is applied where required by policy or law.
-
A.8.12Data leakage prevention
DLP measures protect sensitive information across channels and are monitored.
-
A.8.13Information backup
Backups are taken per policy, protected, and restore-tested.
-
A.8.14Redundancy of information processing facilities
Redundancy meets availability requirements and failover is tested.
-
A.8.15Logging
Relevant events are logged, logs are protected, retained, and analyzed.
-
A.8.16Monitoring activities
Networks, systems, and applications are monitored for anomalies and alerts are triaged.
-
A.8.17Clock synchronization
System clocks are synchronized to approved time sources.
-
A.8.18Use of privileged utility programs
Powerful utility programs are restricted to authorized users and logged.
-
A.8.19Installation of software on operational systems
Software installation on operational systems is controlled and approved.
-
A.8.20Networks security
Networks and devices are secured, managed, and monitored.
-
A.8.21Security of network services
Security features and SLAs of network services are defined, agreed, and monitored.
-
A.8.22Segregation of networks
Networks are segregated by group and sensitivity.
-
A.8.23Web filtering
Access to external websites is managed to reduce malicious exposure.
-
A.8.24Use of cryptography
Cryptography and key management follow a defined, enforced policy.
-
A.8.25Secure development life cycle
A secure development lifecycle with security gates is established and applied.
-
A.8.26Application security requirements
Security requirements are identified, specified, and approved when building or acquiring apps.
-
A.8.27Secure system architecture and engineering principles
Secure engineering principles are documented and applied to development.
-
A.8.28Secure coding
Secure coding principles are defined and enforced.
-
A.8.29Security testing in development and acceptance
Security testing is defined and performed before release.
-
A.8.30Outsourced development
Outsourced development is governed by security requirements and reviewed.
-
A.8.31Separation of development, test and production environments
Development, test, and production environments are separated and access-controlled.
-
A.8.32Change management
Changes are assessed, approved, tested, recorded, and reversible.
-
A.8.33Test information
Test information is selected, protected, and managed; production data is avoided or masked.
-
A.8.34Protection of information systems during audit testing
Audit and assurance tests on operational systems are planned and agreed to limit disruption.