Catalog / ISO 27001

ISO 27001 ISO/IEC 27001:2022 · ISMS

Management clauses 4–10 plus the four Annex A themes — organizational, people, physical, and technological controls — assessed against the evidence you upload.

5
domains
123
controls
269
tests the agent runs

Control catalog

ISMS Management System

MS · 30 controls
  • 4.1

    Understanding the organization and its context

    Internal/external issues affecting the ISMS are identified, documented, and kept current.

  • 4.2

    Understanding the needs and expectations of interested parties

    Interested parties and their security-relevant requirements are identified, and those addressed by the ISMS are determined.

  • 4.3

    Determining the scope of the ISMS

    ISMS scope is documented, justified, and accounts for interfaces and dependencies.

  • 4.4

    Information security management system

    The ISMS operates as a system of interacting, maintained processes.

  • 5.1

    Leadership and commitment

    Top management demonstrably leads, resources, and integrates the ISMS into the business.

  • 5.2

    Policy

    An approved, communicated, available information security policy exists and frames objectives.

  • 5.3

    Organizational roles, responsibilities and authorities

    Responsibilities and authorities for ISMS conformance and performance reporting are assigned and communicated.

  • 6.1.1

    Actions to address risks and opportunities — General

    ISMS-level risks and opportunities are determined and actions planned and integrated.

  • 6.1.2

    Information security risk assessment

    A documented, repeatable risk assessment process produces consistent, valid results.

  • 6.1.3

    Information security risk treatment

    Risks are treated via selected controls, compared to Annex A, with an SoA and approved treatment plan.

  • 6.2

    Information security objectives and planning to achieve them

    Measurable security objectives are set, consistent with policy, with plans to achieve them.

  • 6.3

    Planning of changes

    Changes to the ISMS are planned rather than made ad hoc.

  • 7.1

    Resources

    Resources required for the ISMS are determined and provided.

  • 7.2

    Competence

    Persons affecting security performance are competent; gaps are closed and recorded.

  • 7.3

    Awareness

    Relevant persons are aware of the policy, their role, and the implications of noncompliance.

  • 7.4

    Communication

    Internal and external ISMS communications are determined (what, when, with whom, how).

  • 7.5.1

    Documented information — General

    All documentation required by the standard, plus that needed for effectiveness, exists.

  • 7.5.2

    Creating and updating

    Documents are properly identified, formatted, reviewed, and approved.

  • 7.5.3

    Control of documented information

    Documented information is available, protected, and controlled across its lifecycle.

  • 8.1

    Operational planning and control

    Processes meeting security requirements and treatment actions are planned, implemented, and controlled.

  • 8.2

    Information security risk assessment

    Risk assessments are performed at planned intervals and on significant change, with results retained.

  • 8.3

    Information security risk treatment

    The risk treatment plan is implemented and results are documented.

  • 9.1

    Monitoring, measurement, analysis and evaluation

    ISMS performance and effectiveness are monitored and evaluated using defined methods.

  • 9.2.1

    Internal audit — General

    Internal audits confirm the ISMS conforms to requirements and is effectively implemented.

  • 9.2.2

    Internal audit programme

    An audit programme is planned and run with impartial auditors; results are reported and retained.

  • 9.3.1

    Management review — General

    Top management reviews the ISMS at planned intervals for suitability, adequacy, and effectiveness.

  • 9.3.2

    Management review inputs

    Management reviews consider all required inputs.

  • 9.3.3

    Management review results

    Reviews produce documented decisions on improvement and any needed ISMS changes.

  • 10.1

    Continual improvement

    The ISMS is demonstrably and continually improved.

  • 10.2

    Nonconformity and corrective action

    Nonconformities are reacted to, root-caused, corrected, and the corrective action's effectiveness is reviewed.

A.5 Organizational Controls

A5 · 37 controls
  • A.5.1

    Policies for information security

    An approved, communicated, reviewed set of security policies exists.

  • A.5.2

    Information security roles and responsibilities

    Security roles are defined, assigned to named owners, and accepted.

  • A.5.3

    Segregation of duties

    Conflicting duties are identified and segregated, with compensating controls where segregation is impractical.

  • A.5.4

    Management responsibilities

    Management requires and reinforces adherence to security policies across personnel.

  • A.5.5

    Contact with authorities

    Relevant authorities are identified and a procedure governs when and how to contact them.

  • A.5.6

    Contact with special interest groups

    Contact with relevant security interest groups and forums is maintained.

  • A.5.7

    Threat intelligence

    Threat information is collected, analyzed, and turned into action.

  • A.5.8

    Information security in project management

    Security is integrated into project management regardless of project type.

  • A.5.9

    Inventory of information and other associated assets

    An accurate, owned, maintained inventory of information and associated assets exists.

  • A.5.10

    Acceptable use of information and other associated assets

    Rules for acceptable use and handling of assets exist and are communicated.

  • A.5.11

    Return of assets

    Assets are recovered on termination or role change.

  • A.5.12

    Classification of information

    Information is classified per a defined scheme reflecting CIA and stakeholder needs.

  • A.5.13

    Labelling of information

    Labelling procedures implement the classification scheme in practice.

  • A.5.14

    Information transfer

    Transfer rules and agreements protect information across all channels.

  • A.5.15

    Access control

    Access control rules are established and enforced on need-to-know/least-privilege.

  • A.5.16

    Identity management

    Identities are uniquely assigned and managed across their full lifecycle.

  • A.5.17

    Authentication information

    Allocation and management of authentication information (passwords, secrets) is controlled.

  • A.5.18

    Access rights

    Access rights are provisioned on approval, reviewed periodically, and revoked promptly.

  • A.5.19

    Information security in supplier relationships

    Processes manage security risks arising from supplier products and services.

  • A.5.20

    Addressing information security within supplier agreements

    Relevant security requirements are established and agreed in supplier contracts.

  • A.5.21

    Managing information security in the ICT supply chain

    ICT supply chain security risks, including sub-suppliers, are managed.

  • A.5.22

    Monitoring, review and change management of supplier services

    Supplier services are regularly reviewed against agreements and service changes are managed.

  • A.5.23

    Information security for use of cloud services

    Cloud acquisition, use, management, and exit are governed against security requirements.

  • A.5.24

    Information security incident management planning and preparation

    Incident management is planned with defined processes, roles, and responsibilities.

  • A.5.25

    Assessment and decision on information security events

    Security events are assessed and classified into incidents consistently.

  • A.5.26

    Response to information security incidents

    Incidents are responded to per documented procedures.

  • A.5.27

    Learning from information security incidents

    Lessons from incidents drive control improvements.

  • A.5.28

    Collection of evidence

    Procedures preserve evidence related to events with chain of custody.

  • A.5.29

    Information security during disruption

    Security is maintained at an appropriate level during disruption.

  • A.5.30

    ICT readiness for business continuity

    ICT readiness is planned, maintained, and tested against continuity objectives.

  • A.5.31

    Legal, statutory, regulatory and contractual requirements

    Applicable legal, regulatory, and contractual requirements are identified, documented, and current.

  • A.5.32

    Intellectual property rights

    Procedures protect IP rights and ensure licensing compliance.

  • A.5.33

    Protection of records

    Records are protected from loss, falsification, and unauthorized access/release per retention needs.

  • A.5.34

    Privacy and protection of PII

    PII privacy and protection requirements are identified and implemented.

  • A.5.35

    Independent review of information security

    The security approach is independently reviewed at planned intervals and on significant change.

  • A.5.36

    Compliance with policies, rules and standards for information security

    Compliance with internal security policies, rules, and standards is regularly reviewed and remediated.

  • A.5.37

    Documented operating procedures

    Operating procedures for processing facilities are documented and available.

A.6 People Controls

A6 · 8 controls
  • A.6.1

    Screening

    Background checks are proportionate to role risk and performed before access.

  • A.6.2

    Terms and conditions of employment

    Security responsibilities are stated in employment terms.

  • A.6.3

    Information security awareness, education and training

    Role-relevant security training is provided, updated, and tracked.

  • A.6.4

    Disciplinary process

    A formal, communicated disciplinary process for security violations exists.

  • A.6.5

    Responsibilities after termination or change of employment

    Post-employment security duties are defined, communicated, and enforced.

  • A.6.6

    Confidentiality or non-disclosure agreements

    NDA/confidentiality requirements are identified, in place, and reviewed.

  • A.6.7

    Remote working

    Security measures for remote work are defined and enforced.

  • A.6.8

    Information security event reporting

    Personnel can report security events promptly via a known channel.

A.7 Physical Controls

A7 · 14 controls
  • A.7.1

    Physical security perimeters

    Physical perimeters protect areas holding information and associated assets.

  • A.7.2

    Physical entry

    Entry controls protect secure areas and access is logged.

  • A.7.3

    Securing offices, rooms and facilities

    Offices, rooms, and facilities are physically secured appropriate to contents.

  • A.7.4

    Physical security monitoring

    Premises are continuously monitored for unauthorized access and alerts are reviewed.

  • A.7.5

    Protecting against physical and environmental threats

    Protection against natural and human-made environmental threats is designed in.

  • A.7.6

    Working in secure areas

    Rules for working in secure areas are defined and applied.

  • A.7.7

    Clear desk and clear screen

    Clear-desk and clear-screen rules are defined and enforced.

  • A.7.8

    Equipment siting and protection

    Equipment is sited and protected to reduce environmental and access risk.

  • A.7.9

    Security of assets off-premises

    Off-premises assets are protected.

  • A.7.10

    Storage media

    Storage media is controlled through its lifecycle, including secure disposal.

  • A.7.11

    Supporting utilities

    Facilities are protected from disruption due to utility failures.

  • A.7.12

    Cabling security

    Power and telecom cabling is protected from interception and damage.

  • A.7.13

    Equipment maintenance

    Equipment is maintained per schedule and maintenance is controlled.

  • A.7.14

    Secure disposal or re-use of equipment

    Data and licensed software are removed and verified before disposal or re-use.

A.8 Technological Controls

A8 · 34 controls
  • A.8.1

    User endpoint devices

    Information on or accessed via endpoints is protected and policy is enforced.

  • A.8.2

    Privileged access rights

    Privileged access is restricted, approved, logged, and reviewed.

  • A.8.3

    Information access restriction

    Access to information and assets is restricted per the access control policy.

  • A.8.4

    Access to source code

    Access to source code, tools, and libraries is controlled and reviewed.

  • A.8.5

    Secure authentication

    Authentication strength is matched to risk and secure procedures are applied.

  • A.8.6

    Capacity management

    Resource use is monitored, forecast, and adjusted proactively.

  • A.8.7

    Protection against malware

    Malware protection is deployed, current, and reinforced by user awareness.

  • A.8.8

    Management of technical vulnerabilities

    Vulnerabilities are identified, assessed, and remediated within risk-based SLAs.

  • A.8.9

    Configuration management

    Secure configurations are baselined, monitored for drift, and reviewed.

  • A.8.10

    Information deletion

    Information is deleted per retention when no longer required, across all stores.

  • A.8.11

    Data masking

    Masking or pseudonymization is applied where required by policy or law.

  • A.8.12

    Data leakage prevention

    DLP measures protect sensitive information across channels and are monitored.

  • A.8.13

    Information backup

    Backups are taken per policy, protected, and restore-tested.

  • A.8.14

    Redundancy of information processing facilities

    Redundancy meets availability requirements and failover is tested.

  • A.8.15

    Logging

    Relevant events are logged, logs are protected, retained, and analyzed.

  • A.8.16

    Monitoring activities

    Networks, systems, and applications are monitored for anomalies and alerts are triaged.

  • A.8.17

    Clock synchronization

    System clocks are synchronized to approved time sources.

  • A.8.18

    Use of privileged utility programs

    Powerful utility programs are restricted to authorized users and logged.

  • A.8.19

    Installation of software on operational systems

    Software installation on operational systems is controlled and approved.

  • A.8.20

    Networks security

    Networks and devices are secured, managed, and monitored.

  • A.8.21

    Security of network services

    Security features and SLAs of network services are defined, agreed, and monitored.

  • A.8.22

    Segregation of networks

    Networks are segregated by group and sensitivity.

  • A.8.23

    Web filtering

    Access to external websites is managed to reduce malicious exposure.

  • A.8.24

    Use of cryptography

    Cryptography and key management follow a defined, enforced policy.

  • A.8.25

    Secure development life cycle

    A secure development lifecycle with security gates is established and applied.

  • A.8.26

    Application security requirements

    Security requirements are identified, specified, and approved when building or acquiring apps.

  • A.8.27

    Secure system architecture and engineering principles

    Secure engineering principles are documented and applied to development.

  • A.8.28

    Secure coding

    Secure coding principles are defined and enforced.

  • A.8.29

    Security testing in development and acceptance

    Security testing is defined and performed before release.

  • A.8.30

    Outsourced development

    Outsourced development is governed by security requirements and reviewed.

  • A.8.31

    Separation of development, test and production environments

    Development, test, and production environments are separated and access-controlled.

  • A.8.32

    Change management

    Changes are assessed, approved, tested, recorded, and reversible.

  • A.8.33

    Test information

    Test information is selected, protected, and managed; production data is avoided or masked.

  • A.8.34

    Protection of information systems during audit testing

    Audit and assurance tests on operational systems are planned and agreed to limit disruption.

See ISO 27001 tested against your evidence.