Skip to main content

ISO 27001 Annex A

93 requirements mapped to controls.

Requirements

RequirementTitleControlsOwner
A.5.1Policies for information securitySID-ORG-01operator
A.5.2Information security roles and responsibilitiesSID-ORG-02operator
A.5.3Segregation of dutiesSID-ORG-02, SID-ACCESS-01platform
A.5.4Management responsibilitiesSID-ORG-01operator
A.5.5Contact with authoritiesSID-ORG-05operator
A.5.6Contact with special interest groupsSID-ORG-05operator
A.5.7Threat intelligenceSID-ORG-03, SID-TRUST-02platform
A.5.8Information security in project managementSID-OPS-08platform
A.5.9Inventory of information and other associated assetsSID-OPS-06operator
A.5.10Acceptable use of information and other associated assetsSID-ORG-07operator
A.5.11Return of assetsSID-ARCH-02operator
A.5.12Classification of informationSID-DATA-01, SID-DATA-02, SID-ORG-08platform
A.5.13Labelling of informationSID-ARCH-02, SID-ORG-08operator
A.5.14Information transferSID-TRANS-01, SID-TRANS-02, SID-TRANS-03platform
A.5.15Access controlSID-AUTH-01, SID-AUTH-02, SID-ACCESS-01, SID-ACCESS-02platform
A.5.16Identity managementSID-AUTH-01, SID-AUTH-03platform
A.5.17Authentication informationSID-AUTH-01, SID-CRYPTO-02, SID-CRYPTO-03platform
A.5.18Access rightsSID-ACCESS-01, SID-ACCESS-04platform
A.5.19Information security in supplier relationshipsSID-ORG-04operator
A.5.20Addressing information security within supplier agreementsSID-ORG-04operator
A.5.21Managing information security in the ICT supply chainSID-ORG-04, SID-OPS-04platform
A.5.22Monitor, review and change management of supplier servicesSID-ORG-04operator
A.5.23Information security for use of cloud servicesSID-ORG-04operator
A.5.24Information security incident management planning and preparationSID-OPS-01operator
A.5.25Assessment and decision on information security eventsSID-OPS-01, SID-AUDIT-01platform
A.5.26Response to information security incidentsSID-OPS-01operator
A.5.27Learning from information security incidentsSID-OPS-01operator
A.5.28Collection of evidenceSID-AUDIT-01platform
A.5.29Information security during disruptionSID-OPS-02operator
A.5.30ICT readiness for business continuitySID-OPS-02operator
A.5.31Legal, statutory, regulatory and contractual requirementsSID-ORG-05operator
A.5.32Intellectual property rightsSID-ORG-05operator
A.5.33Protection of recordsSID-CRYPTO-03, SID-OPS-03platform
A.5.34Privacy and protection of PIISID-PRIV-01, SID-DATA-01, SID-DATA-02platform
A.5.35Independent review of information securitySID-ORG-05operator
A.5.36Compliance with policies, rules and standards for information securitySID-ORG-05operator
A.5.37Documented operating proceduresSID-ORG-06operator
A.6.1ScreeningSID-PPL-01operator
A.6.2Terms and conditions of employmentSID-PPL-01operator
A.6.3Information security awareness, education and trainingSID-PPL-02operator
A.6.4Disciplinary processSID-ARCH-02operator
A.6.5Responsibilities after termination or change of employmentSID-ARCH-02operator
A.6.6Confidentiality or non-disclosure agreementsSID-PPL-03operator
A.6.7Remote workingSID-ARCH-02operator
A.6.8Information security event reportingSID-PPL-04operator
A.7.1Physical security perimetersSID-PHY-01operator
A.7.2Physical entrySID-PHY-01operator
A.7.3Securing offices, rooms and facilitiesSID-PHY-01operator
A.7.4Physical security monitoringSID-PHY-01operator
A.7.5Protecting against physical and environmental threatsSID-PHY-01operator
A.7.6Working In secure areasSID-PHY-01operator
A.7.7Clear desk and clear screenSID-PHY-02operator
A.7.8Equipment siting and protectionSID-PHY-02operator
A.7.9Security of assets off-premisesSID-PHY-02operator
A.7.10Storage mediaSID-PHY-02, SID-CRYPTO-03platform
A.7.11Supporting utilitiesSID-PHY-01operator
A.7.12Cabling securitySID-PHY-01operator
A.7.13Equipment maintenanceSID-PHY-02operator
A.7.14Secure disposal or re-use of equipmentSID-PHY-02operator
A.8.1User end point devicesSID-HARD-05, SID-CRYPTO-02platform
A.8.2Privileged access rightsSID-HARD-03platform
A.8.3Information access restrictionSID-ACCESS-01, SID-ACCESS-04platform
A.8.4Access to source codeSID-OPS-08, SID-OPS-12platform
A.8.5Secure authenticationSID-AUTH-01, SID-AUTH-02, SID-AUTH-03, SID-AUTH-04platform
A.8.6Capacity managementSID-OPS-02operator
A.8.7Protection against malwareSID-OPS-04, SID-HARD-05, SID-HARD-09platform
A.8.8Management of technical vulnerabilitiesSID-OPS-04platform
A.8.9Configuration managementSID-OPS-05platform
A.8.10Information deletionSID-PRIV-03, SID-DATA-10, SID-AUTH-06platform
A.8.11Data maskingSID-DATA-01, SID-DATA-02, SID-PRIV-01platform
A.8.12Data leakage preventionSID-HARD-01, SID-HARD-05, SID-PRIV-01, SID-HARD-08, SID-DATA-09, SID-OPS-11platform
A.8.13Information backupSID-OPS-03operator
A.8.14Redundancy of information processing facilitiesSID-OPS-02operator
A.8.15LoggingSID-AUDIT-01, SID-OPS-06platform
A.8.16Monitoring activitiesSID-AUDIT-01, SID-OPS-06platform
A.8.17Clock synchronizationSID-AUDIT-01operator
A.8.18Use of privileged utility programsSID-HARD-03platform
A.8.19Installation of software on operational systemsSID-OPS-05operator
A.8.20Networks securitySID-TRANS-01, SID-TRANS-04platform
A.8.21Security of network servicesSID-TRANS-01, SID-TRANS-04platform
A.8.22Segregation of networksSID-HARD-03platform
A.8.23Web filteringSID-TRANS-04platform
A.8.24Use of cryptographySID-CRYPTO-01, SID-CRYPTO-02, SID-CRYPTO-03, SID-CRYPTO-04, SID-CRYPTO-05, SID-KEY-01, SID-KEY-02, SID-OPS-10, SID-TRANS-05platform
A.8.25Secure development life cycleSID-OPS-08, SID-OPS-09platform
A.8.26Application security requirementsSID-HARD-02, SID-HARD-04, SID-HARD-05platform
A.8.27Secure system architecture and engineering principlesSID-HARD-03, SID-ACCESS-01, SID-KEY-01platform
A.8.28Secure codingSID-HARD-01, SID-HARD-02, SID-TRANS-04, SID-HARD-09platform
A.8.29Security testing in development and acceptanceSID-OPS-08platform
A.8.30Outsourced developmentSID-ORG-04operator
A.8.31Separation of development, test and production environmentsSID-OPS-08platform
A.8.32Change managementSID-OPS-05platform
A.8.33Test informationSID-OPS-08platform
A.8.34Protection of information systems during audit testingSID-OPS-08platform