ISO/IEC 27001:2022
An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
edition ISO/IEC 27001:2022, Annex A. 16 requirements cited here. Every ISO/IEC 27001:2022 clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Administrator accounts (other than the backup administrator) cannot change or delete backups
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Restoring from backup is tested as part of a disaster recovery exercise
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Other business applications are patched within the timeframe in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.2 ISO/IEC 27001:2022 | Privileged access rights The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2. evidence an assessor asks for Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes |
Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.2 ISO/IEC 27001:2022 | Privileged access rights The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2. evidence an assessor asks for Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes |
Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.2 ISO/IEC 27001:2022 | Privileged access rights The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2. evidence an assessor asks for Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes |
Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.19 ISO/IEC 27001:2022 | Installation of software on operational systems Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19. evidence an assessor asks for Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems |
Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.19 ISO/IEC 27001:2022 | Installation of software on operational systems Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19. evidence an assessor asks for Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems |
Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.7 ISO/IEC 27001:2022 | Protection against malware Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7. evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date |
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.23 ISO/IEC 27001:2022 | Web filtering The organization is to manage which external websites can be reached, so that exposure to malicious content falls. Purpose (stated in ISO/IEC 27002:2022): keeps malware off systems and blocks unauthorized web resources. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.23. evidence an assessor asks for Statement of Applicability entry for control A.8.23, showing inclusion or justified exclusion, implementation status and the risks it treats; Current rules on safe, proper use of online resources; Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites; Integration of threat intelligence feeds into block lists; The exception request and approval process with records of approved exceptions |
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.9 ISO/IEC 27001:2022 | Configuration management The organization is to set, record, apply, watch and review how its hardware, software, services and networks are configured, security settings included. Purpose (stated in ISO/IEC 27002:2022): ensures systems and networks work correctly with required security settings and are not changed without approval or by mistake. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.9. evidence an assessor asks for Statement of Applicability entry for control A.8.9, showing inclusion or justified exclusion, implementation status and the risks it treats; Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates; Configuration records or a CMDB showing owner, last change date, template version and relationships between assets; Change records showing configuration changes passed through change management; Configuration compliance scan results comparing actual settings with templates, and records of deviations corrected |
Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.15 ISO/IEC 27001:2022 | Logging Logs recording activity, exceptions, faults and other events of interest are to be generated, kept, protected and analysed. Purpose (stated in ISO/IEC 27002:2022): records events, generates evidence, protects log integrity, identifies security events and supports investigations. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.15. evidence an assessor asks for Statement of Applicability entry for control A.8.15, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection; Log source inventory showing which systems send which event types to central logging or SIEM; Configuration evidence that logs are tamper-protected (append-only storage, hashing, restricted deletion) and that administrators cannot erase their own activity; SIEM correlation rules, use cases and alert tuning records, and evidence of regular log review |
| A.8.16 ISO/IEC 27001:2022 | Monitoring activities Networks, systems and applications are to be monitored for anomalous behaviour, with appropriate steps taken to evaluate possible information security incidents. Purpose (stated in ISO/IEC 27002:2022): spots abnormal behaviour and possible security incidents. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.16. evidence an assessor asks for Statement of Applicability entry for control A.8.16, showing inclusion or justified exclusion, implementation status and the risks it treats; A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods; Baselines of normal behaviour for systems and user groups, and the detection rules built on them; Alerting configuration with thresholds and evidence of tuning to reduce false positives; Monitoring team rota or SOC arrangement with trained staff and redundant alert channels |
There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.5.24 ISO/IEC 27001:2022 | Information security incident management planning and preparation The organization is to prepare for handling information security incidents by defining, setting up and communicating how incidents are managed and who does what. Purpose (stated in ISO/IEC 27002:2022): makes incident handling fast, effective, consistent and orderly, including how events are communicated. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.24. evidence an assessor asks for Statement of Applicability entry for control A.5.24, showing inclusion or justified exclusion, implementation status and the risks it treats; An approved incident management plan and procedures covering evaluation, detection, classification, escalation, recovery, communication, evidence handling and post-incident review; Incident management objectives and priorities agreed with management, including resolution time frames by severity; A roles and responsibilities document for the incident team and its communication to internal and external parties; Training, certification and exercise records for incident responders |
| A.5.26 ISO/IEC 27001:2022 | Response to information security incidents Incidents are to be handled following the documented response procedures. Purpose (stated in ISO/IEC 27002:2022): ensures incidents are responded to efficiently and effectively. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.26. evidence an assessor asks for Statement of Applicability entry for control A.5.26, showing inclusion or justified exclusion, implementation status and the risks it treats; Documented incident response procedures or playbooks communicated to relevant parties; Incident records showing containment, evidence collection, escalation, communication and formal closure; Response activity logs or ticket histories kept for later analysis; Communication records to internal and external parties following need-to-know |
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.7 ISO/IEC 27001:2022 | Protection against malware Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7. evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date |
Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.7 ISO/IEC 27001:2022 | Protection against malware Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7. evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date |
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.6.3 ISO/IEC 27001:2022 | Information security awareness, education and training The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose (stated in ISO/IEC 27002:2022): makes staff and relevant outside parties know and carry out their security duties. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.3. evidence an assessor asks for Statement of Applicability entry for control A.6.3, showing inclusion or justified exclusion, implementation status and the risks it treats; A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers; Assessment results testing understanding at the end of training activities; Awareness materials across channels covering management commitment, obligations, accountability, event reporting and baseline controls |
Laptops, phones and removable media that hold sensitive data are encrypted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.24 ISO/IEC 27001:2022 | Use of cryptography The organization is to define and apply rules for using cryptography effectively, key management included. Purpose (stated in ISO/IEC 27002:2022): makes cryptography work correctly to keep information confidential, genuine or unaltered as business, security and legal needs require. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.24. evidence an assessor asks for Statement of Applicability entry for control A.8.24, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification; Key management procedures covering generation, distribution, storage, rotation, revocation, recovery, backup, destruction and activation periods; Key inventory or HSM and key management service records with logs of key management activity; Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy |
IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.5.19 ISO/IEC 27001:2022 | Information security in supplier relationships The organization is to define and run processes and procedures that manage the information security risks arising from using suppliers' products or services. Purpose (stated in ISO/IEC 27002:2022): keeps security in supplier dealings at the level agreed with the supplier. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.19. evidence an assessor asks for Statement of Applicability entry for control A.5.19, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access; Supplier due diligence and selection records such as questionnaires, certifications, references and on-site assessment reports, scaled to sensitivity; Supplier risk assessments covering misuse of organizational assets and product or component vulnerabilities |
| A.5.20 ISO/IEC 27001:2022 | Addressing information security within supplier agreements The information security requirements that matter for each supplier are to be set and agreed with that supplier, depending on the type of relationship. Purpose (stated in ISO/IEC 27002:2022): makes the agreed security level for each supplier binding through written terms. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.20. evidence an assessor asks for Statement of Applicability entry for control A.5.20, showing inclusion or justified exclusion, implementation status and the risks it treats; Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms; A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed; Minimum security requirement templates per information type and access type used as the basis for individual contracts; Supplier-provided attestations or independent control effectiveness reports and records of issues raised and corrected |
Questions
- When does ISO/IEC 27001:2022 apply here?
- An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
- Which edition is held?
- ISO/IEC 27001:2022, Annex A
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.