ISO/IEC 27001:2022: the evidence behind every control
98 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
Organizational controls
A.5.1Policies for information security hardA.5.2Information security roles and responsibilities hardA.5.3Segregation of duties hardA.5.4Management responsibilities hardA.5.5Contact with authorities hardA.5.6Contact with special interest groups hardA.5.7Threat intelligence moderateA.5.8Information security in project management hardA.5.9Inventory of information and other associated assets moderateA.5.10Acceptable use of information and other associated assets moderateA.5.11Return of assets moderateA.5.12Classification of information hardA.5.13Labelling of information hardA.5.14Information transfer moderateA.5.15Access control hardA.5.16Identity management moderateA.5.17Authentication information moderateA.5.18Access rights hardA.5.19Information security in supplier relationships moderateA.5.20Addressing information security within supplier agreements hardA.5.21Managing information security in the ICT supply chain hardA.5.22Monitoring, review and change management of supplier services hardA.5.23Information security for use of cloud services moderateA.5.24Information security incident management planning and preparation hardA.5.25Assessment and decision on information security events hardA.5.26Response to information security incidents hardA.5.27Learning from information security incidents hardA.5.28Collection of evidence moderateA.5.29Information security during disruption hardA.5.30ICT readiness for business continuity hardA.5.31Legal, statutory, regulatory and contractual requirements hardA.5.32Intellectual property rights hardA.5.33Protection of records moderateA.5.34Privacy and protection of personal identifiable information (PII) hardA.5.35Independent review of information security hardA.5.36Compliance with policies, rules and standards for information security hardA.5.37Documented operating procedures moderatePeople controls
A.6.1Screening hardA.6.2Terms and conditions of employment hardA.6.3Information security awareness, education and training hardA.6.4Disciplinary process hardA.6.5Responsibilities after termination or change of employment hardA.6.6Confidentiality or non-disclosure agreements hardA.6.7Remote working moderateA.6.8Information security event reporting moderatePhysical controls
A.7.1Physical security perimeters hardA.7.2Physical entry hardA.7.3Securing offices, rooms and facilities hardA.7.4Physical security monitoring hardA.7.5Protecting against physical and environmental threats moderateA.7.6Working in secure areas hardA.7.7Clear desk and clear screen hardA.7.8Equipment siting and protection moderateA.7.9Security of assets off-premises hardA.7.10Storage media hardA.7.11Supporting utilities hardA.7.12Cabling security hardA.7.13Equipment maintenance moderateA.7.14Secure disposal or re-use of equipment hardTechnological controls
A.8.1User end point devices moderateA.8.2Privileged access rights moderateA.8.3Information access restriction hardA.8.4Access to source code moderateA.8.5Secure authentication moderateA.8.6Capacity management easyA.8.7Protection against malware hardA.8.8Management of technical vulnerabilities moderateA.8.9Configuration management moderateA.8.10Information deletion moderateA.8.11Data masking hardA.8.12Data leakage prevention hardA.8.13Information backup moderateA.8.14Redundancy of information processing facilities hardA.8.15Logging easyA.8.16Monitoring activities easyA.8.17Clock synchronization moderateA.8.18Use of privileged utility programs moderateA.8.19Installation of software on operational systems moderateA.8.20Networks security moderateA.8.21Security of network services hardA.8.22Segregation of networks moderateA.8.23Web filtering moderateA.8.24Use of cryptography hardA.8.25Secure development life cycle hardA.8.26Application security requirements hardA.8.27Secure system architecture and engineering principles hardA.8.28Secure coding hardA.8.29Security testing in development and acceptance hardA.8.30Outsourced development hardA.8.31Separation of development, test and production environments hardA.8.32Change management moderateA.8.33Test information hardA.8.34Protection of information systems during audit testing moderate