EvidenceSheet

ISO/IEC 27002:2022: the evidence behind every control

93 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

Organizational controls

5.1Policies for information security hard5.2Information security roles and responsibilities hard5.3Segregation of duties hard5.4Management responsibilities hard5.5Contact with authorities hard5.6Contact with special interest groups hard5.7Threat intelligence hard5.8Information security in project management hard5.9Inventory of information and other associated assets hard5.10Acceptable use of information and other associated assets hard5.11Return of assets hard5.12Classification of information hard5.13Labelling of information hard5.14Information transfer hard5.15Access control hard5.16Identity management hard5.17Authentication information moderate5.18Access rights hard5.19Information security in supplier relationships hard5.20Addressing information security within supplier agreements hard5.21Managing information security in the ICT supply chain hard5.22Monitoring, review and change management of supplier services hard5.23Information security for use of cloud services hard5.24Information security incident management planning and preparation hard5.25Assessment and decision on information security events hard5.26Response to information security incidents hard5.27Learning from information security incidents hard5.28Collection of evidence hard5.29Information security during disruption hard5.30ICT readiness for business continuity hard5.31Legal, statutory, regulatory and contractual requirements hard5.32Intellectual property rights hard5.33Protection of records hard5.34Privacy and protection of PII hard5.35Independent review of information security hard5.36Compliance with policies, rules and standards for information security hard5.37Documented operating procedures hard

People controls

6.1Screening hard6.2Terms and conditions of employment hard6.3Information security awareness, education and training hard6.4Disciplinary process hard6.5Responsibilities after termination or change of employment hard6.6Confidentiality or non-disclosure agreements hard6.7Remote working hard6.8Information security event reporting hard

Physical controls

7.1Physical security perimeters hard7.2Physical entry hard7.3Securing offices, rooms and facilities hard7.4Physical security monitoring easy7.5Protecting against physical and environmental threats hard7.6Working in secure areas hard7.7Clear desk and clear screen hard7.8Equipment siting and protection hard7.9Security of assets off-premises hard7.10Storage media hard7.11Supporting utilities hard7.12Cabling security hard7.13Equipment maintenance hard7.14Secure disposal or re-use of equipment hard

Technological controls

8.1User endpoint devices hard8.2Privileged access rights hard8.3Information access restriction hard8.4Access to source code hard8.5Secure authentication moderate8.6Capacity management moderate8.7Protection against malware moderate8.8Management of technical vulnerabilities moderate8.9Configuration management moderate8.10Information deletion hard8.11Data masking hard8.12Data leakage prevention hard8.13Information backup moderate8.14Redundancy of information processing facilities hard8.15Logging easy8.16Monitoring activities easy8.17Clock synchronization moderate8.18Use of privileged utility programs hard8.19Installation of software on operational systems hard8.20Networks security hard8.21Security of network services hard8.22Segregation of networks hard8.23Web filtering hard8.24Use of cryptography hard8.25Secure development life cycle hard8.26Application security requirements moderate8.27Secure system architecture and engineering principles hard8.28Secure coding hard8.29Security testing in development and acceptance hard8.30Outsourced development hard8.31Separation of development, test and production environments hard8.32Change management hard8.33Test information hard8.34Protection of information systems during audit testing hard