What are iso 27001 ...
 
Notifications
Clear all

What are iso 27001 controls?

1 Posts
1 Users
0 Reactions
405 Views
0
Topic starter

What are iso 27001 controls?

1 Answer
0
Topic starter

ISO 27001 controls are a set of 93 best-practice measures, detailed in Annex A of the standard, that an organization can implement to manage and reduce its information security risks. These controls are not a mandatory one-size-fits-all checklist. Instead, an organization selects the relevant controls based on the specific risks it identifies during its risk assessment process.

The Four Control Themes

The controls in the latest version of the standard (ISO 27001:2022) are grouped into four distinct themes:

1. Organizational Controls (37 controls) 🏢

These are high-level controls that establish the overall security framework and governance for the organization.

  • Examples:

    • Information security policies: Creating the foundational rules for information security.

    • Asset management: Identifying and classifying all information assets.

    • Information security in supplier relationships: Ensuring your vendors and partners also protect your data.

 

2. People Controls (8 controls) 👥

These controls focus on the human element of security, recognizing that people are often a key factor in security incidents.

  • Examples:

    • Screening: Performing background checks on new employees.

    • Information security awareness, education, and training: Regularly training staff on their security responsibilities.

    • Remote working: Establishing rules to secure information when employees work from home.

 

3. Physical Controls (14 controls) 🔒

These controls are designed to protect the physical environment where information and systems are located.

  • Examples:

    • Physical security perimeters: Securing the building with measures like fences and access gates.

    • Clear desk and clear screen policy: Requiring employees to lock away sensitive documents and lock their computers when they are away from their desks.

    • Secure disposal: Procedures for securely destroying media (like hard drives or paper files) so data cannot be recovered.

 

4. Technological Controls (34 controls) 💻

These are the technical measures implemented within IT systems and networks to protect against cyber threats.

  • Examples:

    • Access control: Limiting user access to only the information they need for their job (the principle of least privilege).

    • Cryptography: Using encryption to protect the confidentiality of data.

    • Backup: Regularly backing up information to prevent data loss.

    • Logging and monitoring: Tracking activity on systems to detect and investigate security incidents.

Share:

Log in

You dont have an account yet? Register Now