ISO 27001 Annex A Controls
95
- Understanding the ISO 27001 Structure
- ISO/IEC 27001 Step-by-Step Implementation Guide
- A5.1: Policies for Information Security
- A5.2: Information Security Roles and Responsibilities
- A5.3: Segregation of Duties
- A5.4: Management Responsibilities
- A5.5: Contact with Authorities
- A5.6: Contact with Special Interest Groups
- A5.7: Threat Intelligence
- A5.8: Information Security in Project Management
ISO 27001 A.5 Organizational Controls
37
- A5.1: Policies for Information Security
- A5.2: Information Security Roles and Responsibilities
- A5.3: Segregation of Duties
- A5.5: Contact with Authorities
- A5.6: Contact with Special Interest Groups
- A5.7: Threat Intelligence
- A5.8: Information Security in Project Management
- A5.9: Inventory of Information and Other Associated Assets
- A5.10: Acceptable Use of Information and Other Associated Assets
- A5.11: Return of Assets
ISO 27001 A.6 People Controls
9
- A6.1 Screening
- A6.2 Terms and conditions of employment
- A6.3 Information security awareness, education and training
- A6.4 Disciplinary Process
- A6.5 Responsibilities after termination or change of employment
- A6.6 Confidentiality or non-disclosure agreements
- A6.7 Remote working
- A6.8 Information security event reporting
- A.6 People Controls
ISO 27001 A.7 Physical Controls
15
- A7.1 Physical security Perimeter
- A7.2 Physical entry
- A7.3 Securing offices, rooms and facilities
- A7.4 Physical security monitoring
- A7.5 Protecting against physical and environmental threats
- A7.6 Working in secure areas
- A7.7 Clear desk and clear screen
- A7.8 Equipment siting and protection
- A7.9 Security of assets off-premises
- A7.10 Storage media
ISO 27001 A.8 Technological Controls
35
- A8.1 User end point devices
- A8.2 Privileged access rights
- A8.3 Information access restriction
- A8.4 Access to source code
- A8.5 Secure authentication
- A8.6 Capacity management
- A8.7 Protection against malware
- A8.8 Management of technical vulnerabilities
- A8.9 Configuration management
- A8.10 Information Deletion