workflow
ISO 27001 Stage 2 Annex A Controls Audit
Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- domains
- audit
- standards
- iso-27001
- sourceTemplateId
- workflow-library:audit-iso27001-stage2-controls-audit
- releaseId
- sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae
- canonicalUrl
- https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-ACCESS-02
- UC-ACCESS-03
- UC-ACCESS-04
- UC-ACCESS-05
- UC-ACCESS-06
- UC-ACCESS-08
- UC-ACCESS-09
- UC-ACCESS-18
- UC-ASSET-01
- UC-ASSET-03
- UC-ASSET-04
- UC-ASSET-06
- UC-ASSET-07
- UC-ASSET-08
- UC-AUDIT-23
- UC-AUDIT-24
- UC-AUDIT-25
- UC-BCDR-01
- UC-BCDR-03
- UC-BCDR-04
- UC-CONFIG-01
- UC-CONFIG-02
- UC-CONFIG-03
- UC-CONFIG-05
- UC-CRYPTO-02
- UC-DATA-09
- UC-DATA-11
- UC-DATA-12
- UC-DATA-13
- UC-GOV-03
- UC-GOV-06
- UC-GOV-07
- UC-GOV-08
- UC-GOV-14
- UC-GOV-22
- UC-GOV-23
- UC-HR-01
- UC-HR-02
- UC-HR-03
- UC-HR-04
- UC-HR-05
- UC-HR-07
- UC-IR-01
- UC-IR-03
- UC-IR-04
- UC-IR-06
- UC-IR-07
- UC-IR-10
- UC-LOG-01
- UC-LOG-02
- UC-LOG-04
- UC-LOG-08
- UC-NET-01
- UC-NET-13
- UC-PHYS-01
- UC-PHYS-02
- UC-PHYS-03
- UC-PHYS-04
- UC-PHYS-05
- UC-PHYS-06
- UC-PHYS-08
- UC-PHYS-09
- UC-RISK-02
- UC-RISK-17
- UC-SDLC-01
- UC-SDLC-03
- UC-SDLC-04
- UC-SDLC-05
- UC-SDLC-10
- UC-SDLC-14
- UC-TPRM-01
- UC-TPRM-04
- UC-TPRM-07
- UC-TPRM-08
- UC-TRAIN-01
- UC-VULN-03
- UC-VULN-04
- UC-VULN-05
- roleIntegrity
- activityCount
- 5
- ermPhases
- assess
- report
- lineRoles
- third
- serviceModes
- assurance
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- competence
- recency
- nodeIds
- approve-annex-a-conclusion
- assess-organizational-controls
- assess-people-controls
- assess-physical-controls
- assess-technological-controls
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-02 — Review user access rights periodically
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-01 — Operate a third-party security risk management program
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-02 — Monitor physical access and retain visitor and entry records
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-06 — Manage unique identities and identifiers end to end
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-NET-01 — Segment networks and defend the external boundary
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-12 — De-identify, mask, or pseudonymize personal data
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-07 — Hold individuals accountable for control responsibilities
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-05 — Provide emergency power, lighting, and resilient utilities
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-03 — Provide channels to report events and obtain response help
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-08 — Transfer information securely under defined rules and agreements
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-07 — Manage assets through their life cycle and recover them at exit
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-04 — Control storage media through use, storage, and destruction
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-08 — Secure and monitor networks and network services
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-02 — Record complete audit content with synchronized clocks
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-BCDR-01 — Maintain business continuity and disaster recovery plans
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-01 — Restrict physical access to facilities and secure areas
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-05 — Hold third-party personnel to equivalent security terms
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-01 — Log security-relevant events across all systems
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TRAIN-01 — Deliver security awareness training to all personnel
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-10 — Learn from incidents and communicate corrective actions
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-11 — Control data flows, leakage, and cross-border transfers
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-01 — Screen personnel commensurate with position risk
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-01 — Follow a secure development lifecycle with approval gates
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-03 — Protect facilities against fire, water, and environmental hazards
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-04 — Monitor vendor performance, services, and risk
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-VULN-04 — Test software security during development and acceptance
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-04 — Triage, categorize, and escalate reported security events
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-02 — Formalize security responsibilities in employment terms
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-22 — Assess control effectiveness and authorize systems
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-NET-13 — Control mobile code and web content
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-07 — Investigate incidents and preserve evidence and records
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-01 — Maintain an approved incident response plan
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-10 — Oversee outsourced development and vet developers
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-04 — Engineer systems with secure architecture and design
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-03 — Secure termination and transfer of personnel
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-BCDR-03 — Back up data and verify restorability
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-09 — Prevent information exposure at desks, screens, and outputs
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-RISK-17 — Operate threat intelligence and threat hunting
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-VULN-03 — Remediate identified flaws within defined timeframes
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-03 — Separate environments and protect production data in testing
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-04 — Enforce a formal disciplinary process for violations
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-05 — Enforce secure coding and input validation standards
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-08 — Maintain equipment to preserve availability and integrity
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-23 — Maintain contacts with authorities and special interest groups
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-03 — Define and approve security requirements for applications
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-05 — Enforce approved authorizations for information and functions
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-04 — Site facilities and equipment to minimize hazards and exposure
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-AUDIT-25 — Maintain quality records and information for internal control
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-13 — Safeguard personal information with reasonable security
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-BCDR-04 — Provide redundant and alternate processing, storage, and telecom
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-VULN-05 — Block malware, spam, and phishing across all systems
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-06 — Protect power and communications cabling from damage and taps
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-03 — Classify, prioritize, and label information and assets
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-RISK-02 — Integrate risk management into enterprise processes and projects
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-07 — Secure remote working arrangements
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-08 — Govern security of external and cloud service use
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-06 — Define security roles, responsibilities, and authorities
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-05 — Permit only authorized software installation and use
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-06 — Respond to, contain, and eradicate declared incidents
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-SDLC-14 — Protect production systems during audit testing
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-02 — Authorize, test, and approve changes before production