Framework

ISO/IEC 27001:2022

ISO/IEC 27001:2022 Annex A

93 requirements · 78 connected unified controls

Open ISO/IEC 27001:2022 in the map
Version
2022
Published
2022-10-25
Amendments
Amd 1:2024

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Organizational controls

RequirementUnified control and mapping
A.5.1Policies for information security
UC-GOV-14 — Establish and maintain approved security policies and proceduresPartial

Remaining requirement: Policies must also be acknowledged by relevant personnel and interested parties

A.5.2Information security roles and responsibilities
A.5.3Segregation of duties
A.5.4Management responsibilities
A.5.5Contact with authorities
A.5.6Contact with special interest groups
A.5.7Threat intelligence
A.5.8Information security in project management
A.5.9Inventory of information and other associated assets
UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and softwarePartial

Remaining requirement: inventorying information (data) assets themselves, addressed by the data-inventory control

A.5.10Acceptable use of information and other associated assets
A.5.11Return of assets
A.5.12Classification of information
A.5.13Labelling of information
A.5.14Information transfer
A.5.15Access control
UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of dutiesPartial

Remaining requirement: also requires rules controlling physical access to information and assets

A.5.16Identity management
A.5.17Authentication information
UC-ACCESS-08 — Manage and protect authenticators across their lifecyclePartial

Remaining requirement: advising personnel on proper handling and protection of authentication information

A.5.18Access rights
UC-ACCESS-02 — Review user access rights periodicallyPartial

Remaining requirement: provisioning, adjustment, and revocation satisfied by the account lifecycle control

A.5.19Information security in supplier relationships
A.5.20Addressing information security within supplier agreements
UC-HR-05 — Hold third-party personnel to equivalent security termsPartial

Remaining requirement: broader supplier security terms addressed under third-party risk domain

A.5.21Managing information security in the ICT supply chain
UC-TPRM-07 — Verify component authenticity, provenance, and integrityPartial

Remaining requirement: propagation of security requirements through the ICT supply chain via contract control

A.5.22Monitoring, review and change management of supplier services
A.5.23Information security for use of cloud services
A.5.24Information security incident management planning and preparation
A.5.25Assessment and decision on information security events
A.5.26Response to information security incidents
A.5.27Learning from information security incidents
A.5.28Collection of evidence
A.5.29Information security during disruption
A.5.30ICT readiness for business continuity
UC-BCDR-01 — Maintain business continuity and disaster recovery plansPartial

Remaining requirement: periodic ICT readiness testing satisfied by the testing control

A.5.31Legal, statutory, regulatory and contractual requirements
A.5.32Intellectual property rights
UC-AUDIT-24 — Manage compliance with external legal and regulatory requirementsPartial

Remaining requirement: operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation

A.5.33Protection of records
A.5.34Privacy and protection of personal identifiable information (PII)
A.5.35Independent review of information security
A.5.36Compliance with policies, rules and standards for information security
A.5.37Documented operating procedures

People controls

Physical controls

RequirementUnified control and mapping
A.7.1Physical security perimeters
A.7.2Physical entry
A.7.3Securing offices, rooms and facilities
A.7.4Physical security monitoring
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment

Technological controls

RequirementUnified control and mapping
A.8.1User endpoint devices
A.8.2Privileged access rights
A.8.3Information access restriction
A.8.4Access to source code
A.8.5Secure authentication
A.8.6Capacity management
A.8.7Protection against malware
A.8.8Management of technical vulnerabilities
UC-VULN-03 — Remediate identified flaws within defined timeframesPartial

Remaining requirement: also requires obtaining vulnerability intelligence and evaluating exposure

A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.13Information backup
A.8.14Redundancy of information processing facilities
A.8.15Logging
UC-LOG-01 — Log security-relevant events across all systemsPartial

Remaining requirement: also requires protecting, storing, and analysing produced logs

A.8.16Monitoring activities
A.8.17Clock synchronization
A.8.18Use of privileged utility programs
A.8.19Installation of software on operational systems
A.8.20Networks security
A.8.21Security of network services
A.8.22Segregation of networks
A.8.23Web filtering
A.8.24Use of cryptography
UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modulesPartial

Remaining requirement: key management rules satisfied by the key lifecycle control

A.8.25Secure development life cycle
A.8.26Application security requirements
A.8.27Secure system architecture and engineering principles
A.8.28Secure coding
A.8.29Security testing in development and acceptance
A.8.30Outsourced development
A.8.31Separation of development, test and production environments
A.8.32Change management
A.8.33Test information
A.8.34Protection of information systems during audit testing