Framework
ISO/IEC 27001:2022
ISO/IEC 27001:2022 Annex A
93 requirements · 78 connected unified controls
Open ISO/IEC 27001:2022 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Organizational controls
People controls
| Requirement | Unified control and mapping |
|---|---|
| A.6.1Screening | |
| A.6.2Terms and conditions of employment | |
| A.6.3Information security awareness, education and training | |
| A.6.4Disciplinary process | |
| A.6.5Responsibilities after termination or change of employment | |
| A.6.6Confidentiality or non-disclosure agreements | UC-HR-02 — Formalize security responsibilities in employment termsPartial Remaining requirement: NDAs from external/other interested parties, addressed by the third-party personnel control |
| A.6.7Remote working | |
| A.6.8Information security event reporting |
Physical controls
| Requirement | Unified control and mapping |
|---|---|
| A.7.1Physical security perimeters | |
| A.7.2Physical entry | |
| A.7.3Securing offices, rooms and facilities | |
| A.7.4Physical security monitoring | |
| A.7.5Protecting against physical and environmental threats | |
| A.7.6Working in secure areas | |
| A.7.7Clear desk and clear screen | |
| A.7.8Equipment siting and protection | |
| A.7.9Security of assets off-premises | |
| A.7.10Storage media | |
| A.7.11Supporting utilities | |
| A.7.12Cabling security | |
| A.7.13Equipment maintenance | |
| A.7.14Secure disposal or re-use of equipment |