Controls
Control-level reference pages with implementation notes, evidence checklists, and cross-framework mappings.
- ISO 27001A.5.1
Policies for information security · ISO 27001 · A.5
- ISO 27001A.5.2
Information security roles and responsibilities · ISO 27001 · A.5
- ISO 27001A.5.3
Segregation of duties · ISO 27001 · A.5
- ISO 27001A.5.4
Management responsibilities · ISO 27001 · A.5
- ISO 27001A.5.5
Contact with authorities · ISO 27001 · A.5
- ISO 27001A.5.6
Contact with special interest groups · ISO 27001 · A.5
- ISO 27001A.5.7
Threat intelligence · ISO 27001 · A.5
- ISO 27001A.5.8
Information security in project management · ISO 27001 · A.5
- ISO 27001A.5.9
Inventory of information and other assets · ISO 27001 · A.5
- ISO 27001A.5.10
Acceptable use of information and other assets · ISO 27001 · A.5
- ISO 27001A.5.11
Return of assets · ISO 27001 · A.5
- ISO 27001A.5.12
Classification of information · ISO 27001 · A.5
- ISO 27001A.5.13
Labelling of information · ISO 27001 · A.5
- ISO 27001A.5.14
Information transfer · ISO 27001 · A.5
- ISO 27001A.5.15
Access control · ISO 27001 · A.5
- ISO 27001A.5.16
Identity management · ISO 27001 · A.5
- ISO 27001A.5.17
Authentication information · ISO 27001 · A.5
- ISO 27001A.5.18
Access rights · ISO 27001 · A.5
- ISO 27001A.5.19
Information security in supplier relationships · ISO 27001 · A.5
- ISO 27001A.5.20
Addressing information security within supplier agreements · ISO 27001 · A.5
- ISO 27001A.5.21
Managing information security in the ICT supply chain · ISO 27001 · A.5
- ISO 27001A.5.22
Monitoring, review and change management of supplier services · ISO 27001 · A.5
- ISO 27001A.5.23
Information security for use of cloud services · ISO 27001 · A.5
- ISO 27001A.5.24
Information security incident management planning and preparation · ISO 27001 · A.5
- ISO 27001A.5.25
Assessment and decision on information security events · ISO 27001 · A.5
- ISO 27001A.5.26
Response to information security incidents · ISO 27001 · A.5
- ISO 27001A.5.27
Learning from information security incidents · ISO 27001 · A.5
- ISO 27001A.5.28
Collection of evidence · ISO 27001 · A.5
- ISO 27001A.5.29
Information security during disruption · ISO 27001 · A.5
- ISO 27001A.5.30
ICT readiness for business continuity · ISO 27001 · A.5
- ISO 27001A.5.31
Legal, statutory, regulatory and contractual requirements · ISO 27001 · A.5
- ISO 27001A.5.32
Intellectual property rights · ISO 27001 · A.5
- ISO 27001A.5.33
Protection of records · ISO 27001 · A.5
- ISO 27001A.5.34
Privacy and protection of PII · ISO 27001 · A.5
- ISO 27001A.5.35
Independent review of information security · ISO 27001 · A.5
- ISO 27001A.5.36
Compliance with policies, rules and standards for information security · ISO 27001 · A.5
- ISO 27001A.5.37
Documented operating procedures · ISO 27001 · A.5
- ISO 27001A.6.1
Screening · ISO 27001 · A.6
- ISO 27001A.6.2
Terms and conditions of employment · ISO 27001 · A.6
- ISO 27001A.6.3
Information security awareness, education and training · ISO 27001 · A.6
- ISO 27001A.6.4
Disciplinary process · ISO 27001 · A.6
- ISO 27001A.7.1
Physical security perimeters · ISO 27001 · A.7
- ISO 27001A.7.2
Physical entry · ISO 27001 · A.7
- ISO 27001A.7.3
Securing offices, rooms and facilities · ISO 27001 · A.7
- ISO 27001A.7.4
Physical security monitoring · ISO 27001 · A.7
- ISO 27001A.8.2
Privileged access rights · ISO 27001 · A.8
- ISO 27001A.8.3
Information access restriction · ISO 27001 · A.8
- ISO 27001A.8.5
Secure authentication · ISO 27001 · A.8
- ISO 27001A.8.7
Protection against malware · ISO 27001 · A.8
- ISO 27001A.8.8
Management of technical vulnerabilities · ISO 27001 · A.8
- ISO 27001A.8.9
Configuration management · ISO 27001 · A.8
- ISO 27001A.8.10
Information deletion · ISO 27001 · A.8
- ISO 27001A.8.15
Logging · ISO 27001 · A.8
- ISO 27001A.8.16
Monitoring activities · ISO 27001 · A.8
- ISO 27001A.8.20
Networks security · ISO 27001 · A.8
- ISO 27001A.8.24
Use of cryptography · ISO 27001 · A.8
- ISO 27001A.8.25
Secure development life cycle · ISO 27001 · A.8
- ISO 27001A.8.26
Application security requirements · ISO 27001 · A.8
- ISO 27001A.8.27
Secure system architecture and engineering principles · ISO 27001 · A.8
- ISO 27001A.8.28
Secure coding · ISO 27001 · A.8
- ISO 27001A.8.29
Security testing in development and acceptance · ISO 27001 · A.8
- ISO 27001A.8.32
Change management · ISO 27001 · A.8
- GDPRArticle 6
Lawfulness of processing · GDPR · Chapter II
- GDPRArticle 25
Data protection by design and by default · GDPR · Chapter IV
- GDPRArticle 28
Processor · GDPR · Chapter IV
- GDPRArticle 32
Security of processing · GDPR · Chapter IV
- GDPRArticle 33
Notification of a personal data breach to the supervisory authority · GDPR · Chapter IV
- SOC 2CC6.1
Logical and Physical Access Controls · SOC 2 · CC6
- SOC 2CC6.2
Prior to Issuing System Credentials · SOC 2 · CC6
- SOC 2CC6.3
Removes Access When Appropriate · SOC 2 · CC6
- SOC 2CC6.4
Restricts Access to Physical Assets · SOC 2 · CC6
- SOC 2CC6.5
Discontinues Physical Access · SOC 2 · CC6
- SOC 2CC6.6
Limits Access to System Components · SOC 2 · CC6
- SOC 2CC6.7
Restricts Transmission of Information · SOC 2 · CC6
- SOC 2CC6.8
Prevents Unauthorized Software · SOC 2 · CC6
- SOC 2CC7.1
Detection of Security Vulnerabilities · SOC 2 · CC7
- SOC 2CC7.2
Monitoring of System Components · SOC 2 · CC7
- SOC 2CC7.3
Evaluation of Security Events · SOC 2 · CC7
- SOC 2CC7.4
Response to Security Incidents · SOC 2 · CC7
- SOC 2CC7.5
Recovery from Security Incidents · SOC 2 · CC7
- SOC 2CC8.1
Change Management · SOC 2 · CC8