Skip to content
compliancebase

Controls

Control-level reference pages with implementation notes, evidence checklists, and cross-framework mappings.

  • ISO 27001A.5.1

    Policies for information security · ISO 27001 · A.5

  • ISO 27001A.5.2

    Information security roles and responsibilities · ISO 27001 · A.5

  • ISO 27001A.5.3

    Segregation of duties · ISO 27001 · A.5

  • ISO 27001A.5.4

    Management responsibilities · ISO 27001 · A.5

  • ISO 27001A.5.5

    Contact with authorities · ISO 27001 · A.5

  • ISO 27001A.5.6

    Contact with special interest groups · ISO 27001 · A.5

  • ISO 27001A.5.7

    Threat intelligence · ISO 27001 · A.5

  • ISO 27001A.5.8

    Information security in project management · ISO 27001 · A.5

  • ISO 27001A.5.9

    Inventory of information and other assets · ISO 27001 · A.5

  • ISO 27001A.5.10

    Acceptable use of information and other assets · ISO 27001 · A.5

  • ISO 27001A.5.11

    Return of assets · ISO 27001 · A.5

  • ISO 27001A.5.12

    Classification of information · ISO 27001 · A.5

  • ISO 27001A.5.13

    Labelling of information · ISO 27001 · A.5

  • ISO 27001A.5.14

    Information transfer · ISO 27001 · A.5

  • ISO 27001A.5.15

    Access control · ISO 27001 · A.5

  • ISO 27001A.5.16

    Identity management · ISO 27001 · A.5

  • ISO 27001A.5.17

    Authentication information · ISO 27001 · A.5

  • ISO 27001A.5.18

    Access rights · ISO 27001 · A.5

  • ISO 27001A.5.19

    Information security in supplier relationships · ISO 27001 · A.5

  • ISO 27001A.5.20

    Addressing information security within supplier agreements · ISO 27001 · A.5

  • ISO 27001A.5.21

    Managing information security in the ICT supply chain · ISO 27001 · A.5

  • ISO 27001A.5.22

    Monitoring, review and change management of supplier services · ISO 27001 · A.5

  • ISO 27001A.5.23

    Information security for use of cloud services · ISO 27001 · A.5

  • ISO 27001A.5.24

    Information security incident management planning and preparation · ISO 27001 · A.5

  • ISO 27001A.5.25

    Assessment and decision on information security events · ISO 27001 · A.5

  • ISO 27001A.5.26

    Response to information security incidents · ISO 27001 · A.5

  • ISO 27001A.5.27

    Learning from information security incidents · ISO 27001 · A.5

  • ISO 27001A.5.28

    Collection of evidence · ISO 27001 · A.5

  • ISO 27001A.5.29

    Information security during disruption · ISO 27001 · A.5

  • ISO 27001A.5.30

    ICT readiness for business continuity · ISO 27001 · A.5

  • ISO 27001A.5.31

    Legal, statutory, regulatory and contractual requirements · ISO 27001 · A.5

  • ISO 27001A.5.32

    Intellectual property rights · ISO 27001 · A.5

  • ISO 27001A.5.33

    Protection of records · ISO 27001 · A.5

  • ISO 27001A.5.34

    Privacy and protection of PII · ISO 27001 · A.5

  • ISO 27001A.5.35

    Independent review of information security · ISO 27001 · A.5

  • ISO 27001A.5.36

    Compliance with policies, rules and standards for information security · ISO 27001 · A.5

  • ISO 27001A.5.37

    Documented operating procedures · ISO 27001 · A.5

  • ISO 27001A.6.1

    Screening · ISO 27001 · A.6

  • ISO 27001A.6.2

    Terms and conditions of employment · ISO 27001 · A.6

  • ISO 27001A.6.3

    Information security awareness, education and training · ISO 27001 · A.6

  • ISO 27001A.6.4

    Disciplinary process · ISO 27001 · A.6

  • ISO 27001A.7.1

    Physical security perimeters · ISO 27001 · A.7

  • ISO 27001A.7.2

    Physical entry · ISO 27001 · A.7

  • ISO 27001A.7.3

    Securing offices, rooms and facilities · ISO 27001 · A.7

  • ISO 27001A.7.4

    Physical security monitoring · ISO 27001 · A.7

  • ISO 27001A.8.2

    Privileged access rights · ISO 27001 · A.8

  • ISO 27001A.8.3

    Information access restriction · ISO 27001 · A.8

  • ISO 27001A.8.5

    Secure authentication · ISO 27001 · A.8

  • ISO 27001A.8.7

    Protection against malware · ISO 27001 · A.8

  • ISO 27001A.8.8

    Management of technical vulnerabilities · ISO 27001 · A.8

  • ISO 27001A.8.9

    Configuration management · ISO 27001 · A.8

  • ISO 27001A.8.10

    Information deletion · ISO 27001 · A.8

  • ISO 27001A.8.15

    Logging · ISO 27001 · A.8

  • ISO 27001A.8.16

    Monitoring activities · ISO 27001 · A.8

  • ISO 27001A.8.20

    Networks security · ISO 27001 · A.8

  • ISO 27001A.8.24

    Use of cryptography · ISO 27001 · A.8

  • ISO 27001A.8.25

    Secure development life cycle · ISO 27001 · A.8

  • ISO 27001A.8.26

    Application security requirements · ISO 27001 · A.8

  • ISO 27001A.8.27

    Secure system architecture and engineering principles · ISO 27001 · A.8

  • ISO 27001A.8.28

    Secure coding · ISO 27001 · A.8

  • ISO 27001A.8.29

    Security testing in development and acceptance · ISO 27001 · A.8

  • ISO 27001A.8.32

    Change management · ISO 27001 · A.8

  • Lawfulness of processing · GDPR · Chapter II

  • Data protection by design and by default · GDPR · Chapter IV

  • Processor · GDPR · Chapter IV

  • Security of processing · GDPR · Chapter IV

  • Notification of a personal data breach to the supervisory authority · GDPR · Chapter IV

  • SOC 2CC6.1

    Logical and Physical Access Controls · SOC 2 · CC6

  • SOC 2CC6.2

    Prior to Issuing System Credentials · SOC 2 · CC6

  • SOC 2CC6.3

    Removes Access When Appropriate · SOC 2 · CC6

  • SOC 2CC6.4

    Restricts Access to Physical Assets · SOC 2 · CC6

  • SOC 2CC6.5

    Discontinues Physical Access · SOC 2 · CC6

  • SOC 2CC6.6

    Limits Access to System Components · SOC 2 · CC6

  • SOC 2CC6.7

    Restricts Transmission of Information · SOC 2 · CC6

  • SOC 2CC6.8

    Prevents Unauthorized Software · SOC 2 · CC6

  • SOC 2CC7.1

    Detection of Security Vulnerabilities · SOC 2 · CC7

  • SOC 2CC7.2

    Monitoring of System Components · SOC 2 · CC7

  • SOC 2CC7.3

    Evaluation of Security Events · SOC 2 · CC7

  • SOC 2CC7.4

    Response to Security Incidents · SOC 2 · CC7

  • SOC 2CC7.5

    Recovery from Security Incidents · SOC 2 · CC7

  • SOC 2CC8.1

    Change Management · SOC 2 · CC8