ISO 27001A.8 — Management of technical vulnerabilities
A.8.8
Management of technical vulnerabilities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Obtain information about technical vulnerabilities, evaluate exposure, and take appropriate measures.
Points of focus
- Define scope and requirements for management of technical vulnerabilities
- Assign ownership and operating cadence
- Integrate with risk treatment and SoA status
- Retain dated records proving operation
Implementation notes
Scan, prioritize by exploitability and asset criticality, patch or mitigate within SLAs, and record exceptions with owners. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.
Audit tip: Present the SoA line for A.8.8, the current procedure, and one recent dated operating sample with a named owner.
Evidence auditors typically request:
- System configuration export or IaC policy screenshots
- Ticket samples with approver, date, and change outcome
- Monitoring or scan report covering the observation window
- Runbook or SOP linked from the SoA implementation summary
Common gaps
- SoA marks management of technical vulnerabilities applicable without dated operating samples
- Procedure exists but interviews describe a different tribal process
- Owner unclear or last review older than the stated cadence
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.8 | This control |
| SOC 2 | CC7.1 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.8)
Frequently Asked Questions
Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.
Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.
Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.