0% found this document useful (0 votes)
10 views35 pages

ANNEXA

ISO 27001:2022 Annex A outlines 93 mandatory security controls categorized into organizational, people, physical, and technological themes to enhance information security. Organizations must select and justify relevant controls based on risk assessments to maintain compliance and address modern security challenges. The controls are designed to protect sensitive information and ensure ongoing improvement of the Information Security Management System (ISMS).

Uploaded by

7svbprs4mg
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views35 pages

ANNEXA

ISO 27001:2022 Annex A outlines 93 mandatory security controls categorized into organizational, people, physical, and technological themes to enhance information security. Organizations must select and justify relevant controls based on risk assessments to maintain compliance and address modern security challenges. The controls are designed to protect sensitive information and ensure ongoing improvement of the Information Security Management System (ISMS).

Uploaded by

7svbprs4mg
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ISO 27001:2022

Important Controls
Annex A
Annex A contains 93 security controls grouped into four main themes: organizational, people,
physical, and technological, covering all aspects of information security.

Annex A is a mandatory reference for creating the Risk Treatment Plan, requiring
organizations to choose and justify relevant controls based on their risk assessments.

The controls in Annex A are updated to address modern security challenges such as cloud
security, supply chain risks, and data protection, keeping pace with evolving threats.
Annex A organizes controls into four categories for better focus and alignment:
A.5 Organizational Controls
A.6 People Controls
A.7 Physical Controls
A.8 Technological Controls

Annex A aids in maintaining and continually improving the ISMS, ensuring that
controls are regularly reviewed and updated to meet emerging risks and regulatory
requirements.
Most Used A.5
Organizational Controls
A.5.1 Policies for Information Security
Control Explanation: Organizations are required to establish an overarching information security policy that
aligns with their business objectives and regulatory obligations. This policy must be reviewed regularly and
communicated to all personnel to ensure compliance across the organization.

Use Case: A financial services company drafts a comprehensive Information Security Policy outlining how
employees must handle sensitive customer data, secure communications, and escalate security incidents.
The policy is distributed to all departments and reviewed annually to account for any regulatory changes,
such as GDPR.

Outcome: With a structured policy, the company ensures that all staff members understand and follow
proper procedures, significantly reducing the risk of data breaches and ensuring compliance with global data
protection regulations.

Key Documents: Information Security Policy, Policy Review Records.


A.5.2 Information Security Roles and
Responsibilities
Responsibilities​
Control Explanation: This control emphasizes defining and assigning security roles across the
organization. It ensures that there is clear accountability for information security activities, from
management to general employees. Security responsibilities should be reflected in job descriptions and
role-specific tasks.

Use Case: A hospital appoints a Chief Information Security Officer (CISO) to manage and oversee its
security strategy, with dedicated staff assigned to roles such as incident response managers and data
protection officers (DPOs). Each team member is trained and held accountable for maintaining specific
aspects of the hospital’s ISMS.

Outcome: Clearly defined responsibilities lead to better incident management and prevent confusion
during a security breach. The hospital's structured security roles ensure that incidents are addressed
quickly and in compliance with data protection laws like HIPAA.

Key Documents: Role Descriptions, Organizational Charts, Responsibility Matrices.


A.5.7 Threat Intelligence

Control Explanation: This control requires organizations to collect, analyze, and respond to
information security threats. Threat intelligence involves gathering data from multiple internal and
external sources to understand potential risks and adapt security measures proactively.

Use Case: A manufacturing firm subscribes to a cyber threat intelligence service that provides real-
time updates on vulnerabilities affecting their production systems. The IT team acts on this
information by applying patches to mitigate potential risks from newly discovered malware
targeting industrial control systems.

Outcome: By proactively staying informed of potential threats, the firm can protect its production
systems from cyberattacks, ensuring minimal disruption to operations and safeguarding customer
data from breaches.

Key Documents: Threat Intelligence Reports, Threat Monitoring Procedures.


A.5.9 Inventory of Information and Other
Associated Assets

Control Explanation: Organizations are required to maintain an up-to-date inventory of information and
associated assets. This control ensures that all information assets, including hardware, software, and data,
are properly classified, documented, and assigned ownership.

Use Case: A large e-commerce platform keeps an inventory of all its critical information assets, such as
databases containing customer purchase histories, payment processing servers, and encryption keys. Each
asset is assigned to a specific owner who is responsible for monitoring its security.

Outcome: A well-maintained asset inventory allows the e-commerce company to manage and secure its
assets effectively, reducing the risk of unauthorized access or loss of sensitive information.

Key Documents: Asset Registers, Classification Schemes.


A.5.12 Classification of Information

Control Explanation: This control requires organizations to classify information based on its sensitivity and
importance. Proper classification ensures that information receives the appropriate level of protection
according to its value and the risks associated with its exposure.

Use Case: A defense contractor classifies internal design blueprints for a new military aircraft as Top Secret,
restricting access to only senior engineers and executives. Less sensitive information, such as marketing
materials, is classified as Public and shared more widely.

Outcome: By classifying information according to its sensitivity, the contractor ensures that highly confidential
data is protected with stricter access controls, reducing the likelihood of espionage or data leaks.

Key Documents: Information Classification Policy, Data Classification Guidelines.


A.5.21 Managing Information Security in the ICT
Supply Chain

Control Explanation: This control emphasizes the need to manage and mitigate
information security risks that may arise from interactions with third-party vendors and
suppliers involved in the ICT supply chain. Organizations must ensure that third-party
vendors adhere to the organization’s information security policies, protect sensitive
information, and manage security risks effectively. This control also requires ongoing
oversight and contractual agreements that define security expectations.
Use Case: A healthcare company outsources its IT infrastructure to a cloud services provider. To
ensure compliance with A.5.21, the company includes clauses in the contract that require the cloud
provider to follow strict security protocols, such as encrypting patient data, conducting regular
security audits, and promptly reporting any security incidents. The healthcare company also conducts
annual audits to verify compliance with security standards and periodically assesses risks associated
with using third-party services.

Outcome: By managing the security of its ICT supply chain, the healthcare organization ensures that
third-party vendors adhere to the same security standards as the company, minimizing the risk of
data breaches, protecting patient information, and maintaining regulatory compliance. The
structured monitoring and auditing process also allows the organization to quickly identify and
address potential vulnerabilities in the supply chain.

Key Documents: Supply Chain Risk Assessments, Supplier Audits.


Most Used
People Controls
A.6.1 Screening
Control Explanation: This control ensures that all personnel, including contractors and third-party users,
are screened based on their role and responsibilities before employment. This screening typically involves
background checks, identity verification, and assessing suitability for a position involving access to
sensitive information.

Use Case: A financial institution performs thorough background checks on candidates applying for
positions involving access to sensitive customer financial data. This includes verifying educational
qualifications, criminal history, and employment records.

Outcome: By screening employees before granting access to sensitive information, the company
minimizes risks associated with insider threats, fraud, or negligence. It ensures that only trustworthy
individuals are given access to critical systems.

Key Documents: Employee Screening Procedures, Background Check Reports, Employment Eligibility
Verification.
A.6.2 Terms and Conditions of Employment

Control Explanation: Organizations must ensure that employment contracts and agreements define the
security responsibilities of personnel. This includes confidentiality obligations and the need for compliance with
information security policies. It ensures that all employees understand their roles in protecting organizational
assets.

Use Case: An IT services company includes information security clauses in all employee contracts. These
clauses specify that employees are responsible for safeguarding company data and adhering to
cybersecurity policies. Non-compliance can result in disciplinary action.

Outcome: Clearly defined security responsibilities ensure that employees are aware of their obligations. This
reduces the likelihood of security violations, as employees understand the consequences of failing to adhere
to security policies.

Key Documents: Employment Contracts, Role-Specific Information Security Obligations, Security Compliance
Agreements.
A.6.3 Information Security Awareness,
Education, & Training

Control Explanation: This control ensures that all personnel receive regular training and awareness
programs to help them understand the information security risks they face and the policies they must
follow. It aims to minimize human error, which is often a significant factor in security breaches.

Use Case: A healthcare provider implements mandatory annual security awareness training for all staff,
covering topics such as phishing attacks, data privacy regulations (like HIPAA), and safe handling of
patient records.

Outcome: This ongoing education reduces the risk of human error by ensuring that all employees are
equipped to recognize and respond to common security threats, leading to better overall security
compliance.

Key Documents: Training Program Curriculums, Attendance Logs, Awareness Campaigns, Knowledge
Assessments.
A.6.4 Disciplinary Process

Control Explanation: Organizations must implement a formal disciplinary process for employees or
contractors who violate information security policies. This process should outline the steps for investigating
incidents, determining culpability, and applying appropriate consequences.

Use Case: A retail company establishes a disciplinary policy that specifies penalties for security breaches,
such as unauthorized access to customer data. Employees found guilty of violating this policy face
penalties ranging from warnings to termination, depending on the severity.

Outcome: Having a defined disciplinary process ensures that there is accountability for security breaches,
reinforcing the importance of compliance with security protocols and discouraging negligent or malicious
behavior.

Key Documents: Disciplinary Policy, Incident Reports, Sanction Logs.


A.6.5 Responsibilities after Termination or
Change of Employment

Control Explanation: This control requires that organizations revoke access to information and systems when
an employee or contractor leaves the company or changes roles. It also ensures that any physical and
intellectual assets are returned.

Use Case: A tech company revokes system access and retrieves company-issued laptops and ID badges
when an employee leaves. Additionally, access to customer databases and proprietary software is disabled
immediately upon resignation.

Outcome: By promptly removing access and recovering assets, the company mitigates the risk of
unauthorized access to systems after an employee's departure, reducing the potential for data breaches or
misuse.

Key Documents: Exit Procedures, Asset Return Forms, Access Termination Logs.
A.6.6 Confidentiality or Non-Disclosure
Agreements

Control Explanation: Employees and contractors must sign confidentiality or non-disclosure


agreements (NDAs) to protect sensitive company information. This control ensures that personnel
understand their responsibility to maintain confidentiality even after leaving the organization.

Use Case: A law firm requires all employees to sign NDAs that legally bind them from disclosing client
information or firm data, even after their employment ends.

Outcome: By ensuring that personnel are bound by confidentiality agreements, the firm reduces the
risk of sensitive data being disclosed to unauthorized parties, protecting intellectual property and
client privacy.

Key Documents: Non-Disclosure Agreements (NDAs), Confidentiality Agreements, Contractual Security


Clauses.
A.6.7 Information Security Responsibilities for
Contractors & Third Parties

Control Explanation: Contractors and third-party users must be made aware of their information security
responsibilities, especially when they have access to sensitive organizational information. This control
ensures that contractors are held to the same security standards as employees.

Use Case: A multinational company contracts an external IT services provider to manage their
infrastructure. The company requires the provider to follow its internal security policies, including access
controls and regular security audits.

Outcome: Ensuring that third-party contractors follow the same security practices as the company helps
reduce risks associated with outsourcing and minimizes the potential for security breaches.

Key Documents: Remote Working Policy, Virtual Private Network (VPN) Usage Guidelines, Security
Awareness for Remote Workers.
A.6.8 Secure Offboarding and Exit Interviews

Control Explanation: This control ensures that when employees or contractors leave the organization, a
formal offboarding process is followed. This process includes disabling access to systems, retrieving
company-owned assets, and conducting exit interviews to reinforce confidentiality obligations.

Use Case: A pharmaceutical company conducts an exit interview with a departing researcher to remind
them of their ongoing confidentiality obligations, including the non-disclosure of trade secrets. Access to all
laboratory systems is revoked before the employee's last day.

Outcome: Secure offboarding ensures that departing employees do not retain access to sensitive
information, reducing the risk of data leaks or intellectual property theft after they leave.

Key Documents: Incident Reporting Procedures, Event Logging Systems, Incident Response Plans.
Most Used
Physical Controls
A.7.1 Physical Security Perimeter

Control Explanation: This control requires organizations to define and secure physical boundaries
around sensitive areas. This perimeter must prevent unauthorized access and ensure that sensitive
data, systems, and equipment are protected from both external and internal threats.

Use Case: A government data center installs high-security fencing, multiple gated checkpoints, and
secured building access, ensuring only authorized personnel can enter. Surveillance cameras monitor
all perimeters 24/7, and guard patrols provide additional protection.

Outcome: By implementing a strong physical security perimeter, the data center prevents
unauthorized access to sensitive infrastructure, reducing the risk of physical breaches and data theft.

Key Documents: Physical Security Policy, Site Plans, Access Control Logs.
A.7.2 Physical Entry Controls

Control Explanation: Organizations must implement systems to control and monitor physical access
to secure areas. This may include the use of keycards, biometrics, visitor management systems, and
surveillance to ensure only authorized individuals have access.

Use Case: A healthcare organization uses biometric scanners to control access to rooms containing
patient records. Employees must scan their fingerprint to enter these areas, and access logs are
reviewed regularly to ensure compliance.

Outcome: Strict entry controls ensure that only authorized personnel have access to sensitive patient
data, minimizing the risk of unauthorized access and data breaches.

Key Documents: Access Logs, Visitor Management Procedures, Security Check-in Records.
A.7.4 Physical Security Monitoring

Control Explanation: This control mandates continuous monitoring of sensitive areas using systems like
CCTV, alarms, or motion detectors. The purpose is to detect and respond to unauthorized access
attempts in real time, ensuring that intrusions are identified and managed promptly.

Use Case: A financial institution deploys a comprehensive CCTV system throughout its data centers. The
video feeds are monitored in real time by security personnel, and the system records all entries and exits
for later review in case of incidents.

Outcome: Continuous monitoring allows the financial institution to respond quickly to suspicious
activities, preventing unauthorized access and ensuring that physical security measures are properly
enforced.

Key Documents: Security Monitoring Plans, Incident Response Procedures, Monitoring Logs.
A.7.5 Protecting Against Physical & Environmental
Threats

Control Explanation: This control addresses the protection of information assets from natural disasters
and environmental hazards, such as fire, flood, and extreme weather. Organizations should assess risks
related to their physical locations and implement safeguards like fire suppression systems and flood
sensors.

Use Case: A manufacturing company located in a flood-prone area installs water detection sensors in
its server rooms. It also installs a fire suppression system to protect against fire damage.

Outcome: By protecting against environmental threats, the company ensures the safety and continuity
of its information systems, reducing downtime and data loss caused by physical or environmental
disasters.

Key Documents: Disaster Recovery Plans, Environmental Hazard Assessments, Fire Safety Protocols.
A.7.6 Working in Secure Areas

Control Explanation: This control requires organizations to implement specific procedures for accessing
and working in secure areas, including limiting access to authorized personnel only. Security measures in
secure areas should be heightened to protect critical information and systems.

Use Case: An R&D division at a pharmaceutical company designates specific labs as secure areas. Only
employees working on classified projects are granted access, and all activities within the labs are
closely monitored via security cameras.

Outcome: Controlled access to secure areas ensures that critical intellectual property is protected, and
any suspicious activity is detected quickly, preventing the potential theft of sensitive research data.

Key Documents: Secure Area Access Policies, Activity Logs, Staff Supervision Procedures.
A.7.7 Clear Desk and Clear Screen Policy

Control Explanation: This policy mandates that sensitive information should not be left exposed on desks,
screens, or printers. Employees must ensure that all sensitive documents are stored securely and that
screens are locked when unattended to prevent unauthorized viewing.

Use Case: An international law firm implements a clear desk policy that requires employees to store all
confidential documents in locked cabinets at the end of the day. They must also lock their computer
screens when leaving their desks.

Outcome: By enforcing this policy, the law firm ensures that sensitive client data is not exposed to
unauthorized personnel, reducing the risk of accidental data exposure and enhancing overall data
security.

Key Documents: Clear Desk Policy, Clear Screen Guidelines, Employee Compliance Checklists.
Most Used
Technological
Controls
A.8.5 Secure Authentication

Control Explanation: Secure authentication ensures that users accessing systems are verified
through secure methods such as multi-factor authentication (MFA), strong passwords, or
biometric data. This control reduces the risk of unauthorized access to sensitive systems and
information.

Use Case: A financial institution implements MFA for employees accessing sensitive customer
data remotely. Each user must provide not only a password but also a one-time code sent to
their mobile device or authenticate through fingerprint scanning.

Outcome: This control significantly reduces the risk of account compromises and unauthorized
access, ensuring secure and controlled access to critical systems.

Key Documents: Authentication Policy, MFA Implementation Guides.


A.8.7 Protection Against Malware

Control Explanation: This control entails putting in place tools and policies to safeguard systems from
malware (for example, viruses and ransomware). To detect and prevent harmful software from infecting
systems, it is necessary to install anti-malware software, update it on a regular basis, and monitor it
continuously.

Use Case: A healthcare provider installs endpoint protection software on all machines to protect
against ransomware attacks that could compromise patient data. The technology monitors for
malware in real time and notifies the IT team of any questionable activities.

Outcome: By using advanced malware protection, the organization mitigates the risk of data breaches
or service interruptions caused by malware, maintaining data integrity and availability.

Key Documents: Malware Protection Policy, Antivirus Logs.


A.8.8 Management of Technical Vulnerabilities

Control Explanation: Organizations must establish a strategy for identifying, assessing, and resolving
technical vulnerabilities. This control involves regular vulnerability scans, patch management, and
prompt correction of flaws before they may be exploited.

Use Case: A software development company conducts frequent vulnerability scans on its online apps
and network infrastructure. After discovering a major vulnerability in a customer-facing application, the
organization quickly deploys a patch.

Outcome: By continuously fixing vulnerabilities, the organization significantly reduces the likelihood of
attackers exploiting them, assuring system security and regulatory compliance.

Key Documents: Vulnerability Assessment Reports, Patch Management Procedures.


A.8.9 Configuration Management

Control Explanation: Configuration management guarantees that systems and software are set up
securely and consistently. To prevent creating security risks, apply security baselines, disable
superfluous services, and track changes in system configurations.

Use Case: A government agency uses a configuration management tool to monitor and enforce
security configurations on its networked systems, ensuring that no unauthorized changes are made to
the system settings.

Outcome: Proper configuration management decreases the danger of unauthorized changes that
could undermine system security, enhancing overall compliance and lowering system downtime due to
misconfigurations.

Key Documents: Configuration Management Policy, Change Logs.


A.8.13 Information Backup
Control Explanation: Information backup guarantees that essential data is frequently backed up
and securely stored to prevent data loss caused by unintentional deletion, system failure, or
cyberattacks such as ransomware. Backups should be tested on a regular basis to guarantee that
they can be effectively restored.

Use Case: A manufacturing corporation automates regular backups of its production data to offsite,
encrypted cloud storage. The IT staff verifies backups on a regular basis to verify that they can be
recovered in the event of a calamity.

Outcome: This control ensures that key business processes may continue following a system
breakdown or cyberattack, reducing downtime and financial losses.

Key Documents: Backup and Restore Procedures, Backup Schedules.


A.8.16 Monitoring Activities

Control Explanation: Monitoring tasks include continual monitoring and logging of system events, user
actions, and network traffic to detect potential security incidents. This control enables enterprises to notice
and respond to questionable activity in real time.

Use Case: A retail company employs a Security Information and Event Management (SIEM) system to
collect and analyze logs from firewalls, servers, and apps. The SIEM detects unusual login attempts from
foreign IP addresses and sends an alert to the security team.

Outcome: Real-time monitoring allows the company to immediately discover and respond to possible
threats, lowering the likelihood of successful cyberattacks and minimizing the damage from security
incidents.

Key Documents: Network Monitoring Plans, Incident Response Logs.


Any questions?

You might also like