ISO 27001 CONTROLS CHECKLIST
SECTION/ IN
REQUIREMENT/TASK ASSIGNED TO DATE LAST UPDATED
CATEGORY COMPLIANCE?
5. Information Security Policies
5.1 Security policies exist.
All policies approved by
5.2
management.
5.3 Evidence of compliance.
6. Organization of information security
6.1 Roles and responsibilities defined.
6.2 Segregation of duties defined.
Verification body / authority
6.3
contacted for compliance verification.
Establish contact with special interest
6.4
groups regarding compliance.
Evidence of information security in
6.5
project management.
6.6 Defined policy for mobile devices.
6.7 Defined policy for working remotely.
7. Human resources security
Defined policy for screening
7.1
employees prior to employment.
Defined policy for HR terms and
7.2
conditions of employment.
Defined policy for management
7.3
responsibilities.
Defined policy for information
7.4 security awareness, education,
and training.
Defined policy for
7.5 disciplinary process regarding
information security.
Defined policy for HR termination or
7.6 change-of-employment policy
regarding information security.
8. Asset management
8.1 Complete inventory list of assets.
8.2 Complete ownership list of assets.
Defined "acceptable use" of assets
8.3
policy.
8.4 Defined return of assets policy.
Defined policy for classification
8.5
of information.
Defined policy for labeling
8.6
information.
Defined policy for handling
8.7
of assets.
Defined policy for management
8.8
of removable media.
Defined policy for disposal
8.9
of media.
Defined policy for physical
8.10
media transfer.
9. Access control
Defined policy for user asset
9.1
registration and de-registration.
Defined policy for user access
9.2
provisioning.
Defined policy for management of
9.3
privileged access rights.
Defined policy for management of
9.4 secret authentication
information of users.
Defined policy for review of user
9.5
access rights.
Defined policy for removal or
9.6
adjustment of access rights.
Defined policy for use of secret
9.7
authentication information.
Defined policy for information access
9.8
restrictions.
Defined policy for secure log-in
9.9
procedures.
Defined policy for password
9.10
management systems.
Defined policy for use of privileged
9.11
utility programs.
Defined policy for access control to
9.12
program source code.
10. Cryptography
Defined policy for use of
10.1
cryptographic controls.
10.2 Defined policy for key management.
11. Physical and environmental security
Defined policy for physical security
11.1
perimeter.
Defined policy for physical entry
11.2
controls.
Defined policy for securing offices,
11.3
rooms, and facilities.
Defined policy for protection against
11.4
external and environmental threats.
Defined policy for working in secure
11.5
areas.
Defined policy for delivery and
11.6
loading areas.
Defined policy for equipment siting
11.7
and protection.
11.8 Defined policy for supporting utilities.
11.9 Defined policy for cabling security.
Defined policy for equipment
11.10
maintenance.
11.11 Defined policy for removal of assets.
Defined policy for security of
11.12
equipment and assets off premises.
Secure disposal or re-use of
11.13
equipment.
Defined policy for unattended user
11.14
equipment.
Defined policy for clear desk and
11.15
clear screen policy.
12. Operations security
Defined policy for documented
12.1
operating procedures.
Defined policy for change
12.2
management.
Defined policy for capacity
12.3
management.
Defined policy for separation of
12.4 development, testing, and operational
environments.
Defined policy for controls against
12.5
malware.
Defined policy for backing up
12.6
systems.
Defined policy for information
12.7
backup.
12.8 Defined policy for event logging.
Defined policy for protection of
12.9
log information.
Defined policy for administrator and
12.10
operator log.
Defined policy for clock
12.11
synchronization.
Defined policy for installation of
12.12
software on operational systems.
Defined policy for management of
12.13
technical vulnerabilities.
Defined policy for restriction on
12.14
software installation.
Defined policy for information system
12.15
audit control.
13. Communication security
13.1 Defined policy for network controls.
Defined policy for security of network
13.2
services.
Defined policy for segregation in
13.3
networks.
Defined policy for information
13.4
transfer policies and procedures.
Defined policy for agreements on
13.5
information transfer.
Defined policy for electronic
13.6
messaging.
Defined policy for confidentiality or
13.7
non-disclosure agreements.
Defined policy for system acquisition,
13.8
development, and maintenance.
14. System acquisition, development, and maintenance
Defined policy for information
14.1 security requirements analysis and
specification.
Defined policy for securing
14.2 application services on public
networks.
Defined policy for protecting
14.3
application service transactions.
15. Supplier relationships
Defined policy for supplier
15.1
relationships.
16. Information security incident management
Defined policy for information
16.1
security management.
17. Information security aspects of business continuity management
17.1 Defined policy for redundancies.
18. Compliance
Defined policy for identification of
18.1 applicable legislation and contractual
requirement.
Defined policy for intellectual
18.2
property rights.
Defined policy for protection of
18.3
records.
Defined policy for privacy and
18.4 protection of personally identifiable
information.
Defined policy for regulation of
18.5
cryptographic control.
Defined policy for compliance with
18.6
security policies and standards.
Defined policy for technical
18.7
compliance review.