100% found this document useful (1 vote)
127 views5 pages

ISO 27001 Controls Checklist

The document is an ISO 27001 controls checklist that lists policies and procedures across 12 sections to ensure compliance with ISO 27001. It includes requirements for policies on information security, asset management, access control, physical security, operations and more. For each requirement, it indicates if a policy is defined and assigned to someone for compliance. The checklist aims to help organizations define necessary information security policies and assign responsibilities to meet ISO 27001 standards.

Uploaded by

Norah Al-Shamri
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
127 views5 pages

ISO 27001 Controls Checklist

The document is an ISO 27001 controls checklist that lists policies and procedures across 12 sections to ensure compliance with ISO 27001. It includes requirements for policies on information security, asset management, access control, physical security, operations and more. For each requirement, it indicates if a policy is defined and assigned to someone for compliance. The checklist aims to help organizations define necessary information security policies and assign responsibilities to meet ISO 27001 standards.

Uploaded by

Norah Al-Shamri
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
  • Information Security Policies
  • Organization of Information Security
  • Human Resources Security
  • Access Control
  • Asset Management
  • Physical and Environmental Security
  • Cryptography
  • Operations Security
  • Communications Security
  • Information Security Incident Management
  • Compliance
  • Supplier Relationships
  • System Acquisition, Development, and Maintenance
  • Information Security Aspects of Business Continuity Management

ISO 27001 CONTROLS CHECKLIST

SECTION/ IN
REQUIREMENT/TASK ASSIGNED TO DATE LAST UPDATED
CATEGORY COMPLIANCE?

5. Information Security Policies

5.1 Security policies exist.      

All policies approved by


5.2      
management.

5.3 Evidence of compliance.      

6. Organization of information security

6.1 Roles and responsibilities defined.      

6.2 Segregation of duties defined.      

Verification body / authority


6.3      
contacted for compliance verification.

Establish contact with special interest


6.4      
groups regarding compliance.

Evidence of information security in


6.5      
project management.

6.6 Defined policy for mobile devices.      

6.7 Defined policy for working remotely.      

7. Human resources security


Defined policy for screening
7.1      
employees prior to employment.

Defined policy for HR terms and


7.2      
conditions of employment.

Defined policy for management


7.3      
responsibilities. 

Defined policy for information


7.4 security awareness, education,      
and training.

Defined policy for


7.5 disciplinary process regarding      
information security.

Defined policy for HR termination or


7.6 change-of-employment policy      
regarding information security.

8. Asset management
8.1 Complete inventory list of assets.      

8.2 Complete ownership list of assets.      

Defined "acceptable use" of assets


8.3      
policy.

8.4 Defined return of assets policy.      

Defined policy for classification


8.5      
of information. 

Defined policy for labeling


8.6      
information.

Defined policy for handling


8.7      
of assets.

Defined policy for management


8.8      
of removable media.

Defined policy for disposal


8.9      
of media.

Defined policy for physical


8.10      
media transfer.

9. Access control
Defined policy for user asset
9.1      
registration and de-registration.

Defined policy for user access


9.2      
provisioning.

Defined policy for management of


9.3      
privileged access rights.

Defined policy for management of


9.4 secret authentication      
information of users.

Defined policy for review of user


9.5      
access rights.

Defined policy for removal or


9.6      
adjustment of access rights.

Defined policy for use of secret


9.7      
authentication information.

Defined policy for information access


9.8      
restrictions.

Defined policy for secure log-in


9.9      
procedures.

Defined policy for password


9.10      
management systems.
Defined policy for use of privileged
9.11      
utility programs.

Defined policy for access control to


9.12      
program source code.

10. Cryptography
Defined policy for use of
10.1      
cryptographic controls.

10.2 Defined policy for key management.      

11. Physical and environmental security


Defined policy for physical security
11.1      
perimeter.

Defined policy for physical entry


11.2      
controls.

Defined policy for securing offices,


11.3      
rooms, and facilities.

Defined policy for protection against


11.4      
external and environmental threats.

Defined policy for working in secure


11.5      
areas.

Defined policy for delivery and


11.6      
loading areas.

Defined policy for equipment siting


11.7      
and protection.

11.8 Defined policy for supporting utilities.      

11.9 Defined policy for cabling security.      

Defined policy for equipment


11.10      
maintenance.

11.11 Defined policy for removal of assets.      

Defined policy for security of


11.12      
equipment and assets off premises.

Secure disposal or re-use of


11.13      
equipment.

Defined policy for unattended user


11.14      
equipment.

Defined policy for clear desk and


11.15      
clear screen policy.

12. Operations security


Defined policy for documented
12.1      
operating procedures.

Defined policy for change


12.2      
management.

Defined policy for capacity


12.3      
management.

Defined policy for separation of


12.4 development, testing, and operational      
environments.

Defined policy for controls against


12.5      
malware.

Defined policy for backing up


12.6      
systems.

Defined policy for information


12.7      
backup.

12.8 Defined policy for event logging.      

Defined policy for protection of


12.9      
log information.

Defined policy for administrator and


12.10      
operator log.

Defined policy for clock


12.11      
synchronization.

Defined policy for installation of


12.12      
software on operational systems.

Defined policy for management of


12.13      
technical vulnerabilities.

Defined policy for restriction on


12.14      
software installation.

Defined policy for information system


12.15      
audit control.

13. Communication security

13.1 Defined policy for network controls.      

Defined policy for security of network


13.2      
services.

Defined policy for segregation in


13.3      
networks.

Defined policy for information


13.4      
transfer policies and procedures.

Defined policy for agreements on


13.5      
information transfer.
Defined policy for electronic
13.6      
messaging.

Defined policy for confidentiality or


13.7      
non-disclosure agreements.

Defined policy for system acquisition,


13.8      
development, and maintenance.

14. System acquisition, development, and maintenance


Defined policy for information
14.1 security requirements analysis and      
specification.
Defined policy for securing
14.2 application services on public      
networks.

Defined policy for protecting


14.3      
application service transactions.

15. Supplier relationships


Defined policy for supplier
15.1      
relationships.
16. Information security incident management
Defined policy for information
16.1      
security management.

17. Information security aspects of business continuity management

17.1 Defined policy for redundancies.      

18. Compliance
Defined policy for identification of
18.1 applicable legislation and contractual      
requirement.
Defined policy for intellectual
18.2      
property rights.

Defined policy for protection of


18.3      
records.
Defined policy for privacy and
18.4 protection of personally identifiable      
information.
Defined policy for regulation of
18.5      
cryptographic control.

Defined policy for compliance with


18.6      
security policies and standards.
Defined policy for technical
18.7      
compliance review.

ISO 27001 CONTROLS CHECKLIST                     
SECTION/
CATEGORY
REQUIREMENT/TASK
ASSIGNED TO
IN
COMPLIANCE?
DATE LAST UPD
8.1
Complete inventory list of assets.
 
 
 
8.2
Complete ownership list of assets.
 
 
 
8.3
Defined "acceptable use" of ass
9.11
Defined policy for use of privileged 
utility programs.
 
 
 
9.12
Defined policy for access control to 
program source
12.1
Defined policy for documented 
operating procedures.
 
 
 
12.2
Defined policy for change 
management.
 
 
 
12.3
Define
13.6
Defined policy for electronic 
messaging.
 
 
 
13.7
Defined policy for confidentiality or 
non-disclosure agreements.
 

You might also like