Filter posts by category

ISO 27001 Annex A Controls

ISO 27001 Annex A 8.19

ISO 27001:2022 Annex A 8.19 Installation of software on operational systems

ISO 27001:2022 Annex A 8.19: Mastering Software Installation on Operational Systems We have all seen it happen. A well-meaning employee downloads a “free PDF converter” to get their job done faster, and suddenly your operational server is crawling with malware. Or perhaps a developer pushes a new library directly to production without testing, bringing the

ISO 27001:2022 Annex A 8.19 Installation of software on operational systems Read More »

ISO 27001 Annex A 8.27

ISO 27001:2022 Annex A 8.27 Secure systems architecture and engineering principles

ISO 27001:2022 Annex A 8.27: Building Secure Systems by Design We often hear the phrase “secure by design,” but what does it actually mean in practice? Too often, security is bolted on at the end of a project like an afterthought—a firewall here, an encryption key there. But if the underlying architecture is flawed, no

ISO 27001:2022 Annex A 8.27 Secure systems architecture and engineering principles Read More »

ISO 27001 Annex A 8.31

ISO 27001:2022 Annex A 8.31 Separation of development, test and production environments

Mastering ISO 27001 Annex A 8.31: How to Separate Your Environments Effectively If you have ever accidentally deleted a live database because you thought you were on the staging server, you already know why ISO 27001:2022 Annex A 8.31 exists. It is one of those controls that sounds purely technical, but it saves organisations from

ISO 27001:2022 Annex A 8.31 Separation of development, test and production environments Read More »

ISO 27001 Annex A 8.34

ISO 27001:2022 Annex A 8.34 – Protection of Information Systems During Audit Testing

If there is one irony in information security, it is this: the very process designed to find weaknesses in your systems—audit testing—can sometimes be the thing that breaks them. We have all heard horror stories of a vulnerability scan that accidentally flooded a network or a penetration test that knocked a critical database offline during

ISO 27001:2022 Annex A 8.34 – Protection of Information Systems During Audit Testing Read More »

ISO 27001 Annex A 6.5

ISO 27001 Annex A 6.5 Responsibilities After Termination Or Change Of Employment

ISO 27001 Annex A 6.5 asks you to make sure that security duties are still valid even after an employee stops working for you. You need to have these duties clearly stated, shared with people, and enforced. This term is generally a requirement in the contract that explains what you expect an employee to do when they leave the company or when they move

ISO 27001 Annex A 6.5 Responsibilities After Termination Or Change Of Employment Read More »

ISO 27001 Annex A 6.3

ISO 27001 Annex A 6.3 Information Security Awareness Education and Training

ISO 27001 Annex A 6.3 deals with Information Security Awareness, Education, and Training. This control requires you to teach people about information security. This includes everything from general security awareness training and education to giving regular updates on your information security policy, any specific policies you have on certain topics, and all your security procedures.

ISO 27001 Annex A 6.3 Information Security Awareness Education and Training Read More »

ISO 27001 Annex A 6.2

ISO 27001 Annex A 6.2 Terms and Conditions of Employment

For the ISO 27001 control Annex A 6.2, called Terms and Conditions Of Employment, you need to ensure your organization has agreements with employees. These agreements define your information security responsibilities. Terms of Employment are the specific conditions and agreements that establish the relationship between you as the employee and the employer. Usually, these terms explain the

ISO 27001 Annex A 6.2 Terms and Conditions of Employment Read More »

ISO 27001 Annex A 6.1

ISO 27001 Annex A 6.1 Screening

ISO 27001 Annex A 6.1 is about employee screening and performing background checks on people both before you hire them and while they are working for you. What is ISO 27001 Annex A 6.1? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Screening”. What is the ISO

ISO 27001 Annex A 6.1 Screening Read More »

ISO 27001 Annex A 5.36

ISO 27001 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security

You need to follow the policies, rules, and standards you have set for information security, as this is required by ISO 27001 Annex A 5.36. You must make sure that you are compliant with your information security policy, as well as any specific policies, rules, and standards you have created. You should also check these

ISO 27001 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security Read More »

ISO 27001 Annex A 5.35

ISO 27001 Annex A 5.35 Independent Review Of Information Security

ISO 27001 Annex A 5.35 is about how a company should independently review its information security management system to ensure it is effective, meeting it’s objectives and operating as intended. What is ISO 27001 Annex A 5.35? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard

ISO 27001 Annex A 5.35 Independent Review Of Information Security Read More »

ISO 27001 Annex A 5.31

ISO 27001 Annex A 5.31 Legal, statutory, regulatory and contractual requirements

ISO 27001 Annex A 5.31 Legal, Statutory, Regulatory and Contractual Requirements, asks you to know what outside rules and laws apply to your information security and then make sure you follow them. It specifically deals with the legal and contract rules that tell you exactly how you should handle and use information security. What is

ISO 27001 Annex A 5.31 Legal, statutory, regulatory and contractual requirements Read More »

ISO 27001 Annex A 5.30

ISO 27001 Annex A 5.30 ICT Readiness For Business Continuity

This rule is about ICT Readiness for Business Continuity, which means the IT team having business continuity planned, implemented and tested. What is ISO 27001 Annex A 5.30? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “ICT Readiness For Business Continuity”. What

ISO 27001 Annex A 5.30 ICT Readiness For Business Continuity Read More »

ISO 27001 Annex A 5.29

ISO 27001 Annex A 5.29 Information Security During Disruption

This rule is about ensuring that information security is maintained during a disruption, outage or business continuity event. What is ISO 27001 Annex A 5.29? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Information Security During Disruption”. What is the ISO 27001

ISO 27001 Annex A 5.29 Information Security During Disruption Read More »

ISO 27001 Annex A 5.27

ISO 27001 Annex A 5.27 Learning From Information Security Incidents

This rule is about learning from information security incidents so that they do not happen again and so that information security is improved. What is ISO 27001 Annex A 5.27? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Learning From Information Security

ISO 27001 Annex A 5.27 Learning From Information Security Incidents Read More »

ISO 27001 Annex A 5.26

ISO 27001 Annex A 5.26 Response To Information Security Incidents

This rule is about responding to information security incidents, which means a company must have a system to respond to information security incidents and events. What is ISO 27001 Annex A 5.26? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Response

ISO 27001 Annex A 5.26 Response To Information Security Incidents Read More »

ISO 27001 Annex A 5.25

ISO 27001 Annex A 5.25 Assessment And Decision On Information Security Events

This rule is about assessing incidents and then deciding if they are an information security incident and prioritising them for action. What is ISO 27001 Annex A 5.25? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Assessment And Decision On Information Security

ISO 27001 Annex A 5.25 Assessment And Decision On Information Security Events Read More »

ISO 27001 Annex A 5.24

ISO 27001 Annex A 5.24 Information Security Incident Management Planning and Preparation

This rule is about information security incident management, which means a company must have a system and people to handle the information security incidents. What is ISO 27001 Annex A 5.24? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Information Security Incident

ISO 27001 Annex A 5.24 Information Security Incident Management Planning and Preparation Read More »

ISO 27001 Annex A 5.23

ISO 27001 Annex A 5.23 Information Security For Use Of Cloud Services

This rule is about cloud supplier management, which means a company must have a system to handle the information security risks of its third party cloud systems, products and services. What is ISO 27001 Annex A 5.23? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the

ISO 27001 Annex A 5.23 Information Security For Use Of Cloud Services Read More »

ISO 27001 Annex A 5.22

ISO 27001 Annex A 5.22 Monitor, Review And Change Management Of Supplier Services

This rule is about ICT supplier management, which means a company must have a system to handle the management of its third party IT systems, products and services. What is ISO 27001 Annex A 5.22? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is

ISO 27001 Annex A 5.22 Monitor, Review And Change Management Of Supplier Services Read More »

ISO 27001 Annex A 5.21

ISO 27001 Annex A 5.21 Managing Information Security In The ICT Supply Chain

This rule is about ICT supplier management, which means a company must have a system to handle the information security risks of its third party IT systems, products and services. What is ISO 27001 Annex A 5.21? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the

ISO 27001 Annex A 5.21 Managing Information Security In The ICT Supply Chain Read More »