Filter posts by category

ISO 27001 Annex A Controls

ISO 27001 Annex A 8.2 Privileged Access Rights

ISO 27001 Annex A 8.2 Privileged Access Rights – Definitive Guide

ISO 27001 Annex A 8.2 is about privileged access rights, which means a company must restrict access to privileged accounts and manage them. What are Privileged Access Rights? There are users that will be granted privileged access such as administer (admin) accounts, super user accounts, global admin accounts and even service accounts. ISO 27001 Privileged

ISO 27001 Annex A 8.2 Privileged Access Rights – Definitive Guide Read More »

ISO 27001 Annex 7.9 Security Of Assets Off-Premises

ISO 27001 Annex A 7.9 Security Of Assets Off-Premises – Definitive Guide

ISO 27001 Annex A 7.9 is about protecting your assets when they are outside your normal work area to prevent loss, damage, theft or compromise of off-site devices and interruption to the organisations operations. What is ISO 27001 Annex A 7.9? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In

ISO 27001 Annex A 7.9 Security Of Assets Off-Premises – Definitive Guide Read More »

ISO 27001 Annex 7.5 Protecting Against Physical and Environmental Threats

ISO 27001 Annex A 7.5 Protecting Against Physical and Environmental Threats – Definitive Guide

ISO 27001 Annex A 7.5 asks you to protect your business from physical threats. This rule means you must guard against both natural and physical dangers. This is one of the controls that helps you limit harm. It works to cut damage from things you cannot plan for or control. What is ISO 27001 Annex

ISO 27001 Annex A 7.5 Protecting Against Physical and Environmental Threats – Definitive Guide Read More »

ISO 27001 Annex 6.6 Confidentiality Or Non-Disclosure Agreements

ISO 27001 Annex A 6.6 Confidentiality Or Non-Disclosure Agreements – Definitive Guide

ISO 27001 Annex A 6.6 is about a Confidentiality Agreement or Non-Disclosure Agreement (NDA). This is a legal document that stops you or your company from sharing secret information with other people. You often use this kind of agreement in business, during hiring, and in other times when you need to give someone sensitive information.

ISO 27001 Annex A 6.6 Confidentiality Or Non-Disclosure Agreements – Definitive Guide Read More »

What is ISO 27001 Annex 6.5 Responsibilities After Termination Or Change Of Employment?

ISO 27001 Annex A 6.5 Responsibilities After Termination Or Change Of Employment – Definitive Guide

ISO 27001 Annex A 6.5 asks you to make sure that security duties are still valid even after an employee stops working for you. You need to have these duties clearly stated, shared with people, and enforced. This term is generally a requirement in the contract that explains what you expect an employee to do when they leave the company or when they move

ISO 27001 Annex A 6.5 Responsibilities After Termination Or Change Of Employment – Definitive Guide Read More »

What is ISO 27001 Annex 6.3 Information Security Awareness Education and Training

ISO 27001 Annex A 6.3 Information Security Awareness Education and Training – Definitive Guide

ISO 27001 Annex A 6.3 deals with Information Security Awareness, Education, and Training. This control requires you to teach people about information security. This includes everything from general security awareness training and education to giving regular updates on your information security policy, any specific policies you have on certain topics, and all your security procedures.

ISO 27001 Annex A 6.3 Information Security Awareness Education and Training – Definitive Guide Read More »

ISO 27001 Annex 6.2 Terms and Conditions of Employment

ISO 27001 Annex A 6.2 Terms and Conditions of Employment – Definitive Guide

For the ISO 27001 control Annex A 6.2, called Terms and Conditions Of Employment, you need to ensure your organization has agreements with employees. These agreements define your information security responsibilities. Terms of Employment are the specific conditions and agreements that establish the relationship between you as the employee and the employer. Usually, these terms explain the

ISO 27001 Annex A 6.2 Terms and Conditions of Employment – Definitive Guide Read More »

What is ISO 27001 Annex 5.36 Compliance With Policies, Rules And Standards For Information Security?

ISO 27001 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security – Definitive Guide

You need to follow the policies, rules, and standards you have set for information security, as this is required by ISO 27001 Annex A 5.36. You must make sure that you are compliant with your information security policy, as well as any specific policies, rules, and standards you have created. You should also check these

ISO 27001 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security – Definitive Guide Read More »

What is ISO 27001 Annex 5.35 Independent Review Of Information Security?

ISO 27001 Annex A 5.35 Independent Review Of Information Security – Definitive Guide

ISO 27001 Annex A 5.35 is about how a company should independently review its information security management system to ensure it is effective, meeting it’s objectives and operating as intended. What is ISO 27001 Annex A 5.35? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard

ISO 27001 Annex A 5.35 Independent Review Of Information Security – Definitive Guide Read More »

What is ISO 27001 Annex 5.32 Intellectual Property Rights?

ISO 27001 Annex A 5.32 Intellectual Property Rights – Definitive Guide

ISO 27001 Annex A 5.32 is about Intellectual Property Rights. That means you need to know and follow the rules about intellectual property that come from outside your organisation. You should put these rules into practice. These rules are things like laws, government regulations, and agreements you have made about intellectual property. The standard covers

ISO 27001 Annex A 5.32 Intellectual Property Rights – Definitive Guide Read More »

ISO 27001 Annex 5.31 Legal, statutory, regulatory and contractual requirements

ISO 27001 Annex A 5.31 Legal, statutory, regulatory and contractual requirements – Definitive Guide

ISO 27001 Annex A 5.31 Legal, Statutory, Regulatory and Contractual Requirements, asks you to know what outside rules and laws apply to your information security and then make sure you follow them. It specifically deals with the legal and contract rules that tell you exactly how you should handle and use information security. What is

ISO 27001 Annex A 5.31 Legal, statutory, regulatory and contractual requirements – Definitive Guide Read More »

What is ISO 27001 Annex 5.30 ICT Readiness For Business Continuity?

ISO 27001 Annex A 5.30 ICT Readiness For Business Continuity – Definitive Guide

This rule is about ICT Readiness for Business Continuity, which means the IT team having business continuity planned, implemented and tested. What is ISO 27001 Annex A 5.30? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “ICT Readiness For Business Continuity”. What

ISO 27001 Annex A 5.30 ICT Readiness For Business Continuity – Definitive Guide Read More »

What is ISO 27001 Annex 5.29 Information Security During Disruption?

ISO 27001 Annex A 5.29 Information Security During Disruption – Definitive Guide

This rule is about ensuring that information security is maintained during a disruption, outage or business continuity event. What is ISO 27001 Annex A 5.29? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Information Security During Disruption”. What is the ISO 27001

ISO 27001 Annex A 5.29 Information Security During Disruption – Definitive Guide Read More »

What is ISO 27001 Annex 5.28 Collection Of Evidence?

ISO 27001 Annex A 5.28 Collection Of Evidence – Definitive Guide

This rule is about collection of evidence, which means a company must have a system to handle the the collection and management of evidence from information security events. What is ISO 27001 Annex A 5.28? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is

ISO 27001 Annex A 5.28 Collection Of Evidence – Definitive Guide Read More »

What is ISO 27001 Annex 5.27 Learning From Information Security Incidents?

ISO 27001 Annex A 5.27 Learning From Information Security Incidents – Definitive Guide

This rule is about learning from information security incidents so that they do not happen again and so that information security is improved. What is ISO 27001 Annex A 5.27? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Learning From Information Security

ISO 27001 Annex A 5.27 Learning From Information Security Incidents – Definitive Guide Read More »

What is ISO 27001 Annex 5.26 Response To Information Security Incidents?

ISO 27001 Annex A 5.26 Response To Information Security Incidents – Definitive Guide

This rule is about responding to information security incidents, which means a company must have a system to respond to information security incidents and events. What is ISO 27001 Annex A 5.26? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Response

ISO 27001 Annex A 5.26 Response To Information Security Incidents – Definitive Guide Read More »

What is ISO 27001 Annex 5.25 Assessment And Decision On Information Security Events?

ISO 27001 Annex A 5.25 Assessment And Decision On Information Security Events – Definitive Guide

This rule is about assessing incidents and then deciding if they are an information security incident and prioritising them for action. What is ISO 27001 Annex A 5.25? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Assessment And Decision On Information Security

ISO 27001 Annex A 5.25 Assessment And Decision On Information Security Events – Definitive Guide Read More »

What is ISO 27001 Annex 5.24 Information Security Incident Management Planning and Preparation?

ISO 27001 Annex A 5.24 Information Security Incident Management Planning and Preparation – Definitive Guide

This rule is about information security incident management, which means a company must have a system and people to handle the information security incidents. What is ISO 27001 Annex A 5.24? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is titled “Information Security Incident

ISO 27001 Annex A 5.24 Information Security Incident Management Planning and Preparation – Definitive Guide Read More »

What is ISO 27001 Annex 5.23 Information Security For Use Of Cloud Services?

ISO 27001 Annex A 5.23 Information Security For Use Of Cloud Services – Definitive Guide

This rule is about cloud supplier management, which means a company must have a system to handle the information security risks of its third party cloud systems, products and services. What is ISO 27001 Annex A 5.23? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the

ISO 27001 Annex A 5.23 Information Security For Use Of Cloud Services – Definitive Guide Read More »

What is ISO 27001 Annex 5.22 Monitor, Review And Change Management Of Supplier Services?

ISO 27001 Annex A 5.22 Monitor, Review And Change Management Of Supplier Services – Definitive Guide

This rule is about ICT supplier management, which means a company must have a system to handle the management of its third party IT systems, products and services. What is ISO 27001 Annex A 5.22? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the control is

ISO 27001 Annex A 5.22 Monitor, Review And Change Management Of Supplier Services – Definitive Guide Read More »

What is ISO 27001 Annex 5.21 Managing Information Security In The ICT Supply Chain?

ISO 27001 Annex A 5.21 Managing Information Security In The ICT Supply Chain – Definitive Guide

This rule is about ICT supplier management, which means a company must have a system to handle the information security risks of its third party IT systems, products and services. What is ISO 27001 Annex A 5.21? The latest version of the ISO 27001 standard is ISO/IEC 27001:2022 (published in October 2022). In the ISO/IEC 27001:2022 Standard the

ISO 27001 Annex A 5.21 Managing Information Security In The ICT Supply Chain – Definitive Guide Read More »

What is ISO 27001 Annex 5.20 Addressing Information Security Within Supplier Agreements?

ISO 27001 Annex A 5.20 Addressing Information Security Within Supplier Agreements – Definitive Guide

ISO 27001 Annex A 5.20 is a simple rule. It says that your business must create and agree upon information security rules with all your suppliers. What Does This Mean? This rule is about putting a legal plan in place. This plan is often a formal contract, a business agreement, or set of terms. This

ISO 27001 Annex A 5.20 Addressing Information Security Within Supplier Agreements – Definitive Guide Read More »

What is ISO 27001 Annex 5.19 Information Security In Supplier Relationships?

ISO 27001 Annex A 5.19 Information Security In Supplier Relationships – Definitive Guide

The ISO 27001 Annex A 5.19 rule is about managing information security when working with other companies (suppliers). This rule requires your business to handle the security risks that come from using products and services provided by these suppliers. In short, it helps you keep your supply chain secure. Suppliers are one of your biggest

ISO 27001 Annex A 5.19 Information Security In Supplier Relationships – Definitive Guide Read More »

What is ISO 27001 Annex 5.10 Acceptable Use Of Information And Other Associated Assets?

ISO 27001 Annex A 5.10 Acceptable Use Of Information And Other Associated Assets – Definitive Guide

ISO 27001 Annex A 5.10 is about making rules for how people can use a company’s information and other assets. The goal is to make sure that these items are used safely and correctly. This helps keep data private, correct, and available. What is ISO 27001 Annex A 5.10? The latest version of the ISO

ISO 27001 Annex A 5.10 Acceptable Use Of Information And Other Associated Assets – Definitive Guide Read More »