ISO 27001 · Domain 4
Annex A Controls
About 25% of the exam
Four themes, ninety three controls
- A.5 Organizational
- thirty seven controls, widest theme
- A.6 People
- eight controls about staff
- A.7 Physical
- fourteen controls for premises and equipment
- A.8 Technological
- thirty four controls for systems
- Total
- ninety three controls
- Restructure
- fifty seven merged into twenty four
- Additions
- eleven controls new in 2022
The 2013 edition ran fourteen clauses and one hundred fourteen controls; the 2022 edition runs four themes and ninety three
The eleven new controls
- 5.7
- threat intelligence
- 5.23
- security for cloud service use
- 5.30
- ICT readiness for business continuity
- 7.4
- physical security monitoring
- 8.9
- configuration management
- 8.10
- information deletion
- 8.11
- data masking
- 8.12
- data leakage prevention
- 8.16
- monitoring activities
- 8.23
- web filtering
- 8.28
- secure coding
Examiners test the eleven hardest because none of them existed as standalone controls in the 2013 edition
Control attributes in 27002
- Control type
- preventive, detective or corrective
- Security properties
- confidentiality, integrity, availability
- Cybersecurity concepts
- identify, protect, detect, respond, recover
- Operational capabilities
- practical groupings such as governance
- Security domains
- governance, protection, defense, resilience
- Purpose
- filtering and reporting, not conformity
Annex A and ISO/IEC 27002
- Annex A is a normative reference list
- 27002 explains purpose and implementation
- 27002 adds attributes and other information
- Certification is against 27001 only
- Numbering matches across the two
- Guidance is not an audit requirement
How Annex A is meant to be used
- Determine necessary controls from risk first
- Compare that set against Annex A
- Catch anything the team overlooked
- Add controls from elsewhere if needed
- Record every decision in the SoA
- Exclusions need a written justification
A.5 Organizational highlights
- 5.1
- policies for information security
- 5.9
- inventory of information and assets
- 5.14
- information transfer rules
- 5.19
- security in supplier relationships
- 5.24
- incident management planning and preparation
- 5.31
- legal, statutory and contractual requirements
- 5.34
- privacy and protection of personal data
A.6 People highlights
- 6.1
- screening before employment
- 6.2
- terms and conditions of employment
- 6.3
- awareness, education and training
- 6.4
- the disciplinary process
- 6.5
- duties after leaving or changing
- 6.6
- confidentiality or nondisclosure agreements
- 6.8
- event reporting by staff
A.7 Physical highlights
- 7.1
- physical security perimeters
- 7.2
- physical entry controls
- 7.4
- physical security monitoring, new
- 7.7
- clear desk and clear screen
- 7.10
- storage media handling
- 7.13
- equipment maintenance
- 7.14
- secure disposal or reuse
A.8 Technological highlights
- 8.1
- user endpoint devices
- 8.5
- secure authentication
- 8.8
- management of technical vulnerabilities
- 8.15
- logging of relevant events
- 8.16
- monitoring activities, new
- 8.20
- networks security
- 8.24
- use of cryptography
- 8.28
- secure coding, new
From risk to a working control
- Risk identified
- Control determined
- Owner assigned
- Implemented
- Operated with records
- Measured under 9.1
- Audited under 9.2
- Design and operation are different tests
- A control installed last week shows design only
- Records prove the control actually ran
- Rubber stamped reviews are not operation
- Effectiveness is measured, never assumed
Annex A traps in practice
- Claiming physical controls never apply remotely
- Marking a control implemented with no records
- Skipping the Annex A comparison entirely
- Treating 27002 guidance as mandatory text
- Counting one hundred fourteen controls today
- Confusing data masking with encryption
- Applying all ninety three without justification
Mapping Annex A to other frameworks
- Build one control matrix, many frameworks
- Map to NIST CSF subcategories
- Map to SP 800-53 control families
- One control can satisfy several requirements
- Keep the SoA as the ISO record
- Track gaps where mappings are partial
- Recheck mappings after any standard revision
Numbers to memorize
- Themes
- four in the 2022 edition
- Controls
- ninety three in total
- Organizational
- thirty seven controls
- People
- eight controls
- Physical
- fourteen controls
- Technological
- thirty four controls
- New
- eleven controls
- Merged
- fifty seven became twenty four
Control words that get confused
- Preventive
- stops the event happening
- Detective
- spots it while it happens
- Corrective
- limits damage afterwards
- Masking
- limits exposure of displayed data
- Anonymization
- removes the link to a person
- Pseudonymization
- swaps identifiers, still reversible
Reference strip: themes, new controls, attributes, usage, evidence
Themes
- Organizational thirty seven
- People eight, physical fourteen
- Technological thirty four
New in 2022
- Threat intelligence, cloud services
- ICT readiness, physical monitoring
- Deletion, masking, leakage prevention
- Monitoring, web filtering, secure coding
Attributes
- Type, properties, concepts
- Capabilities and security domains
- Used for filtering, not conformity
Usage
- Risk first, Annex A second
- Comparison recorded in the SoA
- Exclusions justified in writing
Evidence
- Owner named per control
- Operating records over a period
- Effectiveness measures under clause 9.1
Quick exam traps
- Trap: Annex A still contains one hundred fourteen controls
- Trap: Every organization must implement all ninety three controls
- Trap: ISO/IEC 27002 guidance is auditable as a requirement
- Trap: A fully remote company can exclude all physical controls automatically
- Trap: A thorough risk assessment removes the need to compare against Annex A
- Trap: Data masking and encryption are the same control
- Trap: Marking a control applicable in the SoA proves it operates
cybercertprep.com · original revision sheet written from the public body of knowledge