ISO/IEC 27001
Primary information-security management assessment profile.
| Control / requirement | Packaged guidance & evidence | Coverage |
|---|---|---|
CLAUSE-4ISMS clauses | Define organizational context, interested parties, ISMS scope and the management system.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-5ISMS clauses | Confirm leadership commitment, policy direction, responsibilities and assigned authority.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-6ISMS clauses | Evaluate risk planning, treatment objectives and controlled changes to the ISMS.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-7ISMS clauses | Review resources, competence, awareness, communication and controlled documented information.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-8ISMS clauses | Verify operational planning, risk assessment execution and treatment implementation.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-9ISMS clauses | Evaluate monitoring, measurement, internal audit and management-review effectiveness.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
CLAUSE-10ISMS clauses | Confirm corrective action and continual improvement are operating and evidenced.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.1Organizational | Security policy direction and approvalEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.2Organizational | Security roles, ownership and accountabilityEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.3Organizational | Separation of conflicting dutiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.4Organizational | Management enforcement of security responsibilitiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.5Organizational | Coordination with relevant authoritiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.6Organizational | Participation in security communities and specialist groupsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.7Organizational | Collection and use of threat intelligenceEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.8Organizational | Security activities within projectsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.9Organizational | Inventory and ownership of information and related assetsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.10Organizational | Rules for acceptable use and handling of assetsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.11Organizational | Return of organizational assets when access or employment changesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.12Organizational | Classification according to sensitivity and business needEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.13Organizational | Consistent labeling of classified informationEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.14Organizational | Protection of information transferred internally or externallyEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.15Organizational | Business rules for physical and logical accessEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.16Organizational | Identity lifecycle managementEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.17Organizational | Protection and administration of authentication informationEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.18Organizational | Provisioning, review and removal of access rightsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.19Organizational | Security risk management for supplier relationshipsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.20Organizational | Security obligations in supplier agreementsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.21Organizational | Security across the ICT supply chainEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.22Organizational | Monitoring and controlled change of supplier servicesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.23Organizational | Security governance for cloud-service acquisition, operation and exitEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.24Organizational | Preparation for managing security incidentsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.25Organizational | Assessment and classification of security eventsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.26Organizational | Coordinated response to security incidentsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.27Organizational | Learning and improvement from security incidentsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.28Organizational | Collection and preservation of evidenceEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.29Organizational | Maintaining security during disruptionEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.30Organizational | ICT readiness supporting business continuityEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.31Organizational | Identification of legal, regulatory and contractual dutiesEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.32Organizational | Protection of intellectual-property rightsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.33Organizational | Protection and retention of organizational recordsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.5.34Organizational | Privacy and protection of personally identifiable informationEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.35Organizational | Independent review of security governance and controlsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.36Organizational | Compliance with policies, rules and standardsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.5.37Organizational | Documented operating procedures for security-relevant activitiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.1People | Personnel screening appropriate to role and riskEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.2People | Security responsibilities in employment termsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.3People | Security awareness, education and trainingEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.4People | Disciplinary process for security violationsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.5People | Responsibilities after role change or terminationEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.6People | Confidentiality and non-disclosure obligationsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.7People | Security controls for remote workingEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.6.8People | Reporting suspected or observed security eventsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.1Physical | Definition and protection of physical security boundariesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.2Physical | Controlled entry to secure areasEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.3Physical | Protection of offices, rooms and facilitiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.4Physical | Monitoring of physical access and activityEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.5Physical | Protection against physical and environmental threatsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.6Physical | Secure working practices inside restricted areasEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.7Physical | Clear-desk and clear-screen practicesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.8Physical | Secure placement and protection of equipmentEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.9Physical | Protection of assets used away from organizational premisesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.10Physical | Lifecycle protection for removable and other storage mediaEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.11Physical | Resilience of supporting utilitiesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.12Physical | Protection of power and data cablingEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.13Physical | Preventive and corrective maintenance of equipmentEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.7.14Physical | Secure disposal or reuse of equipmentEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.1Technological | Security configuration and protection of user endpoint devicesEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.2Technological | Administration of privileged access rightsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.3Technological | Restriction of access to information and system functionsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.4Technological | Controlled access to source code and development toolsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.5Technological | Strong authentication appropriate to riskEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.6Technological | Capacity monitoring and planningEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.7Technological | Prevention, detection and recovery from malwareEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.8Technological | Identification and remediation of technical vulnerabilitiesEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.9Technological | Secure configuration baselines and change controlEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.10Technological | Secure deletion of informationEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.11Technological | Masking sensitive information where appropriateEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.12Technological | Prevention of unauthorized data disclosureEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.13Technological | Resilient backup and verified restorationEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.14Technological | Redundancy supporting availability requirementsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.15Technological | Security logging and protected audit recordsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.16Technological | Monitoring of systems, networks and anomalous activityEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.17Technological | Consistent time synchronization for reliable recordsEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.18Technological | Control of privileged utility programsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.19Technological | Controlled installation of software on production systemsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.20Technological | Network security architecture and operationEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.21Technological | Security expectations for network servicesEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.22Technological | Segmentation of networks and security zonesEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.23Technological | Filtering access to harmful or inappropriate web resourcesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.24Technological | Use and lifecycle management of cryptographyEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.25Technological | Secure development lifecycle governanceEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.26Technological | Application security requirements and acceptance criteriaEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.27Technological | Secure system architecture and engineering principlesEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.28Technological | Secure coding practices and developer controlsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.29Technological | Security testing during development and acceptanceEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.30Technological | Governance of outsourced system developmentEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.31Technological | Separation of development, test and production environmentsEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.32Technological | Controlled change management for systems and infrastructureEvidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
A.8.33Technological | Protection and governance of test informationEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
A.8.34Technological | Safeguards during audit and assurance testingEvidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
No controls match these filters.