IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Products / Frameworks / 4.1.0

ISO/IEC 27001

Primary information-security management assessment profile.

This is the MSP 4.1.0 catalog snapshot, not the full publisher standard and not an assertion of Free/Professional parity. All conclusions require scope, adequate evidence and an authorized reviewer.
100 catalog entries28 with exact test mappings0 family-support entries72 manual / unmapped

Control / requirementPackaged guidance & evidenceCoverage
CLAUSE-4ISMS clausesDefine organizational context, interested parties, ISMS scope and the management system.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-5ISMS clausesConfirm leadership commitment, policy direction, responsibilities and assigned authority.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-6ISMS clausesEvaluate risk planning, treatment objectives and controlled changes to the ISMS.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-7ISMS clausesReview resources, competence, awareness, communication and controlled documented information.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-8ISMS clausesVerify operational planning, risk assessment execution and treatment implementation.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-9ISMS clausesEvaluate monitoring, measurement, internal audit and management-review effectiveness.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
CLAUSE-10ISMS clausesConfirm corrective action and continual improvement are operating and evidenced.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.1OrganizationalSecurity policy direction and approval
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.2OrganizationalSecurity roles, ownership and accountability
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.3OrganizationalSeparation of conflicting duties
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.4OrganizationalManagement enforcement of security responsibilities
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.5OrganizationalCoordination with relevant authorities
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.6OrganizationalParticipation in security communities and specialist groups
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.7OrganizationalCollection and use of threat intelligence
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.8OrganizationalSecurity activities within projects
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.9OrganizationalInventory and ownership of information and related assets
Evidence and test details
  • WIN-INVENTORY-COVERAGE-001 WINDOWSWindows Server canonical collect-once evidence coverage
  • WIN-ROLE-INVENTORY-001 WINDOWSWindows Server domain, role, hardware and feature inventory
  • WIN-SERVICE-INVENTORY-001 WINDOWSWindows service inventory
  • WIN-SHARE-INVENTORY-001 WINDOWSWindows share inventory
  • WIN-STORAGE-INVENTORY-001 WINDOWSWindows local storage inventory
  • WIN-NETWORK-INVENTORY-001 WINDOWSWindows network adapter and IP inventory
  • WIN-REMOTE-AUDIT-ACCESS-001 WINDOWSKnown Windows Server remote audit access and missing-evidence state

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.10OrganizationalRules for acceptable use and handling of assets
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.11OrganizationalReturn of organizational assets when access or employment changes
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.12OrganizationalClassification according to sensitivity and business need
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.13OrganizationalConsistent labeling of classified information
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.14OrganizationalProtection of information transferred internally or externally
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.15OrganizationalBusiness rules for physical and logical access
Evidence and test details
  • NET-OBJ-005 NETWORKAdministrative identity and least privilege
  • NET-OBJ-029 NETWORKRemote administration and support-access configuration
  • WIN-LOCAL-ACCOUNT-INVENTORY-001 WINDOWSWindows local account inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.16OrganizationalIdentity lifecycle management
Evidence and test details
  • AD-PREFLIGHT-001 ADSECDirectory evidence collection availability
  • AD-LIFECYCLE-001 ADSECAccount lifecycle review
  • ENTRA-CONTEXT-001 ENTRACloud identity tenant evidence
  • NET-OBJ-006 NETWORKCentralized AAA / SSO / MFA evidence
  • NET-OBJ-028 NETWORKLocal administrator/account inventory
  • WIN-LOCAL-ACCOUNT-INVENTORY-001 WINDOWSWindows local account inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.17OrganizationalProtection and administration of authentication information
Evidence and test details
  • AD-AUTH-001 ADSECAuthentication credential lifecycle review
  • GPO-PASSWORD-001 GPOAuthentication policy review
  • NET-MERAKI-AUTH-001 NETWORKMeraki Dashboard API authentication evidence
  • NET-OBJ-006 NETWORKCentralized AAA / SSO / MFA evidence

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.18OrganizationalProvisioning, review and removal of access rights
Evidence and test details
  • AD-PREFLIGHT-001 ADSECDirectory evidence collection availability
  • AD-LIFECYCLE-001 ADSECAccount lifecycle review
  • AD-PRIV-001 ADSECPrivileged access membership review
  • ENTRA-ROLE-001 ENTRACloud privileged role inventory
  • NET-OBJ-005 NETWORKAdministrative identity and least privilege
  • NET-OBJ-028 NETWORKLocal administrator/account inventory
  • WIN-LOCAL-ACCOUNT-INVENTORY-001 WINDOWSWindows local account inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.19OrganizationalSecurity risk management for supplier relationships
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.20OrganizationalSecurity obligations in supplier agreements
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.21OrganizationalSecurity across the ICT supply chain
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.22OrganizationalMonitoring and controlled change of supplier services
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.23OrganizationalSecurity governance for cloud-service acquisition, operation and exit
Evidence and test details
  • ENTRA-CONTEXT-001 ENTRACloud identity tenant evidence

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.24OrganizationalPreparation for managing security incidents
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.25OrganizationalAssessment and classification of security events
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.26OrganizationalCoordinated response to security incidents
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.27OrganizationalLearning and improvement from security incidents
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.28OrganizationalCollection and preservation of evidence
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.29OrganizationalMaintaining security during disruption
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.30OrganizationalICT readiness supporting business continuity
Evidence and test details
  • VEEAM-JOB-001 BACKUPBackup job result evidence
  • NET-OBJ-019 NETWORKHigh availability/redundancy state

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.31OrganizationalIdentification of legal, regulatory and contractual duties
Evidence and test details
  • NET-OBJ-027 NETWORKVendor security/compliance mode evidence including validated crypto where exposed

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.32OrganizationalProtection of intellectual-property rights
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.33OrganizationalProtection and retention of organizational records
Evidence and test details
  • NET-EVIDENCE-COVERAGE-001 NETWORKPer-device network audit evidence completeness
  • NET-OBJ-030 NETWORKDevice configuration evidence freshness and collection completeness
  • NET-CLI-RAW-001 NETWORKRead-only network CLI evidence capture

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.5.34OrganizationalPrivacy and protection of personally identifiable information
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.35OrganizationalIndependent review of security governance and controls
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.36OrganizationalCompliance with policies, rules and standards
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.5.37OrganizationalDocumented operating procedures for security-relevant activities
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.1PeoplePersonnel screening appropriate to role and risk
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.2PeopleSecurity responsibilities in employment terms
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.3PeopleSecurity awareness, education and training
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.4PeopleDisciplinary process for security violations
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.5PeopleResponsibilities after role change or termination
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.6PeopleConfidentiality and non-disclosure obligations
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.7PeopleSecurity controls for remote working
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.6.8PeopleReporting suspected or observed security events
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.1PhysicalDefinition and protection of physical security boundaries
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.2PhysicalControlled entry to secure areas
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.3PhysicalProtection of offices, rooms and facilities
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.4PhysicalMonitoring of physical access and activity
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.5PhysicalProtection against physical and environmental threats
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.6PhysicalSecure working practices inside restricted areas
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.7PhysicalClear-desk and clear-screen practices
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.8PhysicalSecure placement and protection of equipment
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.9PhysicalProtection of assets used away from organizational premises
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.10PhysicalLifecycle protection for removable and other storage media
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.11PhysicalResilience of supporting utilities
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.12PhysicalProtection of power and data cabling
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.13PhysicalPreventive and corrective maintenance of equipment
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.7.14PhysicalSecure disposal or reuse of equipment
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.1TechnologicalSecurity configuration and protection of user endpoint devices
Evidence and test details
  • WIN-OS-001 WINDOWSWindows platform and support inventory
  • LNX-OS-001 LINUXLinux server platform inventory
  • NET-MERAKI-ORG-001 NETWORKMeraki organization inventory
  • NET-OBJ-001 NETWORKDevice identity/model/serial and role
  • WIN-INVENTORY-COVERAGE-001 WINDOWSWindows Server canonical collect-once evidence coverage
  • WIN-ROLE-INVENTORY-001 WINDOWSWindows Server domain, role, hardware and feature inventory
  • WIN-STORAGE-INVENTORY-001 WINDOWSWindows local storage inventory
  • WIN-REMOTE-AUDIT-ACCESS-001 WINDOWSKnown Windows Server remote audit access and missing-evidence state

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.2TechnologicalAdministration of privileged access rights
Evidence and test details
  • AD-PREFLIGHT-001 ADSECDirectory evidence collection availability
  • AD-PRIV-001 ADSECPrivileged access membership review
  • ENTRA-ROLE-001 ENTRACloud privileged role inventory
  • NET-OBJ-005 NETWORKAdministrative identity and least privilege
  • NET-OBJ-028 NETWORKLocal administrator/account inventory
  • WIN-LOCAL-ACCOUNT-INVENTORY-001 WINDOWSWindows local account inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.3TechnologicalRestriction of access to information and system functions
Evidence and test details
  • WIN-SHARE-INVENTORY-001 WINDOWSWindows share inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.4TechnologicalControlled access to source code and development tools
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.5TechnologicalStrong authentication appropriate to risk
Evidence and test details
  • AD-AUTH-001 ADSECAuthentication credential lifecycle review
  • GPO-PASSWORD-001 GPOAuthentication policy review
  • NET-OBJ-006 NETWORKCentralized AAA / SSO / MFA evidence

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.6TechnologicalCapacity monitoring and planning
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.7TechnologicalPrevention, detection and recovery from malware
Evidence and test details
  • WIN-AV-001 WINDOWSEndpoint malware protection status
  • NET-OBJ-021 NETWORKIDS/IPS/threat-protection configuration
  • NET-OBJ-022 NETWORKContent/malware filtering where applicable

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.8TechnologicalIdentification and remediation of technical vulnerabilities
Evidence and test details
  • WIN-OS-001 WINDOWSWindows platform and support inventory
  • WIN-SMB1-001 WINDOWSLegacy protocol exposure
  • VMW-HOST-001 VMWAREVirtualization host inventory
  • WIN-PATCH-INVENTORY-001 WINDOWSWindows installed update month and patch build inventory
  • WIN-PATCH-COHORT-001 WINDOWSSame-OS Windows server patch cohort consistency
  • LNX-OS-001 LINUXLinux server platform inventory
  • LNX-PATCH-INVENTORY-001 LINUXLinux package update evidence
  • NET-OBJ-002 NETWORKFirmware/software version and support posture
  • NET-OBJ-004 NETWORKInsecure management services disabled
  • NET-OBJ-025 NETWORKUnused/default services and insecure defaults review

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.9TechnologicalSecure configuration baselines and change control
Evidence and test details
  • AD-DC-001 ADSECDomain controller configuration and monitoring inventory
  • GPO-INVENTORY-001 GPOConfiguration policy inventory
  • WIN-OS-001 WINDOWSWindows platform and support inventory
  • VMW-HOST-001 VMWAREVirtualization host inventory
  • VMW-VM-001 VMWAREVirtual machine inventory
  • WIN-PATCH-INVENTORY-001 WINDOWSWindows installed update month and patch build inventory
  • WIN-PATCH-COHORT-001 WINDOWSSame-OS Windows server patch cohort consistency
  • LNX-OS-001 LINUXLinux server platform inventory
  • LNX-PATCH-INVENTORY-001 LINUXLinux package update evidence
  • NET-EVIDENCE-COVERAGE-001 NETWORKPer-device network audit evidence completeness
  • NET-OBJ-001 NETWORKDevice identity/model/serial and role
  • NET-OBJ-002 NETWORKFirmware/software version and support posture
  • NET-OBJ-020 NETWORKConfiguration backup/export evidence
  • NET-OBJ-025 NETWORKUnused/default services and insecure defaults review
  • NET-OBJ-030 NETWORKDevice configuration evidence freshness and collection completeness
  • NET-CLI-RAW-001 NETWORKRead-only network CLI evidence capture
  • WIN-INVENTORY-COVERAGE-001 WINDOWSWindows Server canonical collect-once evidence coverage
  • WIN-SERVICE-INVENTORY-001 WINDOWSWindows service inventory
  • WIN-REMOTE-AUDIT-ACCESS-001 WINDOWSKnown Windows Server remote audit access and missing-evidence state

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.10TechnologicalSecure deletion of information
Evidence and test details
  • WIN-STORAGE-INVENTORY-001 WINDOWSWindows local storage inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.11TechnologicalMasking sensitive information where appropriate
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.12TechnologicalPrevention of unauthorized data disclosure
Evidence and test details
  • STOR-INVENTORY-001 STORAGEStorage management-plane inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.13TechnologicalResilient backup and verified restoration
Evidence and test details
  • VEEAM-JOB-001 BACKUPBackup job result evidence
  • VEEAM-REPO-001 BACKUPBackup repository inventory
  • STOR-INVENTORY-001 STORAGEStorage management-plane inventory
  • NET-OBJ-020 NETWORKConfiguration backup/export evidence

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.14TechnologicalRedundancy supporting availability requirements
Evidence and test details
  • NET-OBJ-019 NETWORKHigh availability/redundancy state
  • NET-OBJ-026 NETWORKHA peers, stack members, uplinks and topology relationships

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.15TechnologicalSecurity logging and protected audit records
Evidence and test details
  • NET-OBJ-008 NETWORKSecurity/event logging enabled
  • NET-OBJ-009 NETWORKCentral syslog/SIEM destinations configured
  • NET-OBJ-023 NETWORKConfiguration-change audit trail
  • NET-CLI-RAW-001 NETWORKRead-only network CLI evidence capture

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.16TechnologicalMonitoring of systems, networks and anomalous activity
Evidence and test details
  • AD-DC-001 ADSECDomain controller configuration and monitoring inventory
  • WIN-AV-001 WINDOWSEndpoint malware protection status
  • NET-OBJ-008 NETWORKSecurity/event logging enabled
  • NET-OBJ-009 NETWORKCentral syslog/SIEM destinations configured
  • NET-OBJ-012 NETWORKSecure SNMP/telemetry configuration
  • NET-OBJ-021 NETWORKIDS/IPS/threat-protection configuration
  • WIN-SERVICE-INVENTORY-001 WINDOWSWindows service inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.17TechnologicalConsistent time synchronization for reliable records
Evidence and test details
  • NET-OBJ-010 NETWORKAuthoritative NTP/time synchronization

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.18TechnologicalControl of privileged utility programs
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.19TechnologicalControlled installation of software on production systems
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.20TechnologicalNetwork security architecture and operation
Evidence and test details
  • WIN-FW-001 WINDOWSHost firewall configuration
  • WIN-SMB1-001 WINDOWSLegacy protocol exposure
  • NET-INVENTORY-001 NETWORKNetwork asset and service exposure inventory
  • NET-RDP-001 NETWORKRemote administration exposure review
  • VMW-HOST-001 VMWAREVirtualization host inventory
  • STOR-INVENTORY-001 STORAGEStorage management-plane inventory
  • NET-VENDOR-001 NETWORKNetwork vendor management profile
  • NET-MGMT-TLS-001 NETWORKNetwork management TLS evidence
  • NET-MGMT-SSH-001 NETWORKNetwork SSH management evidence
  • NET-MERAKI-AUTH-001 NETWORKMeraki Dashboard API authentication evidence
  • NET-SCOPE-001 NETWORKNetwork vendor scope configuration
  • NET-SCOPE-002 NETWORKNetwork management mode configuration
  • NET-DEVICE-SCOPE-001 NETWORKConfigured network device/controller scope
  • NET-MGMT-PREFLIGHT-001 NETWORKNetwork management availability
  • NET-MERAKI-ORG-001 NETWORKMeraki organization inventory
  • NET-OBJ-003 NETWORKEncrypted management protocols
  • NET-OBJ-004 NETWORKInsecure management services disabled
  • NET-OBJ-007 NETWORKManagement-plane source restrictions
  • NET-OBJ-011 NETWORKSecure DNS configuration
  • NET-OBJ-012 NETWORKSecure SNMP/telemetry configuration
  • NET-OBJ-013 NETWORKInterfaces, VLANs, trunks and segmentation inventory
  • NET-OBJ-014 NETWORKRouting and gateway configuration inventory
  • NET-OBJ-015 NETWORKFirewall/ACL rules and default policy
  • NET-OBJ-016 NETWORKSite-to-site and remote-access VPN encryption
  • NET-OBJ-017 NETWORKWireless authentication/encryption
  • NET-OBJ-021 NETWORKIDS/IPS/threat-protection configuration
  • NET-OBJ-022 NETWORKContent/malware filtering where applicable
  • NET-OBJ-024 NETWORKPublic/WAN exposure and management exposure review
  • NET-OBJ-026 NETWORKHA peers, stack members, uplinks and topology relationships
  • NET-OBJ-029 NETWORKRemote administration and support-access configuration
  • WIN-SHARE-INVENTORY-001 WINDOWSWindows share inventory
  • WIN-NETWORK-INVENTORY-001 WINDOWSWindows network adapter and IP inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.21TechnologicalSecurity expectations for network services
Evidence and test details
  • WIN-FW-001 WINDOWSHost firewall configuration
  • NET-INVENTORY-001 NETWORKNetwork asset and service exposure inventory
  • NET-RDP-001 NETWORKRemote administration exposure review
  • NET-VENDOR-001 NETWORKNetwork vendor management profile
  • NET-MERAKI-AUTH-001 NETWORKMeraki Dashboard API authentication evidence
  • NET-SCOPE-001 NETWORKNetwork vendor scope configuration
  • NET-SCOPE-002 NETWORKNetwork management mode configuration
  • NET-DEVICE-SCOPE-001 NETWORKConfigured network device/controller scope
  • NET-MGMT-PREFLIGHT-001 NETWORKNetwork management availability
  • NET-MERAKI-ORG-001 NETWORKMeraki organization inventory
  • NET-OBJ-007 NETWORKManagement-plane source restrictions
  • NET-OBJ-011 NETWORKSecure DNS configuration
  • NET-OBJ-014 NETWORKRouting and gateway configuration inventory
  • NET-OBJ-015 NETWORKFirewall/ACL rules and default policy
  • NET-OBJ-024 NETWORKPublic/WAN exposure and management exposure review
  • WIN-NETWORK-INVENTORY-001 WINDOWSWindows network adapter and IP inventory

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.22TechnologicalSegmentation of networks and security zones
Evidence and test details
  • NET-OBJ-013 NETWORKInterfaces, VLANs, trunks and segmentation inventory
  • NET-OBJ-015 NETWORKFirewall/ACL rules and default policy

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.23TechnologicalFiltering access to harmful or inappropriate web resources
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.24TechnologicalUse and lifecycle management of cryptography
Evidence and test details
  • STOR-INVENTORY-001 STORAGEStorage management-plane inventory
  • NET-MGMT-TLS-001 NETWORKNetwork management TLS evidence
  • NET-MGMT-SSH-001 NETWORKNetwork SSH management evidence
  • NET-OBJ-003 NETWORKEncrypted management protocols
  • NET-OBJ-004 NETWORKInsecure management services disabled
  • NET-OBJ-016 NETWORKSite-to-site and remote-access VPN encryption
  • NET-OBJ-017 NETWORKWireless authentication/encryption
  • NET-OBJ-018 NETWORKManagement/device certificate inventory and expiry
  • NET-OBJ-027 NETWORKVendor security/compliance mode evidence including validated crypto where exposed

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.25TechnologicalSecure development lifecycle governance
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.26TechnologicalApplication security requirements and acceptance criteria
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.27TechnologicalSecure system architecture and engineering principles
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.28TechnologicalSecure coding practices and developer controls
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.29TechnologicalSecurity testing during development and acceptance
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.30TechnologicalGovernance of outsourced system development
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.31TechnologicalSeparation of development, test and production environments
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.32TechnologicalControlled change management for systems and infrastructure
Evidence and test details
  • NET-OBJ-023 NETWORKConfiguration-change audit trail

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
A.8.33TechnologicalProtection and governance of test information
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
A.8.34TechnologicalSafeguards during audit and assurance testing
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping