ISO/IEC 27001:2013 Annex A (legacy)
Version: 2013 (withdrawn; certification transition ended 2025-10-31)
The 114 Annex A reference controls of the withdrawn 2013 edition, in 14 domains and 35 control objectives. Kept for crosswalks to older certificates and customer questionnaires; the 2022 edition replaces it.
Where we stand
Controls
76%
Evidence
27%
Policies
21%
80 of 114 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| A.5.1 Management direction for information security | |||||
| A.5.1.1 | Policies for information security Controls: BIZ-14, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| A.5.1.2 | Review of the policies for information security Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| A.6.1 Internal organization | |||||
| A.6.1.1 | Information security roles and responsibilities Controls: BIZ-15, PEOPLE-08, PEOPLE-09 | Not passing | Not current | Not approved | Not yet |
| A.6.1.2 | Segregation of duties Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| A.6.1.3 | Contact with authorities Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| A.6.1.4 | Contact with special interest groups | Unmapped | Unmapped | Unmapped | Not yet |
| A.6.1.5 | Information security in project management Controls: PDP-01 | Passing | Not current | Approved | (4 mo ago) |
| A.6.2 Mobile devices and teleworking | |||||
| A.6.2.1 | Mobile device policy Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| A.6.2.2 | Teleworking | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.1 Prior to employment | |||||
| A.7.1.1 | Screening Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| A.7.1.2 | Terms and conditions of employment Controls: PEOPLE-02, PEOPLE-08, PEOPLE-15 | Not passing | Not current | Not approved | Not yet |
| A.7.2 During employment | |||||
| A.7.2.1 | Management responsibilities Controls: PEOPLE-04, PEOPLE-05 | Passing | Current | Not approved | (29 d ago) |
| A.7.2.2 | Information security awareness, education and training Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| A.7.2.3 | Disciplinary process Controls: PEOPLE-07 | Passing | Not current | Not approved | Not yet |
| A.7.3 Termination and change of employment | |||||
| A.7.3.1 | Termination or change of employment responsibilities Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| A.8.1 Responsibility for assets | |||||
| A.8.1.1 | Inventory of assets Controls: IT-04, IT-05 | Passing | Not current | Not approved | Not yet |
| A.8.1.2 | Ownership of assets Controls: IT-04, IT-05 | Passing | Not current | Not approved | Not yet |
| A.8.1.3 | Acceptable use of assets Controls: IT-01 | Passing | Not current | Approved | Not yet |
| A.8.1.4 | Return of assets Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| A.8.2 Information classification | |||||
| A.8.2.1 | Classification of information Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| A.8.2.2 | Labelling of information Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| A.8.2.3 | Handling of assets Controls: DATA-01, DATA-05 | Passing | Not current | Not approved | Not yet |
| A.8.3 Media handling | |||||
| A.8.3.1 | Management of removable media | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.3.2 | Disposal of media | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.3.3 | Physical media transfer | Unmapped | Unmapped | Unmapped | Not yet |
| A.9.1 Business requirements of access control | |||||
| A.9.1.1 | Access control policy Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| A.9.1.2 | Access to networks and network services Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| A.9.2 User access management | |||||
| A.9.2.1 | User registration and de-registration | Unmapped | Unmapped | Unmapped | Not yet |
| A.9.2.2 | User access provisioning Controls: IAM-05, IAM-07 | Not passing | Not current | Not approved | (29 d ago) |
| A.9.2.3 | Management of privileged access rights Controls: IAM-04, IAM-06 | Passing | Not current | Not approved | (29 d ago) |
| A.9.2.4 | Management of secret authentication information of users | Unmapped | Unmapped | Unmapped | Not yet |
| A.9.2.5 | Review of user access rights Controls: IAM-09 | Passing | Current | Not approved | (29 d ago) |
| A.9.2.6 | Removal or adjustment of access rights | Unmapped | Unmapped | Unmapped | Not yet |
| A.9.3 User responsibilities | |||||
| A.9.3.1 | Use of secret authentication information Controls: IAM-03 | Passing | Current | Not approved | (29 d ago) |
| A.9.4 System and application access control | |||||
| A.9.4.1 | Information access restriction Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| A.9.4.2 | Secure log-on procedures Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| A.9.4.3 | Password management system Controls: IAM-03, IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| A.9.4.4 | Use of privileged utility programs | Unmapped | Unmapped | Unmapped | Not yet |
| A.9.4.5 | Access control to program source code Controls: PDP-06 | Passing | Current | Approved | (4 mo ago) |
| A.10.1 Cryptographic controls | |||||
| A.10.1.1 | Policy on the use of cryptographic controls Controls: APP-01, DATA-02, DATA-03, DATA-06, IT-02 | Not passing | Not current | Not approved | (8 h ago) |
| A.10.1.2 | Key management | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.1 Secure areas | |||||
| A.11.1.1 | Physical security perimeter Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.1.2 | Physical entry controls Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.1.3 | Securing offices, rooms and facilities | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.1.4 | Protecting against external and environmental threats | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.1.5 | Working in secure areas Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.1.6 | Delivery and loading areas Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.2 Equipment | |||||
| A.11.2.1 | Equipment siting and protection Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.2.2 | Supporting utilities | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.2.3 | Cabling security Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.11.2.4 | Equipment maintenance | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.2.5 | Removal of assets Controls: IT-04 | Passing | Not current | Not approved | Not yet |
| A.11.2.6 | Security of equipment and assets off-premises | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.2.7 | Secure disposal or re-use of equipment | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.2.8 | Unattended user equipment | Unmapped | Unmapped | Unmapped | Not yet |
| A.11.2.9 | Clear desk and clear screen policy | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.1 Operational procedures and responsibilities | |||||
| A.12.1.1 | Documented operating procedures | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.1.2 | Change management Controls: CLOUD-02, CUST-04, PDP-02 | Not passing | Not current | Not approved | (23 d ago) |
| A.12.1.3 | Capacity management | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.1.4 | Separation of development, testing and operational environments Controls: CLOUD-06 | Passing | Current | Approved | (29 d ago) |
| A.12.2 Protection from malware | |||||
| A.12.2.1 | Controls against malware | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.3 Backup | |||||
| A.12.3.1 | Information backup Controls: DATA-12, DATA-13, DATA-14, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| A.12.4 Logging and monitoring | |||||
| A.12.4.1 | Event logging Controls: MON-01, MON-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| A.12.4.2 | Protection of log information | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.4.3 | Administrator and operator logs Controls: MON-02 | Passing | Not current | Not approved | (4 mo ago) |
| A.12.4.4 | Clock synchronisation | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.5 Control of operational software | |||||
| A.12.5.1 | Installation of software on operational systems Controls: PDP-05 | Passing | Current | Not approved | (29 d ago) |
| A.12.6 Technical vulnerability management | |||||
| A.12.6.1 | Management of technical vulnerabilities Controls: CLOUD-05, IT-03, MON-05, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| A.12.6.2 | Restrictions on software installation | Unmapped | Unmapped | Unmapped | Not yet |
| A.12.7 Information systems audit considerations | |||||
| A.12.7.1 | Information systems audit controls Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| A.13.1 Network security management | |||||
| A.13.1.1 | Network controls Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| A.13.1.2 | Security of network services | Unmapped | Unmapped | Unmapped | Not yet |
| A.13.1.3 | Segregation in networks Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| A.13.2 Information transfer | |||||
| A.13.2.1 | Information transfer policies and procedures Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| A.13.2.2 | Agreements on information transfer Controls: CUST-02, VEND-02 | Passing | Not current | Not approved | Not yet |
| A.13.2.3 | Electronic messaging | Unmapped | Unmapped | Unmapped | Not yet |
| A.13.2.4 | Confidentiality or non-disclosure agreements Controls: PEOPLE-02 | Passing | Not current | Not approved | Not yet |
| A.14.1 Security requirements of information systems | |||||
| A.14.1.1 | Information security requirements analysis and specification | Unmapped | Unmapped | Unmapped | Not yet |
| A.14.1.2 | Securing application services on public networks Controls: CLOUD-01, DATA-03 | Passing | Current | Not approved | (8 h ago) |
| A.14.1.3 | Protecting application services transactions | Unmapped | Unmapped | Unmapped | Not yet |
| A.14.2 Security in development and support processes | |||||
| A.14.2.1 | Secure development policy Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| A.14.2.2 | System change control procedures Controls: CLOUD-02, PDP-02, PDP-03 | Not passing | Not current | Not approved | (8 h ago) |
| A.14.2.3 | Technical review of applications after operating platform changes Controls: PDP-14 | Passing | Current | Approved | (4 mo ago) |
| A.14.2.4 | Restrictions on changes to software packages Controls: PDP-02 | Passing | Not current | Not approved | (23 d ago) |
| A.14.2.5 | Secure system engineering principles Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| A.14.2.6 | Secure development environment Controls: CLOUD-06, PDP-06 | Passing | Current | Approved | (29 d ago) |
| A.14.2.7 | Outsourced development Controls: PDP-03 | Not passing | Current | Not approved | (8 h ago) |
| A.14.2.8 | System security testing Controls: APP-02, MON-04, PDP-04 | Not passing | Not current | Not approved | (8 h ago) |
| A.14.2.9 | System acceptance testing Controls: PDP-04 | Passing | Not current | Not approved | (29 d ago) |
| A.14.3 Test data | |||||
| A.14.3.1 | Protection of test data | Unmapped | Unmapped | Unmapped | Not yet |
| A.15.1 Information security in supplier relationships | |||||
| A.15.1.1 | Information security policy for supplier relationships Controls: VEND-01, VEND-03 | Passing | Not current | Not approved | Not yet |
| A.15.1.2 | Addressing security within supplier agreements Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| A.15.1.3 | Information and communication technology supply chain Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| A.15.2 Supplier service delivery management | |||||
| A.15.2.1 | Monitoring and review of supplier services Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| A.15.2.2 | Managing changes to supplier services Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| A.16.1 Management of information security incidents and improvements | |||||
| A.16.1.1 | Responsibilities and procedures Controls: BIZ-02, BIZ-21 | Passing | Not current | Not approved | (3 mo ago) |
| A.16.1.2 | Reporting information security events Controls: BIZ-13, CUST-01 | Passing | Not current | Approved | (29 d ago) |
| A.16.1.3 | Reporting information security weaknesses Controls: BIZ-13 | Passing | Current | Approved | (29 d ago) |
| A.16.1.4 | Assessment of and decision on information security events Controls: BIZ-03, MON-03 | Not passing | Not current | Not approved | (8 h ago) |
| A.16.1.5 | Response to information security incidents Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| A.16.1.6 | Learning from information security incidents Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
| A.16.1.7 | Collection of evidence | Unmapped | Unmapped | Unmapped | Not yet |
| A.17.1 Information security continuity | |||||
| A.17.1.1 | Planning information security continuity Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| A.17.1.2 | Implementing information security continuity Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| A.17.1.3 | Verify, review and evaluate information security continuity Controls: BIZ-20, BIZ-21, DATA-15 | Passing | Not current | Not approved | (4 mo ago) |
| A.17.2 Redundancies | |||||
| A.17.2.1 | Availability of information processing facilities | Unmapped | Unmapped | Unmapped | Not yet |
| A.18.1 Compliance with legal and contractual requirements | |||||
| A.18.1.1 | Identification of applicable legislation and contractual requirements Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| A.18.1.2 | Intellectual property rights | Unmapped | Unmapped | Unmapped | Not yet |
| A.18.1.3 | Protection of records Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| A.18.1.4 | Privacy and protection of personally identifiable information Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| A.18.1.5 | Regulation of cryptographic controls | Unmapped | Unmapped | Unmapped | Not yet |
| A.18.2 Information security reviews | |||||
| A.18.2.1 | Independent review of information security | Unmapped | Unmapped | Unmapped | Not yet |
| A.18.2.2 | Compliance with security policies and standards Controls: BIZ-08, BIZ-09 | Passing | Not current | Approved | Not yet |
| A.18.2.3 | Technical compliance review Controls: MON-04, MON-05 | Not passing | Not current | Not approved | (8 h ago) |
