FintastIQTrust Center
LoginBook a Consultation
Framework

ISO/IEC 27001:2013 Annex A (legacy)

Version: 2013 (withdrawn; certification transition ended 2025-10-31)

The 114 Annex A reference controls of the withdrawn 2013 edition, in 14 domains and 35 control objectives. Kept for crosswalks to older certificates and customer questionnaires; the 2022 edition replaces it.

Official source

Summary

Where we stand

Controls
76%
Evidence
27%
Policies
21%

80 of 114 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
A.5.1 Management direction for information security
A.5.1.1Policies for information security
Controls: BIZ-14, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
A.5.1.2Review of the policies for information security
Controls: BIZ-14
PassingNot currentNot approvedNot yet
A.6.1 Internal organization
A.6.1.1Information security roles and responsibilities
Controls: BIZ-15, PEOPLE-08, PEOPLE-09
Not passingNot currentNot approvedNot yet
A.6.1.2Segregation of duties
Controls: BIZ-15
PassingNot currentNot approvedNot yet
A.6.1.3Contact with authorities
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
A.6.1.4Contact with special interest groupsUnmappedUnmappedUnmappedNot yet
A.6.1.5Information security in project management
Controls: PDP-01
PassingNot currentApproved(4 mo ago)
A.6.2 Mobile devices and teleworking
A.6.2.1Mobile device policy
Controls: IT-02
Not passingNot currentApprovedNot yet
A.6.2.2TeleworkingUnmappedUnmappedUnmappedNot yet
A.7.1 Prior to employment
A.7.1.1Screening
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
A.7.1.2Terms and conditions of employment
Controls: PEOPLE-02, PEOPLE-08, PEOPLE-15
Not passingNot currentNot approvedNot yet
A.7.2 During employment
A.7.2.1Management responsibilities
Controls: PEOPLE-04, PEOPLE-05
PassingCurrentNot approved(29 d ago)
A.7.2.2Information security awareness, education and training
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
A.7.2.3Disciplinary process
Controls: PEOPLE-07
PassingNot currentNot approvedNot yet
A.7.3 Termination and change of employment
A.7.3.1Termination or change of employment responsibilities
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
A.8.1 Responsibility for assets
A.8.1.1Inventory of assets
Controls: IT-04, IT-05
PassingNot currentNot approvedNot yet
A.8.1.2Ownership of assets
Controls: IT-04, IT-05
PassingNot currentNot approvedNot yet
A.8.1.3Acceptable use of assets
Controls: IT-01
PassingNot currentApprovedNot yet
A.8.1.4Return of assets
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
A.8.2 Information classification
A.8.2.1Classification of information
Controls: DATA-01
PassingNot currentNot approvedNot yet
A.8.2.2Labelling of information
Controls: DATA-01
PassingNot currentNot approvedNot yet
A.8.2.3Handling of assets
Controls: DATA-01, DATA-05
PassingNot currentNot approvedNot yet
A.8.3 Media handling
A.8.3.1Management of removable mediaUnmappedUnmappedUnmappedNot yet
A.8.3.2Disposal of mediaUnmappedUnmappedUnmappedNot yet
A.8.3.3Physical media transferUnmappedUnmappedUnmappedNot yet
A.9.1 Business requirements of access control
A.9.1.1Access control policy
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
A.9.1.2Access to networks and network services
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
A.9.2 User access management
A.9.2.1User registration and de-registrationUnmappedUnmappedUnmappedNot yet
A.9.2.2User access provisioning
Controls: IAM-05, IAM-07
Not passingNot currentNot approved(29 d ago)
A.9.2.3Management of privileged access rights
Controls: IAM-04, IAM-06
PassingNot currentNot approved(29 d ago)
A.9.2.4Management of secret authentication information of usersUnmappedUnmappedUnmappedNot yet
A.9.2.5Review of user access rights
Controls: IAM-09
PassingCurrentNot approved(29 d ago)
A.9.2.6Removal or adjustment of access rightsUnmappedUnmappedUnmappedNot yet
A.9.3 User responsibilities
A.9.3.1Use of secret authentication information
Controls: IAM-03
PassingCurrentNot approved(29 d ago)
A.9.4 System and application access control
A.9.4.1Information access restriction
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
A.9.4.2Secure log-on procedures
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
A.9.4.3Password management system
Controls: IAM-03, IAM-08
PassingNot currentNot approved(8 h ago)
A.9.4.4Use of privileged utility programsUnmappedUnmappedUnmappedNot yet
A.9.4.5Access control to program source code
Controls: PDP-06
PassingCurrentApproved(4 mo ago)
A.10.1 Cryptographic controls
A.10.1.1Policy on the use of cryptographic controls
Controls: APP-01, DATA-02, DATA-03, DATA-06, IT-02
Not passingNot currentNot approved(8 h ago)
A.10.1.2Key managementUnmappedUnmappedUnmappedNot yet
A.11.1 Secure areas
A.11.1.1Physical security perimeter
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.1.2Physical entry controls
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.1.3Securing offices, rooms and facilitiesUnmappedUnmappedUnmappedNot yet
A.11.1.4Protecting against external and environmental threatsUnmappedUnmappedUnmappedNot yet
A.11.1.5Working in secure areas
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.1.6Delivery and loading areas
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.2 Equipment
A.11.2.1Equipment siting and protection
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.2.2Supporting utilitiesUnmappedUnmappedUnmappedNot yet
A.11.2.3Cabling security
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.11.2.4Equipment maintenanceUnmappedUnmappedUnmappedNot yet
A.11.2.5Removal of assets
Controls: IT-04
PassingNot currentNot approvedNot yet
A.11.2.6Security of equipment and assets off-premisesUnmappedUnmappedUnmappedNot yet
A.11.2.7Secure disposal or re-use of equipmentUnmappedUnmappedUnmappedNot yet
A.11.2.8Unattended user equipmentUnmappedUnmappedUnmappedNot yet
A.11.2.9Clear desk and clear screen policyUnmappedUnmappedUnmappedNot yet
A.12.1 Operational procedures and responsibilities
A.12.1.1Documented operating proceduresUnmappedUnmappedUnmappedNot yet
A.12.1.2Change management
Controls: CLOUD-02, CUST-04, PDP-02
Not passingNot currentNot approved(23 d ago)
A.12.1.3Capacity managementUnmappedUnmappedUnmappedNot yet
A.12.1.4Separation of development, testing and operational environments
Controls: CLOUD-06
PassingCurrentApproved(29 d ago)
A.12.2 Protection from malware
A.12.2.1Controls against malwareUnmappedUnmappedUnmappedNot yet
A.12.3 Backup
A.12.3.1Information backup
Controls: DATA-12, DATA-13, DATA-14, DATA-15
PassingNot currentNot approved(29 d ago)
A.12.4 Logging and monitoring
A.12.4.1Event logging
Controls: MON-01, MON-02, MON-03
Not passingNot currentNot approved(3 mo ago)
A.12.4.2Protection of log informationUnmappedUnmappedUnmappedNot yet
A.12.4.3Administrator and operator logs
Controls: MON-02
PassingNot currentNot approved(4 mo ago)
A.12.4.4Clock synchronisationUnmappedUnmappedUnmappedNot yet
A.12.5 Control of operational software
A.12.5.1Installation of software on operational systems
Controls: PDP-05
PassingCurrentNot approved(29 d ago)
A.12.6 Technical vulnerability management
A.12.6.1Management of technical vulnerabilities
Controls: CLOUD-05, IT-03, MON-05, MON-06
Not passingNot currentNot approved(8 h ago)
A.12.6.2Restrictions on software installationUnmappedUnmappedUnmappedNot yet
A.12.7 Information systems audit considerations
A.12.7.1Information systems audit controls
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
A.13.1 Network security management
A.13.1.1Network controls
Controls: CLOUD-03
PassingNot currentApprovedNot yet
A.13.1.2Security of network servicesUnmappedUnmappedUnmappedNot yet
A.13.1.3Segregation in networks
Controls: CLOUD-03
PassingNot currentApprovedNot yet
A.13.2 Information transfer
A.13.2.1Information transfer policies and procedures
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
A.13.2.2Agreements on information transfer
Controls: CUST-02, VEND-02
PassingNot currentNot approvedNot yet
A.13.2.3Electronic messagingUnmappedUnmappedUnmappedNot yet
A.13.2.4Confidentiality or non-disclosure agreements
Controls: PEOPLE-02
PassingNot currentNot approvedNot yet
A.14.1 Security requirements of information systems
A.14.1.1Information security requirements analysis and specificationUnmappedUnmappedUnmappedNot yet
A.14.1.2Securing application services on public networks
Controls: CLOUD-01, DATA-03
PassingCurrentNot approved(8 h ago)
A.14.1.3Protecting application services transactionsUnmappedUnmappedUnmappedNot yet
A.14.2 Security in development and support processes
A.14.2.1Secure development policy
Controls: APP-01
PassingCurrentApproved(4 mo ago)
A.14.2.2System change control procedures
Controls: CLOUD-02, PDP-02, PDP-03
Not passingNot currentNot approved(8 h ago)
A.14.2.3Technical review of applications after operating platform changes
Controls: PDP-14
PassingCurrentApproved(4 mo ago)
A.14.2.4Restrictions on changes to software packages
Controls: PDP-02
PassingNot currentNot approved(23 d ago)
A.14.2.5Secure system engineering principles
Controls: CLOUD-04
PassingNot currentApprovedNot yet
A.14.2.6Secure development environment
Controls: CLOUD-06, PDP-06
PassingCurrentApproved(29 d ago)
A.14.2.7Outsourced development
Controls: PDP-03
Not passingCurrentNot approved(8 h ago)
A.14.2.8System security testing
Controls: APP-02, MON-04, PDP-04
Not passingNot currentNot approved(8 h ago)
A.14.2.9System acceptance testing
Controls: PDP-04
PassingNot currentNot approved(29 d ago)
A.14.3 Test data
A.14.3.1Protection of test dataUnmappedUnmappedUnmappedNot yet
A.15.1 Information security in supplier relationships
A.15.1.1Information security policy for supplier relationships
Controls: VEND-01, VEND-03
PassingNot currentNot approvedNot yet
A.15.1.2Addressing security within supplier agreements
Controls: VEND-02
PassingNot currentNot approvedNot yet
A.15.1.3Information and communication technology supply chain
Controls: VEND-03
PassingNot currentNot approvedNot yet
A.15.2 Supplier service delivery management
A.15.2.1Monitoring and review of supplier services
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
A.15.2.2Managing changes to supplier services
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
A.16.1 Management of information security incidents and improvements
A.16.1.1Responsibilities and procedures
Controls: BIZ-02, BIZ-21
PassingNot currentNot approved(3 mo ago)
A.16.1.2Reporting information security events
Controls: BIZ-13, CUST-01
PassingNot currentApproved(29 d ago)
A.16.1.3Reporting information security weaknesses
Controls: BIZ-13
PassingCurrentApproved(29 d ago)
A.16.1.4Assessment of and decision on information security events
Controls: BIZ-03, MON-03
Not passingNot currentNot approved(8 h ago)
A.16.1.5Response to information security incidents
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
A.16.1.6Learning from information security incidents
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)
A.16.1.7Collection of evidenceUnmappedUnmappedUnmappedNot yet
A.17.1 Information security continuity
A.17.1.1Planning information security continuity
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
A.17.1.2Implementing information security continuity
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
A.17.1.3Verify, review and evaluate information security continuity
Controls: BIZ-20, BIZ-21, DATA-15
PassingNot currentNot approved(4 mo ago)
A.17.2 Redundancies
A.17.2.1Availability of information processing facilitiesUnmappedUnmappedUnmappedNot yet
A.18.1 Compliance with legal and contractual requirements
A.18.1.1Identification of applicable legislation and contractual requirements
Controls: CUST-02
PassingNot currentApprovedNot yet
A.18.1.2Intellectual property rightsUnmappedUnmappedUnmappedNot yet
A.18.1.3Protection of records
Controls: DATA-04
PassingNot currentNot approvedNot yet
A.18.1.4Privacy and protection of personally identifiable information
Controls: LEGAL-01
PassingNot currentApprovedNot yet
A.18.1.5Regulation of cryptographic controlsUnmappedUnmappedUnmappedNot yet
A.18.2 Information security reviews
A.18.2.1Independent review of information securityUnmappedUnmappedUnmappedNot yet
A.18.2.2Compliance with security policies and standards
Controls: BIZ-08, BIZ-09
PassingNot currentApprovedNot yet
A.18.2.3Technical compliance review
Controls: MON-04, MON-05
Not passingNot currentNot approved(8 h ago)