ISO/IEC 27001:2022
Version: 2022 (incl. Amd 1:2024)
International standard for establishing, running and continually improving an information security management system (ISMS), with 93 reference controls in Annex A. Any organization can certify against it through an accredited certification body.
Where we stand
Controls
70%
Evidence
21%
Policies
21%
82 of 118 clauses mapped to adopted controls · 1 known gap
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 4 Context of the organization | |||||
| 4.1 | Understanding the organization and its context | Unmapped | Unmapped | Unmapped | Not yet |
| 4.2 | Understanding the needs and expectations of interested parties | Unmapped | Unmapped | Unmapped | Not yet |
| 4.3 | Determining the scope of the information security management system | Unmapped | Unmapped | Unmapped | Not yet |
| 4.4 | Information security management system Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5 Leadership | |||||
| 5.1 | Leadership and commitment Controls: BIZ-11, BIZ-12, BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.2 | Policy Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.3 | Organizational roles, responsibilities and authorities Controls: BIZ-15, PEOPLE-08, PEOPLE-09 | Not passing | Not current | Not approved | Not yet |
| 6.1 Actions to address risks and opportunities | |||||
| 6.1.1 | General Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| 6.1.2 | Information security risk assessment Controls: BIZ-04, BIZ-05, BIZ-06 | Passing | Not current | Not approved | (4 mo ago) |
| 6.1.3 | Information security risk treatment Controls: BIZ-04, BIZ-07, BIZ-10 | Not passing | Not current | Not approved | Not yet |
| 6 Planning | |||||
| 6.2 | Information security objectives and planning to achieve them | Unmapped | Unmapped | Unmapped | Not yet |
| 6.3 | Planning of changes | Unmapped | Unmapped | Unmapped | Not yet |
| 7 Support | |||||
| 7.1 | Resources | Unmapped | Unmapped | Unmapped | Not yet |
| 7.2 | Competence | Unmapped | Unmapped | Unmapped | Not yet |
| 7.3 | Awareness Controls: PEOPLE-04, PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 7.4 | Communication Controls: BIZ-13, CUST-01, CUST-03, CUST-04 | Not passing | Not current | Approved | (29 d ago) |
| 7.5 | Documented information | Unmapped | Unmapped | Unmapped | Not yet |
| 8 Operation | |||||
| 8.1 | Operational planning and control Controls: BIZ-07, PDP-02, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| 8.2 | Information security risk assessment Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| 8.3 | Information security risk treatment Controls: BIZ-05, BIZ-07 | Passing | Not current | Not approved | (4 mo ago) |
| 9 Performance evaluation | |||||
| 9.1 | Monitoring, measurement, analysis and evaluation Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| 9.2 | Internal audit | Unmapped | Unmapped | Unmapped | Not yet |
| 9.3 | Management review | Unmapped | Unmapped | Unmapped | Not yet |
| 10 Improvement | |||||
| 10.1 | Continual improvement Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| 10.2 | Nonconformity and corrective action Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| A.5 Organizational controls | |||||
| A.5.1 | Policies for information security Controls: BIZ-14, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| A.5.2 | Information security roles and responsibilities Controls: BIZ-15, PEOPLE-08, PEOPLE-09 | Not passing | Not current | Not approved | Not yet |
| A.5.3 | Segregation of duties Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| A.5.4 | Management responsibilities Controls: PEOPLE-04, PEOPLE-05 | Passing | Current | Not approved | (29 d ago) |
| A.5.5 | Contact with authorities Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| A.5.6 | Contact with special interest groups | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.7 | Threat intelligence | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.8 | Information security in project management Controls: PDP-01, PDP-14 | Passing | Not current | Approved | (4 mo ago) |
| A.5.9 | Inventory of information and other associated assets Controls: IT-04, IT-05 | Passing | Not current | Not approved | Not yet |
| A.5.10 | Acceptable use of information and other associated assets Controls: IT-01 | Passing | Not current | Approved | Not yet |
| A.5.11 | Return of assets Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| A.5.12 | Classification of information Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| A.5.13 | Labelling of information Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| A.5.14 | Information transfer Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| A.5.15 | Access control Controls: IAM-01, IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| A.5.16 | Identity management Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| A.5.17 | Authentication information Controls: IAM-02, IAM-03, IAM-08 | Not passing | Not current | Not approved | (8 h ago) |
| A.5.18 | Access rights Controls: IAM-04, IAM-05, IAM-07, IAM-09 | Not passing | Not current | Not approved | (29 d ago) |
| A.5.19 | Information security in supplier relationships Controls: VEND-01, VEND-03 | Passing | Not current | Not approved | Not yet |
| A.5.20 | Addressing information security within supplier agreements Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| A.5.21 | Managing information security in the information and communication technology (ICT) supply chain Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| A.5.22 | Monitoring, review and change management of supplier services Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| A.5.23 | Information security for use of cloud services | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.24 | Information security incident management planning and preparation Controls: BIZ-02, BIZ-21 | Passing | Not current | Not approved | (3 mo ago) |
| A.5.25 | Assessment and decision on information security events Controls: BIZ-02, BIZ-03, MON-03 | Not passing | Not current | Not approved | (8 h ago) |
| A.5.26 | Response to information security incidents Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| A.5.27 | Learning from information security incidents Controls: BIZ-03, BIZ-21 | Passing | Current | Not approved | (8 h ago) |
| A.5.28 | Collection of evidence | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.29 | Information security during disruption Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| A.5.30 | ICT readiness for business continuity Controls: BIZ-01, BIZ-20, DATA-13, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| A.5.31 | Legal, statutory, regulatory and contractual requirements Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| A.5.32 | Intellectual property rights | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.33 | Protection of records Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| A.5.34 | Privacy and protection of personally identifiable information (PII) Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| A.5.35 | Independent review of information security | Unmapped | Unmapped | Unmapped | Not yet |
| A.5.36 | Compliance with policies, rules and standards for information security Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| A.5.37 | Documented operating procedures | Unmapped | Unmapped | Unmapped | Not yet |
| A.6 People controls | |||||
| A.6.1 | Screening Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| A.6.2 | Terms and conditions of employment Controls: PEOPLE-02, PEOPLE-04, PEOPLE-08, PEOPLE-15 | Not passing | Not current | Not approved | (4 mo ago) |
| A.6.3 | Information security awareness, education and training Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| A.6.4 | Disciplinary process Controls: PEOPLE-07 | Passing | Not current | Not approved | Not yet |
| A.6.5 | Responsibilities after termination or change of employment Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| A.6.6 | Confidentiality or non-disclosure agreements Controls: PEOPLE-02 | Passing | Not current | Not approved | Not yet |
| A.6.7 | Remote working | Unmapped | Unmapped | Unmapped | Not yet |
| A.6.8 | Information security event reporting Controls: BIZ-13 | Passing | Current | Approved | (29 d ago) |
| A.7 Physical controls | |||||
| A.7.1 | Physical security perimeters Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.2 | Physical entry Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.3 | Securing offices, rooms and facilities Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.4 | Physical security monitoring Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.5 | Protecting against physical and environmental threats | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.6 | Working in secure areas Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.7 | Clear desk and clear screen | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.8 | Equipment siting and protection Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.9 | Security of assets off-premises | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.10 | Storage media | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.11 | Supporting utilities | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.12 | Cabling security Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| A.7.13 | Equipment maintenance | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.14 | Secure disposal or re-use of equipment | Unmapped | Unmapped | Unmapped | Not yet |
| A.8 Technological controls | |||||
| A.8.1 | User end point devices Controls: IT-02, IT-03 | Not passing | Not current | Approved | (8 h ago) |
| A.8.2 | Privileged access rights Controls: IAM-04, IAM-06 | Passing | Not current | Not approved | (29 d ago) |
| A.8.3 | Information access restriction Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| A.8.4 | Access to source code Controls: PDP-06 | Passing | Current | Approved | (4 mo ago) |
| A.8.5 | Secure authentication Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.6 | Capacity management | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.7 | Protection against malware | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.8 | Management of technical vulnerabilities Controls: CLOUD-05, IT-03, MON-04, MON-05, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.9 | Configuration management Controls: CLOUD-02, CLOUD-04 | Passing | Not current | Approved | (29 d ago) |
| A.8.10 | Information deletion Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| A.8.11 | Data masking | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.12 | Data leakage prevention | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.13 | Information backup Controls: DATA-12, DATA-13, DATA-14, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| A.8.14 | Redundancy of information processing facilities | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.15 | Logging Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| A.8.16 | Monitoring activities Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| A.8.17 | Clock synchronization | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.18 | Use of privileged utility programs | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.19 | Installation of software on operational systems Controls: PDP-05 | Passing | Current | Not approved | (29 d ago) |
| A.8.20 | Networks security Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| A.8.21 | Security of network services Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| A.8.22 | Segregation of networks Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| A.8.23 | Web filtering | Known gap | Known gap | Known gap | Not yet |
| A.8.24 | Use of cryptography Controls: CLOUD-01, DATA-02, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.25 | Secure development life cycle Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| A.8.26 | Application security requirements | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.27 | Secure system architecture and engineering principles | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.28 | Secure coding Controls: APP-01, APP-02, PDP-03 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.29 | Security testing in development and acceptance Controls: APP-02, MON-04, PDP-04 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.30 | Outsourced development Controls: PDP-03 | Not passing | Current | Not approved | (8 h ago) |
| A.8.31 | Separation of development, test and production environments Controls: CLOUD-06, PDP-05 | Passing | Current | Not approved | (29 d ago) |
| A.8.32 | Change management Controls: PDP-02, PDP-03, PDP-14 | Not passing | Not current | Not approved | (8 h ago) |
| A.8.33 | Test information | Unmapped | Unmapped | Unmapped | Not yet |
| A.8.34 | Protection of information systems during audit testing Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
