FintastIQTrust Center
LoginBook a Consultation
Framework

ISO/IEC 27001:2022

Version: 2022 (incl. Amd 1:2024)

International standard for establishing, running and continually improving an information security management system (ISMS), with 93 reference controls in Annex A. Any organization can certify against it through an accredited certification body.

Official source

Summary

Where we stand

Controls
70%
Evidence
21%
Policies
21%

82 of 118 clauses mapped to adopted controls · 1 known gap

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
4 Context of the organization
4.1Understanding the organization and its contextUnmappedUnmappedUnmappedNot yet
4.2Understanding the needs and expectations of interested partiesUnmappedUnmappedUnmappedNot yet
4.3Determining the scope of the information security management systemUnmappedUnmappedUnmappedNot yet
4.4Information security management system
Controls: BIZ-14
PassingNot currentNot approvedNot yet
5 Leadership
5.1Leadership and commitment
Controls: BIZ-11, BIZ-12, BIZ-14
PassingNot currentNot approvedNot yet
5.2Policy
Controls: BIZ-14
PassingNot currentNot approvedNot yet
5.3Organizational roles, responsibilities and authorities
Controls: BIZ-15, PEOPLE-08, PEOPLE-09
Not passingNot currentNot approvedNot yet
6.1 Actions to address risks and opportunities
6.1.1General
Controls: BIZ-04
PassingNot currentNot approvedNot yet
6.1.2Information security risk assessment
Controls: BIZ-04, BIZ-05, BIZ-06
PassingNot currentNot approved(4 mo ago)
6.1.3Information security risk treatment
Controls: BIZ-04, BIZ-07, BIZ-10
Not passingNot currentNot approvedNot yet
6 Planning
6.2Information security objectives and planning to achieve themUnmappedUnmappedUnmappedNot yet
6.3Planning of changesUnmappedUnmappedUnmappedNot yet
7 Support
7.1ResourcesUnmappedUnmappedUnmappedNot yet
7.2CompetenceUnmappedUnmappedUnmappedNot yet
7.3Awareness
Controls: PEOPLE-04, PEOPLE-06
Not passingCurrentApproved(8 h ago)
7.4Communication
Controls: BIZ-13, CUST-01, CUST-03, CUST-04
Not passingNot currentApproved(29 d ago)
7.5Documented informationUnmappedUnmappedUnmappedNot yet
8 Operation
8.1Operational planning and control
Controls: BIZ-07, PDP-02, VEND-04
Not passingNot currentNot approved(8 h ago)
8.2Information security risk assessment
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
8.3Information security risk treatment
Controls: BIZ-05, BIZ-07
PassingNot currentNot approved(4 mo ago)
9 Performance evaluation
9.1Monitoring, measurement, analysis and evaluation
Controls: BIZ-08
PassingNot currentApprovedNot yet
9.2Internal auditUnmappedUnmappedUnmappedNot yet
9.3Management reviewUnmappedUnmappedUnmappedNot yet
10 Improvement
10.1Continual improvement
Controls: BIZ-09
PassingNot currentApprovedNot yet
10.2Nonconformity and corrective action
Controls: BIZ-09
PassingNot currentApprovedNot yet
A.5 Organizational controls
A.5.1Policies for information security
Controls: BIZ-14, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
A.5.2Information security roles and responsibilities
Controls: BIZ-15, PEOPLE-08, PEOPLE-09
Not passingNot currentNot approvedNot yet
A.5.3Segregation of duties
Controls: BIZ-15
PassingNot currentNot approvedNot yet
A.5.4Management responsibilities
Controls: PEOPLE-04, PEOPLE-05
PassingCurrentNot approved(29 d ago)
A.5.5Contact with authorities
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
A.5.6Contact with special interest groupsUnmappedUnmappedUnmappedNot yet
A.5.7Threat intelligenceUnmappedUnmappedUnmappedNot yet
A.5.8Information security in project management
Controls: PDP-01, PDP-14
PassingNot currentApproved(4 mo ago)
A.5.9Inventory of information and other associated assets
Controls: IT-04, IT-05
PassingNot currentNot approvedNot yet
A.5.10Acceptable use of information and other associated assets
Controls: IT-01
PassingNot currentApprovedNot yet
A.5.11Return of assets
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
A.5.12Classification of information
Controls: DATA-01
PassingNot currentNot approvedNot yet
A.5.13Labelling of information
Controls: DATA-01
PassingNot currentNot approvedNot yet
A.5.14Information transfer
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
A.5.15Access control
Controls: IAM-01, IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
A.5.16Identity management
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
A.5.17Authentication information
Controls: IAM-02, IAM-03, IAM-08
Not passingNot currentNot approved(8 h ago)
A.5.18Access rights
Controls: IAM-04, IAM-05, IAM-07, IAM-09
Not passingNot currentNot approved(29 d ago)
A.5.19Information security in supplier relationships
Controls: VEND-01, VEND-03
PassingNot currentNot approvedNot yet
A.5.20Addressing information security within supplier agreements
Controls: VEND-02
PassingNot currentNot approvedNot yet
A.5.21Managing information security in the information and communication technology (ICT) supply chain
Controls: VEND-03
PassingNot currentNot approvedNot yet
A.5.22Monitoring, review and change management of supplier services
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
A.5.23Information security for use of cloud servicesUnmappedUnmappedUnmappedNot yet
A.5.24Information security incident management planning and preparation
Controls: BIZ-02, BIZ-21
PassingNot currentNot approved(3 mo ago)
A.5.25Assessment and decision on information security events
Controls: BIZ-02, BIZ-03, MON-03
Not passingNot currentNot approved(8 h ago)
A.5.26Response to information security incidents
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
A.5.27Learning from information security incidents
Controls: BIZ-03, BIZ-21
PassingCurrentNot approved(8 h ago)
A.5.28Collection of evidenceUnmappedUnmappedUnmappedNot yet
A.5.29Information security during disruption
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
A.5.30ICT readiness for business continuity
Controls: BIZ-01, BIZ-20, DATA-13, DATA-15
PassingNot currentNot approved(29 d ago)
A.5.31Legal, statutory, regulatory and contractual requirements
Controls: CUST-02
PassingNot currentApprovedNot yet
A.5.32Intellectual property rightsUnmappedUnmappedUnmappedNot yet
A.5.33Protection of records
Controls: DATA-04
PassingNot currentNot approvedNot yet
A.5.34Privacy and protection of personally identifiable information (PII)
Controls: LEGAL-01
PassingNot currentApprovedNot yet
A.5.35Independent review of information securityUnmappedUnmappedUnmappedNot yet
A.5.36Compliance with policies, rules and standards for information security
Controls: BIZ-08
PassingNot currentApprovedNot yet
A.5.37Documented operating proceduresUnmappedUnmappedUnmappedNot yet
A.6 People controls
A.6.1Screening
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
A.6.2Terms and conditions of employment
Controls: PEOPLE-02, PEOPLE-04, PEOPLE-08, PEOPLE-15
Not passingNot currentNot approved(4 mo ago)
A.6.3Information security awareness, education and training
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
A.6.4Disciplinary process
Controls: PEOPLE-07
PassingNot currentNot approvedNot yet
A.6.5Responsibilities after termination or change of employment
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
A.6.6Confidentiality or non-disclosure agreements
Controls: PEOPLE-02
PassingNot currentNot approvedNot yet
A.6.7Remote workingUnmappedUnmappedUnmappedNot yet
A.6.8Information security event reporting
Controls: BIZ-13
PassingCurrentApproved(29 d ago)
A.7 Physical controls
A.7.1Physical security perimeters
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.2Physical entry
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.3Securing offices, rooms and facilities
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.4Physical security monitoring
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.5Protecting against physical and environmental threatsUnmappedUnmappedUnmappedNot yet
A.7.6Working in secure areas
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.7Clear desk and clear screenUnmappedUnmappedUnmappedNot yet
A.7.8Equipment siting and protection
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.9Security of assets off-premisesUnmappedUnmappedUnmappedNot yet
A.7.10Storage mediaUnmappedUnmappedUnmappedNot yet
A.7.11Supporting utilitiesUnmappedUnmappedUnmappedNot yet
A.7.12Cabling security
Controls: PHYS-01
PassingNot currentNot approvedNot yet
A.7.13Equipment maintenanceUnmappedUnmappedUnmappedNot yet
A.7.14Secure disposal or re-use of equipmentUnmappedUnmappedUnmappedNot yet
A.8 Technological controls
A.8.1User end point devices
Controls: IT-02, IT-03
Not passingNot currentApproved(8 h ago)
A.8.2Privileged access rights
Controls: IAM-04, IAM-06
PassingNot currentNot approved(29 d ago)
A.8.3Information access restriction
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
A.8.4Access to source code
Controls: PDP-06
PassingCurrentApproved(4 mo ago)
A.8.5Secure authentication
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
A.8.6Capacity managementUnmappedUnmappedUnmappedNot yet
A.8.7Protection against malwareUnmappedUnmappedUnmappedNot yet
A.8.8Management of technical vulnerabilities
Controls: CLOUD-05, IT-03, MON-04, MON-05, MON-06
Not passingNot currentNot approved(8 h ago)
A.8.9Configuration management
Controls: CLOUD-02, CLOUD-04
PassingNot currentApproved(29 d ago)
A.8.10Information deletion
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
A.8.11Data maskingUnmappedUnmappedUnmappedNot yet
A.8.12Data leakage preventionUnmappedUnmappedUnmappedNot yet
A.8.13Information backup
Controls: DATA-12, DATA-13, DATA-14, DATA-15
PassingNot currentNot approved(29 d ago)
A.8.14Redundancy of information processing facilitiesUnmappedUnmappedUnmappedNot yet
A.8.15Logging
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
A.8.16Monitoring activities
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
A.8.17Clock synchronizationUnmappedUnmappedUnmappedNot yet
A.8.18Use of privileged utility programsUnmappedUnmappedUnmappedNot yet
A.8.19Installation of software on operational systems
Controls: PDP-05
PassingCurrentNot approved(29 d ago)
A.8.20Networks security
Controls: CLOUD-03
PassingNot currentApprovedNot yet
A.8.21Security of network services
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
A.8.22Segregation of networks
Controls: CLOUD-03
PassingNot currentApprovedNot yet
A.8.23Web filteringKnown gapKnown gapKnown gapNot yet
A.8.24Use of cryptography
Controls: CLOUD-01, DATA-02, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
A.8.25Secure development life cycle
Controls: APP-01
PassingCurrentApproved(4 mo ago)
A.8.26Application security requirementsUnmappedUnmappedUnmappedNot yet
A.8.27Secure system architecture and engineering principlesUnmappedUnmappedUnmappedNot yet
A.8.28Secure coding
Controls: APP-01, APP-02, PDP-03
Not passingNot currentNot approved(8 h ago)
A.8.29Security testing in development and acceptance
Controls: APP-02, MON-04, PDP-04
Not passingNot currentNot approved(8 h ago)
A.8.30Outsourced development
Controls: PDP-03
Not passingCurrentNot approved(8 h ago)
A.8.31Separation of development, test and production environments
Controls: CLOUD-06, PDP-05
PassingCurrentNot approved(29 d ago)
A.8.32Change management
Controls: PDP-02, PDP-03, PDP-14
Not passingNot currentNot approved(8 h ago)
A.8.33Test informationUnmappedUnmappedUnmappedNot yet
A.8.34Protection of information systems during audit testing
Controls: MON-04
Not passingCurrentNot approved(8 h ago)