| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Statement of Applicability | ||||||||||||||||||||||||||
2 | Section | Information security control | Applicable | Justification | Implementation Method | Status | |||||||||||||||||||||
3 | A5 | Organizational controls | |||||||||||||||||||||||||
4 | A.5.1 | Policies for information security | Yes | Not implemented | |||||||||||||||||||||||
5 | A.5.2 | Information security roles and responsibilities | Yes | Not implemented | |||||||||||||||||||||||
6 | A.5.3 | Segregation of duties | Yes | Not implemented | |||||||||||||||||||||||
7 | A.5.4 | Management responsibilities | Yes | Not implemented | |||||||||||||||||||||||
8 | A.5.5 | Contact with authorities | Yes | Not implemented | |||||||||||||||||||||||
9 | A.5.6 | Contact with special interest groups | Yes | Not implemented | |||||||||||||||||||||||
10 | A.5.7 | Threat intelligence | Yes | Not implemented | |||||||||||||||||||||||
11 | A.5.8 | Information security in projectmanagement | Yes | Not implemented | |||||||||||||||||||||||
12 | A.5.9 | Inventory of information and other associated assets | Yes | Not implemented | |||||||||||||||||||||||
13 | A.5.10 | Acceptable use of information and other associated assets | Yes | Not implemented | |||||||||||||||||||||||
14 | A.5.11 | Return of assets | Yes | Not implemented | |||||||||||||||||||||||
15 | A.5.12 | Classification of information | Yes | Not implemented | |||||||||||||||||||||||
16 | A.5.13 | Labelling of information | Yes | Not implemented | |||||||||||||||||||||||
17 | A.5.14 | Information transfer | Yes | Not implemented | |||||||||||||||||||||||
18 | A.5.15 | Access control | Yes | Not implemented | |||||||||||||||||||||||
19 | A.5.16 | Identity management | Yes | Not implemented | |||||||||||||||||||||||
20 | A.5.17 | Authentication information | Yes | Not implemented | |||||||||||||||||||||||
21 | A.5.18 | Access rights | Yes | Not implemented | |||||||||||||||||||||||
22 | A.5.19 | Information security in supplier relationships | Yes | Not implemented | |||||||||||||||||||||||
23 | A.5.20 | Addressing information security within supplier agreements | Yes | Not implemented | |||||||||||||||||||||||
24 | A.5.21 | Managing information security in the information and communication technology (ICT) supply-chain | Yes | Not implemented | |||||||||||||||||||||||
25 | A.5.22 | Monitoring, review and change management of supplier services | Yes | Not implemented | |||||||||||||||||||||||
26 | A.5.23 | Information security for use of cloud services | Yes | Not implemented | |||||||||||||||||||||||
27 | A.5.24 | Information security incident management planning and preparation | Yes | Not implemented | |||||||||||||||||||||||
28 | A.5.25 | Assessment and decision on information security events | Yes | Not implemented | |||||||||||||||||||||||
29 | A.5.26 | Response to information security incidents | Yes | Not implemented | |||||||||||||||||||||||
30 | A.5.27 | Learning from information security incidents | Yes | Not implemented | |||||||||||||||||||||||
31 | A.5.28 | Collection of evidence | Yes | Not implemented | |||||||||||||||||||||||
32 | A.5.29 | Information security during disruption | Yes | Not implemented | |||||||||||||||||||||||
33 | A.5.30 | ICT readiness for business continuity | Yes | Not implemented | |||||||||||||||||||||||
34 | A.5.31 | Legal, statutory, regulatory and contractual requirements | Yes | Not implemented | |||||||||||||||||||||||
35 | A.5.32 | Intellectual property rights | Yes | Not implemented | |||||||||||||||||||||||
36 | A.5.33 | Protection of records | Yes | Not implemented | |||||||||||||||||||||||
37 | A.5.34 | Privacy and protection of personal identifiable information (PII) | Yes | Not implemented | |||||||||||||||||||||||
38 | A.5.35 | Independent review of information security | Yes | Not implemented | |||||||||||||||||||||||
39 | A.5.36 | Compliance with policies, rules and standards for information security | Yes | Not implemented | |||||||||||||||||||||||
40 | A.5.37 | Documented operating procedures | Yes | Not implemented | |||||||||||||||||||||||
41 | A6 | People controls | |||||||||||||||||||||||||
42 | A.6.1 | Screening | Yes | Not implemented | |||||||||||||||||||||||
43 | A.6.2 | Terms and conditions of employment | Yes | Not implemented | |||||||||||||||||||||||
44 | A.6.3 | Information security awareness, education and training | Yes | Not implemented | |||||||||||||||||||||||
45 | A.6.4 | Disciplinary process | Yes | Not implemented | |||||||||||||||||||||||
46 | A.6.5 | Responsibilities after termination or change of employment | Yes | Not implemented | |||||||||||||||||||||||
47 | A.6.6 | Confidentiality or non-disclosure agreements | Yes | Not implemented | |||||||||||||||||||||||
48 | A.6.7 | Remote working | Yes | Not implemented | |||||||||||||||||||||||
49 | A.6.8 | Information security event reporting | Yes | Not implemented | |||||||||||||||||||||||
50 | A7 | Physical controls | |||||||||||||||||||||||||
51 | A.7.1 | Physical security perimeters | Yes | Not implemented | |||||||||||||||||||||||
52 | A.7.2 | Physical entry | Yes | Not implemented | |||||||||||||||||||||||
53 | A.7.3 | Securing offices, rooms and facilities | Yes | Not implemented | |||||||||||||||||||||||
54 | A.7.4 | Physical security monitoring | Yes | Not implemented | |||||||||||||||||||||||
55 | A.7.5 | Protecting against physical and environmental threats | Yes | Not implemented | |||||||||||||||||||||||
56 | A.7.6 | Working in secure areas | Yes | Not implemented | |||||||||||||||||||||||
57 | A.7.7 | Clear desk and clear screen | Yes | Not implemented | |||||||||||||||||||||||
58 | A.7.8 | Equipment siting and protection | Yes | Not implemented | |||||||||||||||||||||||
59 | A.7.9 | Security of assets off-premises | Yes | Not implemented | |||||||||||||||||||||||
60 | A.7.10 | Storage media | Yes | Not implemented | |||||||||||||||||||||||
61 | A.7.11 | Supporting utilities | Yes | Not implemented | |||||||||||||||||||||||
62 | A.7.12 | Cabling security | Yes | Not implemented | |||||||||||||||||||||||
63 | A.7.13 | Equipment maintenance | Yes | Not implemented | |||||||||||||||||||||||
64 | A.7.14 | Secure disposal or re-use of equipment | Yes | Not implemented | |||||||||||||||||||||||
65 | A8 | Technological controls | |||||||||||||||||||||||||
66 | A.8.1 | User end point devices | Yes | Not implemented | |||||||||||||||||||||||
67 | A.8.2 | Privileged access rights | Yes | Not implemented | |||||||||||||||||||||||
68 | A.8.3 | Information access restriction | Yes | Not implemented | |||||||||||||||||||||||
69 | A.8.4 | Access to source code | Yes | Not implemented | |||||||||||||||||||||||
70 | A.8.5 | Secure authentication | Yes | Not implemented | |||||||||||||||||||||||
71 | A.8.6 | Capacity management | Yes | Not implemented | |||||||||||||||||||||||
72 | A.8.7 | Protection against malware | Yes | Not implemented | |||||||||||||||||||||||
73 | A.8.8 | Management of technical vulnerabilities | Yes | Not implemented | |||||||||||||||||||||||
74 | A.8.9 | Configuration management | Yes | Not implemented | |||||||||||||||||||||||
75 | A.8.10 | Information deletion | Yes | Not implemented | |||||||||||||||||||||||
76 | A.8.11 | Data masking | Yes | Not implemented | |||||||||||||||||||||||
77 | A.8.12 | Data leakage prevention | Yes | Not implemented | |||||||||||||||||||||||
78 | A.8.13 | Information backup | Yes | Not implemented | |||||||||||||||||||||||
79 | A.8.14 | Redundancy of information processing facilities | Yes | Not implemented | |||||||||||||||||||||||
80 | A.8.15 | Logging | Yes | Not implemented | |||||||||||||||||||||||
81 | A.8.16 | Monitoring activities | Yes | Not implemented | |||||||||||||||||||||||
82 | A.8.17 | Clock synchronization | Yes | Not implemented | |||||||||||||||||||||||
83 | A.8.18 | Use of privileged utility programs | Yes | Not implemented | |||||||||||||||||||||||
84 | A.8.19 | Installation of software on operational systems | Yes | Not implemented | |||||||||||||||||||||||
85 | A.8.20 | Networks security | Yes | Not implemented | |||||||||||||||||||||||
86 | A.8.21 | Security of network services | Yes | Not implemented | |||||||||||||||||||||||
87 | A.8.22 | Segregation of networks | Yes | Not implemented | |||||||||||||||||||||||
88 | A.8.23 | Web filtering | Yes | Not implemented | |||||||||||||||||||||||
89 | A.8.24 | Use of cryptography | Yes | Not implemented | |||||||||||||||||||||||
90 | A.8.25 | Secure development life cycle | Yes | Not implemented | |||||||||||||||||||||||
91 | A.8.26 | Application security requirements | Yes | Not implemented | |||||||||||||||||||||||
92 | A.8.27 | Secure system architecture and engineering principles | Yes | Not implemented | |||||||||||||||||||||||
93 | A.8.28 | Secure coding | Yes | Not implemented | |||||||||||||||||||||||
94 | A.8.29 | Security testing in development and acceptance | Yes | Not implemented | |||||||||||||||||||||||
95 | A.8.30 | Outsourced development | Yes | Not implemented | |||||||||||||||||||||||
96 | A.8.31 | Separation of development, test and production environments | Yes | Not implemented | |||||||||||||||||||||||
97 | A.8.32 | Change management | Yes | Not implemented | |||||||||||||||||||||||
98 | A.8.33 | Test information | Yes | Not implemented | |||||||||||||||||||||||
99 | A.8.34 | Protection of information systems during audit testing | Yes | Not implemented | |||||||||||||||||||||||
100 | 93 | Number of controls | Number of controls | Number of controls | |||||||||||||||||||||||