ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Statement of Applicability
2
SectionInformation security controlApplicableJustificationImplementation MethodStatus
3
A5Organizational controls
4
A.5.1Policies for information securityYesNot implemented
5
A.5.2Information security roles and responsibilitiesYesNot implemented
6
A.5.3Segregation of dutiesYesNot implemented
7
A.5.4Management responsibilitiesYesNot implemented
8
A.5.5Contact with authoritiesYesNot implemented
9
A.5.6Contact with special interest groupsYesNot implemented
10
A.5.7Threat intelligenceYesNot implemented
11
A.5.8Information security in projectmanagementYesNot implemented
12
A.5.9Inventory of information and other associated assetsYesNot implemented
13
A.5.10Acceptable use of information and other associated assetsYesNot implemented
14
A.5.11Return of assetsYesNot implemented
15
A.5.12Classification of informationYesNot implemented
16
A.5.13Labelling of informationYesNot implemented
17
A.5.14Information transferYesNot implemented
18
A.5.15Access controlYesNot implemented
19
A.5.16Identity managementYesNot implemented
20
A.5.17Authentication informationYesNot implemented
21
A.5.18Access rightsYesNot implemented
22
A.5.19Information security in supplier relationshipsYesNot implemented
23
A.5.20Addressing information security within supplier agreementsYesNot implemented
24
A.5.21Managing information security in the information
and communication technology (ICT) supply-chain
YesNot implemented
25
A.5.22Monitoring, review and change management of supplier servicesYesNot implemented
26
A.5.23Information security for use of cloud servicesYesNot implemented
27
A.5.24Information security incident management planning and preparationYesNot implemented
28
A.5.25Assessment and decision on information security eventsYesNot implemented
29
A.5.26Response to information security incidentsYesNot implemented
30
A.5.27Learning from information security incidentsYesNot implemented
31
A.5.28Collection of evidenceYesNot implemented
32
A.5.29Information security during disruptionYesNot implemented
33
A.5.30ICT readiness for business continuityYesNot implemented
34
A.5.31Legal, statutory, regulatory and contractual requirementsYesNot implemented
35
A.5.32Intellectual property rightsYesNot implemented
36
A.5.33Protection of recordsYesNot implemented
37
A.5.34Privacy and protection of personal identifiable information (PII)YesNot implemented
38
A.5.35Independent review of information securityYesNot implemented
39
A.5.36Compliance with policies, rules and standards for information securityYesNot implemented
40
A.5.37Documented operating proceduresYesNot implemented
41
A6People controls
42
A.6.1ScreeningYesNot implemented
43
A.6.2Terms and conditions of employmentYesNot implemented
44
A.6.3Information security awareness, education and trainingYesNot implemented
45
A.6.4Disciplinary processYesNot implemented
46
A.6.5Responsibilities after termination or change of employmentYesNot implemented
47
A.6.6Confidentiality or non-disclosure agreementsYesNot implemented
48
A.6.7Remote workingYesNot implemented
49
A.6.8Information security event reportingYesNot implemented
50
A7Physical controls
51
A.7.1Physical security perimetersYesNot implemented
52
A.7.2Physical entryYesNot implemented
53
A.7.3Securing offices, rooms and facilitiesYesNot implemented
54
A.7.4Physical security monitoringYesNot implemented
55
A.7.5Protecting against physical and environmental threatsYesNot implemented
56
A.7.6Working in secure areasYesNot implemented
57
A.7.7Clear desk and clear screenYesNot implemented
58
A.7.8Equipment siting and protectionYesNot implemented
59
A.7.9Security of assets off-premisesYesNot implemented
60
A.7.10Storage mediaYesNot implemented
61
A.7.11Supporting utilitiesYesNot implemented
62
A.7.12Cabling securityYesNot implemented
63
A.7.13Equipment maintenanceYesNot implemented
64
A.7.14Secure disposal or re-use of equipmentYesNot implemented
65
A8Technological controls
66
A.8.1User end point devicesYesNot implemented
67
A.8.2Privileged access rightsYesNot implemented
68
A.8.3Information access restrictionYesNot implemented
69
A.8.4Access to source codeYesNot implemented
70
A.8.5Secure authenticationYesNot implemented
71
A.8.6Capacity managementYesNot implemented
72
A.8.7Protection against malwareYesNot implemented
73
A.8.8Management of technical vulnerabilitiesYesNot implemented
74
A.8.9Configuration managementYesNot implemented
75
A.8.10Information deletionYesNot implemented
76
A.8.11Data maskingYesNot implemented
77
A.8.12Data leakage preventionYesNot implemented
78
A.8.13Information backupYesNot implemented
79
A.8.14Redundancy of information processing facilitiesYesNot implemented
80
A.8.15LoggingYesNot implemented
81
A.8.16Monitoring activitiesYesNot implemented
82
A.8.17Clock synchronizationYesNot implemented
83
A.8.18Use of privileged utility programsYesNot implemented
84
A.8.19Installation of software on operational systemsYesNot implemented
85
A.8.20Networks securityYesNot implemented
86
A.8.21Security of network servicesYesNot implemented
87
A.8.22Segregation of networksYesNot implemented
88
A.8.23Web filteringYesNot implemented
89
A.8.24Use of cryptographyYesNot implemented
90
A.8.25Secure development life cycleYesNot implemented
91
A.8.26Application security requirementsYesNot implemented
92
A.8.27Secure system architecture and engineering principlesYesNot implemented
93
A.8.28Secure codingYesNot implemented
94
A.8.29Security testing in development and acceptanceYesNot implemented
95
A.8.30Outsourced developmentYesNot implemented
96
A.8.31Separation of development, test and production environmentsYesNot implemented
97
A.8.32Change managementYesNot implemented
98
A.8.33Test informationYesNot implemented
99
A.8.34Protection of information systems during audit testingYesNot implemented
100
93Number of controlsNumber of controlsNumber of controls