STATIC PREVIEW — synthetic data v0.4.0-draft · not a live system · links between rendered pages work, others are inert

Annex A controls

All 93 controls of ISO/IEC 27001:2022 Annex A, with applicability, implementation status and linked evidence.

The Statement of Applicability is the 49 undecided controls, not the implemented ones. ISO 27001 requires a documented decision for every Annex A control — including a written justification for each exclusion. Marking a control implemented without linked evidence is a claim, not a control.
Implemented
12/93
Applicability undecided
49
no SoA entry yet
Applicable, zero evidence
30
nothing an auditor could look at
Marked applicable
30
in scope for the ISMS
93 shown
RefControlTheme ApplicabilityImplementation EvidenceOwner
A.5.1 Policies for information security Organizational applicable implemented 0 R. Brunner
A.5.2 Information security roles and responsibilities Organizational applicable implemented 0 R. Brunner
A.5.3 Segregation of duties Organizational undecided in progress 0
A.5.4 Management responsibilities Organizational undecided not started 0
A.5.5 Contact with authorities Organizational undecided not started 0
A.5.6 Contact with special interest groups Organizational undecided not started 0
A.5.7 Threat intelligence Organizational applicable in progress 0 T. Oduya
A.5.8 Information security in project management Organizational undecided not started 0
A.5.9 Inventory of information and other associated assets Organizational applicable implemented 0 R. Brunner
A.5.10 Acceptable use of information and other associated assets Organizational applicable implemented 0 R. Brunner
A.5.11 Return of assets Organizational undecided not started 0
A.5.12 Classification of information Organizational undecided not started 0
A.5.13 Labelling of information Organizational undecided not started 0
A.5.14 Information transfer Organizational undecided not started 0
A.5.15 Access control Organizational applicable implemented 0 R. Brunner
A.5.16 Identity management Organizational undecided not started 0
A.5.17 Authentication information Organizational undecided not started 0
A.5.18 Access rights Organizational undecided in progress 0
A.5.19 Information security in supplier relationships Organizational applicable in progress 0 T. Oduya
A.5.20 Addressing information security within supplier agreements Organizational applicable in progress 0 T. Oduya
A.5.21 Managing information security in the ICT supply chain Organizational applicable in progress 0 T. Oduya
A.5.22 Monitoring, review and change management of supplier services Organizational undecided not started 0
A.5.23 Information security for use of cloud services Organizational undecided not started 0
A.5.24 Information security incident management planning and preparation Organizational applicable needs review 0 R. Brunner
A.5.25 Assessment and decision on information security events Organizational undecided not started 0
A.5.26 Response to information security incidents Organizational applicable needs review 0 R. Brunner
A.5.27 Learning from information security incidents Organizational undecided not started 0
A.5.28 Collection of evidence Organizational undecided not started 0
A.5.29 Information security during disruption Organizational undecided not started 0
A.5.30 ICT readiness for business continuity Organizational applicable in progress 0 T. Oduya
A.5.31 Legal, statutory, regulatory and contractual requirements Organizational undecided not started 0
A.5.32 Intellectual property rights Organizational undecided not started 0
A.5.33 Protection of records Organizational undecided in progress 0
A.5.34 Privacy and protection of personally identifiable information (PII) Organizational undecided not started 0
A.5.35 Independent review of information security Organizational undecided not started 0
A.5.36 Compliance with policies, rules and standards for information security Organizational undecided not started 0
A.5.37 Documented operating procedures Organizational undecided in progress 0
A.6.1 Screening People applicable not started 0
A.6.2 Terms and conditions of employment People applicable not started 0
A.6.3 Information security awareness, education and training People applicable implemented 0 R. Brunner
A.6.4 Disciplinary process People applicable not started 0
A.6.5 Responsibilities after termination or change of employment People applicable not started 0
A.6.6 Confidentiality or non-disclosure agreements People applicable not started 0
A.6.7 Remote working People applicable not started 0
A.6.8 Information security event reporting People applicable not started 0
A.7.1 Physical security perimeters Physical excluded not started 0
A.7.2 Physical entry Physical excluded not started 0
A.7.3 Securing offices, rooms and facilities Physical excluded not started 0
A.7.4 Physical security monitoring Physical excluded not started 0
A.7.5 Protecting against physical and environmental threats Physical excluded not started 0
A.7.6 Working in secure areas Physical excluded not started 0
A.7.7 Clear desk and clear screen Physical excluded not started 0
A.7.8 Equipment siting and protection Physical excluded not started 0
A.7.9 Security of assets off-premises Physical excluded not started 0
A.7.10 Storage media Physical excluded not started 0
A.7.11 Supporting utilities Physical excluded not started 0
A.7.12 Cabling security Physical excluded not started 0
A.7.13 Equipment maintenance Physical excluded not started 0
A.7.14 Secure disposal or re-use of equipment Physical excluded not started 0
A.8.1 User endpoint devices Technological undecided not started 0
A.8.2 Privileged access rights Technological applicable implemented 0 R. Brunner
A.8.3 Information access restriction Technological undecided not started 0
A.8.4 Access to source code Technological undecided not started 0
A.8.5 Secure authentication Technological applicable implemented 0 R. Brunner
A.8.6 Capacity management Technological undecided not started 0
A.8.7 Protection against malware Technological undecided not started 0
A.8.8 Management of technical vulnerabilities Technological applicable in progress 0 T. Oduya
A.8.9 Configuration management Technological applicable in progress 0 T. Oduya
A.8.10 Information deletion Technological undecided not started 0
A.8.11 Data masking Technological undecided not started 0
A.8.12 Data leakage prevention Technological applicable in progress 0 T. Oduya
A.8.13 Information backup Technological undecided in progress 0
A.8.14 Redundancy of information processing facilities Technological undecided not started 0
A.8.15 Logging Technological applicable implemented 0 R. Brunner
A.8.16 Monitoring activities Technological applicable implemented 0 R. Brunner
A.8.17 Clock synchronization Technological undecided not started 0
A.8.18 Use of privileged utility programs Technological undecided not started 0
A.8.19 Installation of software on operational systems Technological undecided not started 0
A.8.20 Networks security Technological undecided in progress 0
A.8.21 Security of network services Technological undecided not started 0
A.8.22 Segregation of networks Technological undecided not started 0
A.8.23 Web filtering Technological undecided not started 0
A.8.24 Use of cryptography Technological applicable implemented 0 R. Brunner
A.8.25 Secure development life cycle Technological undecided not started 0
A.8.26 Application security requirements Technological undecided not started 0
A.8.27 Secure system architecture and engineering principles Technological undecided not started 0
A.8.28 Secure coding Technological applicable in progress 0 T. Oduya
A.8.29 Security testing in development and acceptance Technological undecided not started 0
A.8.30 Outsourced development Technological undecided not started 0
A.8.31 Separation of development, test and production environments Technological undecided not started 0
A.8.32 Change management Technological applicable implemented 0 R. Brunner
A.8.33 Test information Technological undecided not started 0
A.8.34 Protection of information systems during audit testing Technological undecided not started 0