Annex A controls
All 93 controls of ISO/IEC 27001:2022 Annex A, with applicability, implementation status and linked evidence.
The Statement of Applicability is the 49 undecided controls, not the implemented ones.
ISO 27001 requires a documented decision for every Annex A control — including a written justification for each exclusion.
Marking a control implemented without linked evidence is a claim, not a control.
Implemented
12/93
Applicability undecided
49
no SoA entry yet
Applicable, zero evidence
30
nothing an auditor could look at
Marked applicable
30
in scope for the ISMS
| Ref | Control | Theme | Applicability | Implementation | Evidence | Owner |
|---|---|---|---|---|---|---|
| A.5.1 | Policies for information security | Organizational | applicable | implemented | 0 | R. Brunner |
| A.5.2 | Information security roles and responsibilities | Organizational | applicable | implemented | 0 | R. Brunner |
| A.5.3 | Segregation of duties | Organizational | undecided | in progress | 0 | — |
| A.5.4 | Management responsibilities | Organizational | undecided | not started | 0 | — |
| A.5.5 | Contact with authorities | Organizational | undecided | not started | 0 | — |
| A.5.6 | Contact with special interest groups | Organizational | undecided | not started | 0 | — |
| A.5.7 | Threat intelligence | Organizational | applicable | in progress | 0 | T. Oduya |
| A.5.8 | Information security in project management | Organizational | undecided | not started | 0 | — |
| A.5.9 | Inventory of information and other associated assets | Organizational | applicable | implemented | 0 | R. Brunner |
| A.5.10 | Acceptable use of information and other associated assets | Organizational | applicable | implemented | 0 | R. Brunner |
| A.5.11 | Return of assets | Organizational | undecided | not started | 0 | — |
| A.5.12 | Classification of information | Organizational | undecided | not started | 0 | — |
| A.5.13 | Labelling of information | Organizational | undecided | not started | 0 | — |
| A.5.14 | Information transfer | Organizational | undecided | not started | 0 | — |
| A.5.15 | Access control | Organizational | applicable | implemented | 0 | R. Brunner |
| A.5.16 | Identity management | Organizational | undecided | not started | 0 | — |
| A.5.17 | Authentication information | Organizational | undecided | not started | 0 | — |
| A.5.18 | Access rights | Organizational | undecided | in progress | 0 | — |
| A.5.19 | Information security in supplier relationships | Organizational | applicable | in progress | 0 | T. Oduya |
| A.5.20 | Addressing information security within supplier agreements | Organizational | applicable | in progress | 0 | T. Oduya |
| A.5.21 | Managing information security in the ICT supply chain | Organizational | applicable | in progress | 0 | T. Oduya |
| A.5.22 | Monitoring, review and change management of supplier services | Organizational | undecided | not started | 0 | — |
| A.5.23 | Information security for use of cloud services | Organizational | undecided | not started | 0 | — |
| A.5.24 | Information security incident management planning and preparation | Organizational | applicable | needs review | 0 | R. Brunner |
| A.5.25 | Assessment and decision on information security events | Organizational | undecided | not started | 0 | — |
| A.5.26 | Response to information security incidents | Organizational | applicable | needs review | 0 | R. Brunner |
| A.5.27 | Learning from information security incidents | Organizational | undecided | not started | 0 | — |
| A.5.28 | Collection of evidence | Organizational | undecided | not started | 0 | — |
| A.5.29 | Information security during disruption | Organizational | undecided | not started | 0 | — |
| A.5.30 | ICT readiness for business continuity | Organizational | applicable | in progress | 0 | T. Oduya |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | Organizational | undecided | not started | 0 | — |
| A.5.32 | Intellectual property rights | Organizational | undecided | not started | 0 | — |
| A.5.33 | Protection of records | Organizational | undecided | in progress | 0 | — |
| A.5.34 | Privacy and protection of personally identifiable information (PII) | Organizational | undecided | not started | 0 | — |
| A.5.35 | Independent review of information security | Organizational | undecided | not started | 0 | — |
| A.5.36 | Compliance with policies, rules and standards for information security | Organizational | undecided | not started | 0 | — |
| A.5.37 | Documented operating procedures | Organizational | undecided | in progress | 0 | — |
| A.6.1 | Screening | People | applicable | not started | 0 | — |
| A.6.2 | Terms and conditions of employment | People | applicable | not started | 0 | — |
| A.6.3 | Information security awareness, education and training | People | applicable | implemented | 0 | R. Brunner |
| A.6.4 | Disciplinary process | People | applicable | not started | 0 | — |
| A.6.5 | Responsibilities after termination or change of employment | People | applicable | not started | 0 | — |
| A.6.6 | Confidentiality or non-disclosure agreements | People | applicable | not started | 0 | — |
| A.6.7 | Remote working | People | applicable | not started | 0 | — |
| A.6.8 | Information security event reporting | People | applicable | not started | 0 | — |
| A.7.1 | Physical security perimeters | Physical | excluded | not started | 0 | — |
| A.7.2 | Physical entry | Physical | excluded | not started | 0 | — |
| A.7.3 | Securing offices, rooms and facilities | Physical | excluded | not started | 0 | — |
| A.7.4 | Physical security monitoring | Physical | excluded | not started | 0 | — |
| A.7.5 | Protecting against physical and environmental threats | Physical | excluded | not started | 0 | — |
| A.7.6 | Working in secure areas | Physical | excluded | not started | 0 | — |
| A.7.7 | Clear desk and clear screen | Physical | excluded | not started | 0 | — |
| A.7.8 | Equipment siting and protection | Physical | excluded | not started | 0 | — |
| A.7.9 | Security of assets off-premises | Physical | excluded | not started | 0 | — |
| A.7.10 | Storage media | Physical | excluded | not started | 0 | — |
| A.7.11 | Supporting utilities | Physical | excluded | not started | 0 | — |
| A.7.12 | Cabling security | Physical | excluded | not started | 0 | — |
| A.7.13 | Equipment maintenance | Physical | excluded | not started | 0 | — |
| A.7.14 | Secure disposal or re-use of equipment | Physical | excluded | not started | 0 | — |
| A.8.1 | User endpoint devices | Technological | undecided | not started | 0 | — |
| A.8.2 | Privileged access rights | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.3 | Information access restriction | Technological | undecided | not started | 0 | — |
| A.8.4 | Access to source code | Technological | undecided | not started | 0 | — |
| A.8.5 | Secure authentication | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.6 | Capacity management | Technological | undecided | not started | 0 | — |
| A.8.7 | Protection against malware | Technological | undecided | not started | 0 | — |
| A.8.8 | Management of technical vulnerabilities | Technological | applicable | in progress | 0 | T. Oduya |
| A.8.9 | Configuration management | Technological | applicable | in progress | 0 | T. Oduya |
| A.8.10 | Information deletion | Technological | undecided | not started | 0 | — |
| A.8.11 | Data masking | Technological | undecided | not started | 0 | — |
| A.8.12 | Data leakage prevention | Technological | applicable | in progress | 0 | T. Oduya |
| A.8.13 | Information backup | Technological | undecided | in progress | 0 | — |
| A.8.14 | Redundancy of information processing facilities | Technological | undecided | not started | 0 | — |
| A.8.15 | Logging | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.16 | Monitoring activities | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.17 | Clock synchronization | Technological | undecided | not started | 0 | — |
| A.8.18 | Use of privileged utility programs | Technological | undecided | not started | 0 | — |
| A.8.19 | Installation of software on operational systems | Technological | undecided | not started | 0 | — |
| A.8.20 | Networks security | Technological | undecided | in progress | 0 | — |
| A.8.21 | Security of network services | Technological | undecided | not started | 0 | — |
| A.8.22 | Segregation of networks | Technological | undecided | not started | 0 | — |
| A.8.23 | Web filtering | Technological | undecided | not started | 0 | — |
| A.8.24 | Use of cryptography | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.25 | Secure development life cycle | Technological | undecided | not started | 0 | — |
| A.8.26 | Application security requirements | Technological | undecided | not started | 0 | — |
| A.8.27 | Secure system architecture and engineering principles | Technological | undecided | not started | 0 | — |
| A.8.28 | Secure coding | Technological | applicable | in progress | 0 | T. Oduya |
| A.8.29 | Security testing in development and acceptance | Technological | undecided | not started | 0 | — |
| A.8.30 | Outsourced development | Technological | undecided | not started | 0 | — |
| A.8.31 | Separation of development, test and production environments | Technological | undecided | not started | 0 | — |
| A.8.32 | Change management | Technological | applicable | implemented | 0 | R. Brunner |
| A.8.33 | Test information | Technological | undecided | not started | 0 | — |
| A.8.34 | Protection of information systems during audit testing | Technological | undecided | not started | 0 | — |