Annex A controls: Understanding the ISO 27001 Part 8
Adewale Adeife, CISM
Cyber Risk Management and Technology Consultant || GRC Professional || PCI-DSS Consultant || I help keep top organizations, Fintechs, and financial institutions secure by focusing on People, Process, and Technology.
Annex A of the ISMS controls a list of 93 controls grouped into 4 themes:
1. Organizational controls
2. People controls
3. Physical controls
4. Technological controls
In the ISO 27001:2013 version, Annex A contained 114 controls and 14 domains but the 27001:2022 has 93 controls and 4 domains.
Organizational controls(37 controls)
Organizational control concentrates on the policies, procedures, roles, responsibilities, and other organizational-level measures necessary for maintaining a strong information security posture. They include:
People control (8 controls)
Information security revolves around people, processes, and technology. People especially employees are the weak link and they play a crucial part in the information security equation.
This control includes:
领英推荐
Physical Controls (14 controls)
Physical controls focus on the physical environment of the ISMS. The physical environment is as important as the technological or digital environment for ensuring information security. This control relates to the following:
Technological controls (34 controls)
Technological controls are controls implemented through technology to protect the security of information. This section includes:
Since 2022, ISMS has integrated eleven new Annex A controls ?which are:
Why is Annex A important?
Thanks for reading so far
IT Auditor-Consultant at CP CAN. Consulting
7 个月Excellent, thanks for sharing, Adewale
PhD|| UN Women UK Participant for CSW68|| Multi-Award winning Cybersecurity Professional || Teacher|| Keynote Speaker|| Cybersecurity Career Coach and Mentor|| Cyblack||
7 个月Well done ??????