Policy Register

ISO/IEC 27001:2022

Is read here with the ISO/IEC 27002:2022 guidance beside each control. It requires an information security policy and topic-specific policies (control 5.1) and, control by control, the rules, procedures and plans the Annex A controls are implemented through; the ISO/IEC 27002:2022 guidance beside each control says what the document is expected to say.

Tick ISO/IEC 27001:2022 on the register and these documents are expected and these clauses attach. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here. Open the standard.

The documents it expects

35 documents expected

Each becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).

Governance and the management system

People

Access and identity

Assets, data and classification

Operations and technology

Suppliers and third parties

Resilience and incidents

Privacy

Every document it reaches

73 types carry at least one of its clauses
Document control procedure 5.1, 5.37, 7.5 (named)Information security policy 5.1, 5.2 (named)Information security roles and responsibilities 5.2, 5.3 (named)Internal audit charter and programme 9.2 (named)Legal and regulatory register 5.31Management review procedure 9.3 (named)Nonconformity and corrective action procedure 10.2 (named)Risk management policy 6.1.2 (named), 6.1.3 (named)Acceptable use policy 5.10Background screening policy 6.1Clear desk and clear screen policy 7.7Confidentiality and non-disclosure agreement 6.6Disciplinary process 6.4HR security policy (joiners, movers, leavers) 6.1, 6.2, 6.5Offboarding and termination procedure 6.5, 5.11, 5.18Remote working policy 6.7Security awareness and training policy 6.3, 7.3 (named)Access control policy 5.15, 5.18Access review procedure 5.18Identity and access management standard 5.16, 5.18Password and authentication standard 5.17, 8.5Privileged access management policy 8.2Asset management policy 5.9, 5.11Data governance policy 5.9, 5.12Information classification and handling policy 5.12, 5.13Information transfer policy 5.14Media handling and disposal policy 7.10, 7.14, 8.10Records retention schedule 5.33Software asset management policy 5.9, 8.19API security standard 8.26Backup policy 8.13Bring your own device policy 8.1, 6.7Certificate management policy 8.24Change management procedure 8.32Cloud security policy 5.23Configuration management policy 8.9Container and orchestration security standard 8.9Cryptography policy 8.24Database security standard 8.3, 8.11, 8.33Documented operating procedures 5.37Email and messaging policy 5.14, 8.23Endpoint device policy 8.1, 8.7Environmental security standard 7.5Key management policy 8.24Logging and monitoring standard 8.15, 8.16Mobile device policy 8.1, 6.7Network security policy 8.20, 8.21, 8.22Patch management policy 8.8Physical security policy 7.1, 7.2, 7.4Secure development policy 8.25, 8.26, 8.28Security testing and penetration testing policy 8.29Threat intelligence procedure 5.7Vulnerability management policy 8.8Wireless network standard 8.20, 8.21Zero trust architecture standard 8.27, 8.22Cloud vendor management policy 5.23Outsourcing policy 8.30Service level management policy 5.22Supplier and third-party security policy 5.19, 5.20, 5.21, 5.22Supply chain security policy 5.21Vendor contract security requirements 5.20Vendor security assessment procedure 5.19, 5.22Business continuity plan 5.29Business continuity policy 5.29Disaster recovery plan 5.30, 8.14Evidence collection and forensics procedure 5.28Incident response plan 5.24, 5.26, 5.27Security event reporting procedure 6.8, 5.25Data protection policy 5.34AI use policy (acceptable AI use) 5.10Code of conduct 6.2Social media policy 5.14, 5.10Whistleblowing policy 6.8

The guidance beside every control

ISO/IEC 27002:2022 is quoted beside each ISO/IEC 27001:2022 control as what the guidance expects the document to say; control 5.1's guidance names the topic-specific policies an organisation commonly writes, which is where most of this regime's expected list comes from. Named and not quoted: SOC 2 (CC1 and CC5 name the same documents; not quoted here); PCI DSS Requirement 12 (the security policy and its topic documents; not quoted here).

The clauses, quoted

71 of 93 in the framework

Requirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.

ISO 27001 5.1 Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

What the ISO 27002 guidance expects the document to say: Requires an information security policy together with supporting topic specific policies. These must be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed on a planned cycle and whenever significant change occurs.

Evidence an auditor accepts: The approved information security policy, showing the approving authority and the date of approval; the set of topic specific policies beneath it, such as access control, cryptography, backup, acceptable use and supplier security, each with an owner; evidence of publication and of communication to personnel and to relevant interested parties, such as intranet publication records or distribution lists
Common gap: Policies not formally approved by senior management
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.10 Acceptable use of information and other associated assets

Define and enforce rules for how information and assets may be used and handled.

What the ISO 27002 guidance expects the document to say: Requires rules for acceptable use, and procedures for handling information and its associated assets, to be identified, documented and put into effect.

Evidence an auditor accepts: The acceptable use rules, covering personal use, removable media, cloud storage, email, messaging and use of artificial intelligence services where relevant; handling procedures per classification level, covering storage, transmission, printing, sharing and destruction; evidence rules were communicated and accepted by personnel and by third parties given access
Common gap: Policy not reviewed or updated regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.11 Return of assets

Recover all organizational assets on exit or role change.

What the ISO 27002 guidance expects the document to say: Requires personnel and other relevant interested parties to return all organisational assets in their possession when employment, a contract or an agreement changes or ends.

Evidence an auditor accepts: The leaver and role change procedure showing asset return as a mandatory step; the checklist or ticket used per departure, listing assets issued to that person from the inventory; signed confirmation of return, and records for assets not returned including the escalation taken
Common gap: Missing signatures on return forms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.12 Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.

Evidence an auditor accepts: The classification scheme, defining the levels and the criteria for each against confidentiality, integrity and availability; evidence the criteria account for the requirements of relevant interested parties, such as customers, regulators and contracts; classification applied to actual information assets in the inventory, not only defined in policy
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.13 Labelling of information

Label information consistently with the classification scheme so handling rules can follow it.

What the ISO 27002 guidance expects the document to say: Requires a matching set of information labelling procedures to be developed and implemented, so that information carries markings consistent with the classification scheme the organisation has adopted.

Evidence an auditor accepts: The labelling procedures showing how labels are applied for each medium, covering documents, email, physical media, screens and system records; samples of labelled information from live systems, in each classification level in use; evidence labelling extends to information shared with third parties
Common gap: Labels applied inconsistently across departments
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.14 Information transfer

Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.

What the ISO 27002 guidance expects the document to say: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.

Evidence an auditor accepts: Transfer rules covering each transfer type in use, being electronic, physical and verbal; transfer agreements with external parties, setting out protection, liability and traceability requirements; technical evidence of protection in transit, such as enforced transport encryption, secure file transfer configuration and managed file transfer logs
Common gap: Reliance on informal verbal agreements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.15 Access control

Set rules for physical and logical access based on business and security requirements.

What the ISO 27002 guidance expects the document to say: Requires rules governing access to information and the assets tied to it, covering both physical entry and logical access, to be established and implemented on the basis of business need and security requirements.

Evidence an auditor accepts: The access control policy and the specific rules derived from it, expressed per information asset or asset group; evidence the rules reflect business need and the classification of the information rather than convenience; the mapping from rules to enforcement points, covering logical systems and physical areas
Common gap: Infrequent review of access rights
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.16 Identity management

Manage the full life cycle of identities.

What the ISO 27002 guidance expects the document to say: Requires the full life cycle of identities to be managed, from creation through change to removal.

Evidence an auditor accepts: The identity lifecycle procedure covering creation, change and removal, for internal users, external users and non human identities; records showing each identity is traceable to a person or to an accountable owner where the identity is for a service or device; approval records for identity creation, sourced from an authoritative system such as human resources or contract management
Common gap: relying on manual spreadsheets for provisioning
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.17 Authentication information

Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.

What the ISO 27002 guidance expects the document to say: Requires a management process to control how authentication information is issued and looked after over time, including guidance to personnel on handling it appropriately.

Evidence an auditor accepts: The process for allocating authentication information, including initial issue, secure delivery and forced change on first use; rules on strength, reuse, expiry and storage, and the configuration enforcing them; evidence of secure storage, such as hashing configuration for stored credentials and a controlled vault for shared or privileged secrets
Common gap: Policies exist but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

What the ISO 27002 guidance expects the document to say: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.

Evidence an auditor accepts: Provisioning records showing the authorisation behind each access grant, tied to the access control rules; modification records where access changed after a role change, showing removal of the previous entitlements; removal records on termination, with the date of removal against the date of departure
Common gap: Reviews lack documented corrective actions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

What the ISO 27002 guidance expects the document to say: Requires processes and procedures to be defined and implemented for managing the information security risks that arise from using suppliers' products or services.

Evidence an auditor accepts: The supplier security process, covering identification, risk assessment, selection, onboarding and exit; the supplier register with risk tiering, showing what drives the tier such as data access, criticality or connectivity; risk assessments performed for suppliers in the period, at the depth their tier requires
Common gap: Treating all suppliers as low risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

What the ISO 27002 guidance expects the document to say: Requires information security roles and responsibilities to be defined and allocated in line with what the organisation actually needs, so ownership of each security duty is explicit rather than assumed.

Evidence an auditor accepts: The documented allocation of information security roles and responsibilities, naming individuals or positions rather than teams; role descriptions or terms of reference setting out the security duties attached to each role; evidence the allocation was formally approved and communicated to the holders
Common gap: Roles not updated after staff changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

What the ISO 27002 guidance expects the document to say: Requires the relevant information security requirements to be established and agreed with each supplier, scaled to the type of supplier relationship involved.

Evidence an auditor accepts: Executed agreements containing the agreed information security requirements, sampled across supplier tiers; the clause set used, covering confidentiality, information handling, incident notification with a timeframe, subcontracting, personnel screening, return or deletion at exit and right to audit; evidence requirements were scaled to the relationship type rather than applied as one template regardless
Common gap: missing explicit security clauses
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

What the ISO 27002 guidance expects the document to say: Requires processes and procedures to be defined and implemented to manage information security risk arising along the supply chain for ICT products and services.

Evidence an auditor accepts: The process for managing ICT supply chain risk, distinct from general supplier management; requirements imposed on ICT suppliers regarding their own suppliers, component provenance and secure development; evidence of verification, such as a software bill of materials, component listings or attestation of development practice
Common gap: Treating supplier security as one-off check
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

What the ISO 27002 guidance expects the document to say: Requires supplier information security practice and service delivery to be monitored, reviewed and evaluated on a regular basis, and requires change within them to be managed.

Evidence an auditor accepts: The schedule of supplier reviews, showing frequency by tier and evidence the schedule was met; service reports and security metrics received from suppliers, and the review of them; records of issues raised with suppliers, and their resolution or escalation
Common gap: relying on informal verbal updates
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

What the ISO 27002 guidance expects the document to say: Requires processes for the acquisition, use, management and exit of cloud services to be established in line with the organisation's own information security requirements. Supporting material frames the aim as preserving confidentiality, integrity and availability of information assets held in cloud services.

Evidence an auditor accepts: The process covering cloud acquisition, use, management and exit, including who may acquire a cloud service; the register of cloud services in use, with data classification, owner and criticality per service; the shared responsibility position documented per service, showing which controls the provider operates and which the organisation must
Common gap: Relying solely on provider's security assurances
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

What the ISO 27002 guidance expects the document to say: Requires the organisation to plan and prepare for incident handling ahead of time. Incident management processes, plus the roles and responsibilities attached to them, must be defined, put in place and communicated.

Evidence an auditor accepts: The incident management process, defining categories, severity, escalation and the decision authority at each level; documented roles and responsibilities for incident handling, including out of hours coverage and named deputies; evidence the process and roles were communicated to those who must act on them
Common gap: roles are defined but not formally assigned or approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.25 Assessment and decision on information security events

Triage security events and decide which become incidents.

What the ISO 27002 guidance expects the document to say: Requires information security events to be assessed and a decision taken on whether each event is to be categorised as an information security incident.

Evidence an auditor accepts: The criteria used to decide whether an event is an incident, and the severity scale applied; records of events assessed in the period, including those assessed as not incidents, with the reason recorded; evidence of who performed the assessment and that they were competent and authorised to do so
Common gap: no documented triage steps
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.26 Response to information security incidents

Respond to incidents according to the documented procedures.

What the ISO 27002 guidance expects the document to say: Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.

Evidence an auditor accepts: Documented response procedures per incident type, and evidence they were followed in actual incidents; incident records carrying detection, containment, eradication and recovery timestamps and the actions taken at each stage; evidence of decisions taken during response and by whom, including any decision to preserve rather than eradicate
Common gap: Plans not tested regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.27 Learning from information security incidents

Feed lessons from incidents back into stronger controls.

What the ISO 27002 guidance expects the document to say: Requires knowledge gained from information security incidents to be fed back into strengthening and improving the information security controls.

Evidence an auditor accepts: Post incident review records for incidents meeting the defined threshold, with attendees and findings; root cause analysis distinguishing the technical cause from the process or control failure that allowed it; actions arising, with owner, due date and evidence of completion
Common gap: Root cause analysis limited to symptoms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.28 Collection of evidence

Have procedures to identify, collect, acquire and preserve evidence related to security events.

What the ISO 27002 guidance expects the document to say: Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.

Evidence an auditor accepts: Procedures for identification, collection, acquisition and preservation of evidence, covering the media types the organisation holds; chain of custody records for evidence collected in the period, showing who held it and when; evidence of the method used to acquire data in a way that preserves integrity, such as hashing and write protection
Common gap: Procedures not aligned with legal requirements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.29 Information security during disruption

Plan how to keep information security at the right level during disruption.

What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.

Evidence an auditor accepts: Continuity plans showing how information security is maintained while the organisation is operating in a degraded or alternative mode; the assessment of which security controls would be weakened or bypassed during disruption, and the compensating arrangements; evidence security requirements are part of continuity testing, not only recovery of function
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.30 ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

What the ISO 27002 guidance expects the document to say: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.

Evidence an auditor accepts: ICT continuity requirements derived from the business impact analysis, expressed as recovery time and recovery point objectives per service; the ICT continuity plans and the technical capability supporting them, such as replication, failover and alternative capacity; test plans and results for the period, showing objectives were measured against the requirement rather than assumed
Common gap: Testing frequency not aligned with risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

What the ISO 27002 guidance expects the document to say: Requires the legal, statutory, regulatory and contractual requirements bearing on information security, and the organisation's approach to meeting them, to be identified, documented and kept up to date.

Evidence an auditor accepts: The register of legal, statutory, regulatory and contractual requirements relevant to information security, per jurisdiction of operation; the documented approach to meeting each requirement, with the control or process that satisfies it; evidence the register is maintained, showing how new and changed obligations are identified and the date of the last update
Common gap: outdated legal register
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.33 Protection of records

Protect records from loss, destruction, falsification, unauthorized access and unauthorized release.

What the ISO 27002 guidance expects the document to say: Requires records to be protected against loss, destruction, falsification, unauthorised access and unauthorised release.

Evidence an auditor accepts: The records retention schedule, showing retention periods and their legal or business basis per record type; evidence of protection appropriate to each record type against loss, destruction, falsification and unauthorised access or release; controls over the storage medium including its readability over the retention period
Common gap: retention schedules not aligned with legal requirements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

What the ISO 27002 guidance expects the document to say: Requires the requirements for preserving privacy and protecting personally identifiable information to be identified and met, in line with applicable laws, regulations and contractual requirements.

Evidence an auditor accepts: Identification of the privacy and personally identifiable information requirements that apply, per jurisdiction and per contract; the record of processing activities, showing what personal data is held, why, on what basis and for how long; evidence of the protections applied, such as access restriction, minimisation, pseudonymisation and transfer safeguards
Common gap: Missing documented consent for all data subjects
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.37 Documented operating procedures

Document operating procedures for information processing facilities and make them available to those who need them.

What the ISO 27002 guidance expects the document to say: Requires the operating procedures used to run information processing facilities to be written down and made available to the personnel who need them.

Evidence an auditor accepts: The set of documented operating procedures for information processing facilities, covering routine operation, backup, monitoring, incident handling and restart; evidence procedures are available to the personnel who need them, including during an outage of the primary system that hosts them; version control and review records, showing procedures are current against the systems they describe
Common gap: outdated procedures still in use
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.7 Threat intelligence

Collect and analyse threat information and turn it into decisions, not just unread feeds.

What the ISO 27002 guidance expects the document to say: Requires information about information security threats to be collected and analysed so that it becomes usable threat intelligence. Supporting material frames this as gathering and applying intelligence proactively, to identify, assess and mitigate emerging threats before they are realised.

Evidence an auditor accepts: The defined sources of threat information, covering strategic, tactical and operational levels; the process for analysing raw information into intelligence relevant to the organisation, naming who performs it; intelligence products produced during the period and their distribution list
Common gap: Collecting feeds without validation
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.9 Inventory of information and other associated assets

Maintain a current asset inventory with owners.

What the ISO 27002 guidance expects the document to say: Requires an inventory of information and of the other assets associated with it to be developed and kept current, and requires that inventory to record ownership of each entry.

Evidence an auditor accepts: The inventory of information and associated assets, showing scope across hardware, software, services, information stores and cloud tenancies; the recorded owner for each entry, and evidence owners have accepted the role; the process and cadence for keeping the inventory current, including additions and retirements
Common gap: Outdated entries in inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.1 Screening

Background-check candidates and personnel proportional to risk and classification, within the law.

What the ISO 27002 guidance expects the document to say: Requires background verification checks on all candidates for personnel before they join and on an ongoing basis afterwards, within the bounds of applicable laws, regulations and ethics, and proportionate to business requirements, the classification of information to be accessed and the perceived risk.

Evidence an auditor accepts: The screening procedure, showing what checks are performed and how the level is set against the classification of information accessed and the perceived risk; completed screening records for personnel who joined in the period, including contractors and agency staff; evidence of the legal and regulatory limits applied in each jurisdiction, and of candidate consent where required
Common gap: One‑size‑fits‑all screening regardless of risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.2 Terms and conditions of employment

State the security responsibilities of both the person and the organization in the employment agreement.

What the ISO 27002 guidance expects the document to say: Requires employment contractual agreements to state what the individual and the organisation are each responsible for with respect to information security.

Evidence an auditor accepts: Employment contracts and contractor agreements containing the information security responsibilities of both parties; evidence the clauses cover confidentiality, acceptable use, return of assets and obligations continuing after employment; signed acceptance records for personnel in scope, including those who joined before the current clause set
Common gap: missing security clauses in standard contracts
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.3 Information security awareness, education and training

Give personnel and relevant parties appropriate, current security training for their role.

What the ISO 27002 guidance expects the document to say: Requires personnel and relevant interested parties to receive appropriate information security awareness, education and training, plus regular updates on the security policy, topic specific policies and procedures relevant to their job function. Supporting SME guidance separates merely informing people from making them aware and from training those holding specific roles, and treats repetition as necessary because objectives, threats and available measures keep changing.

Evidence an auditor accepts: The awareness and training programme, distinguishing general awareness from role specific training for those with defined security duties; completion records per individual, with coverage measured against the full population including contractors; content evidence showing the material reflects current policy, current threats and the organisation's own procedures
Common gap: Training not aligned to specific job functions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.4 Disciplinary process

Have a formal, communicated disciplinary process for security policy violations.

What the ISO 27002 guidance expects the document to say: Requires a formalised disciplinary process, communicated in advance, so that action can be taken where personnel or other relevant parties have breached information security policy.

Evidence an auditor accepts: The formalised disciplinary process covering information security breaches, and evidence it was communicated in advance; evidence of the link from incident and compliance findings into the disciplinary route, including who decides to invoke it; records of cases where the process was invoked, with the assessment of the breach and the outcome
Common gap: Policy exists but not communicated to staff
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.5 Responsibilities after termination or change of employment

Define and enforce security responsibilities that remain valid after an exit or role change.

What the ISO 27002 guidance expects the document to say: Requires the security duties and responsibilities that survive the end of employment, or a move to a different role, to be defined, communicated to the people concerned and enforced.

Evidence an auditor accepts: Documented responsibilities that remain in force after employment ends or after a change of role, such as confidentiality and non disclosure; evidence these were communicated to the individual at the point of departure or change, with acknowledgement; the leaver and mover procedure showing the security steps and their completion within a defined timeframe
Common gap: Delayed revocation of privileged accounts
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.6 Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

What the ISO 27002 guidance expects the document to say: Requires confidentiality or non-disclosure agreements matching the organisation's need to protect information to be identified, documented, reviewed on a regular basis and signed by personnel and by other relevant parties.

Evidence an auditor accepts: The confidentiality or non disclosure agreements in use, and the assessment showing they reflect the organisation's protection needs; signed agreements for personnel and for third parties with access, held and retrievable; evidence of regular review of the agreement terms and of who is covered
Common gap: NDAs not refreshed when data classification changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.7 Remote working

Apply security measures when people access, process or store information outside the organization's premises.

What the ISO 27002 guidance expects the document to say: Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.

Evidence an auditor accepts: The remote working rules, covering approval, permitted locations, equipment, network use and handling of physical material; technical measures evidence, such as device encryption, endpoint protection, secure remote access configuration and enforced patching for remote devices; evidence of protection where personally owned devices are used, including separation of organisational information
Common gap: Missing MFA for remote access
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.8 Information security event reporting

Give people an easy, timely channel to report observed or suspected security events.

What the ISO 27002 guidance expects the document to say: Requires a mechanism through which personnel can report security events they have observed or suspect, using appropriate channels and without delay.

Evidence an auditor accepts: The defined reporting mechanism and channels, and evidence they are known to personnel and to relevant third parties; reporting records for the period, showing volume, source and the time between observation and report; evidence the channel is available at all times and does not depend on a system that may itself be affected
Common gap: no anonymous reporting option
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.1 Physical security perimeters

Define and use security perimeters to protect areas holding information and assets.

What the ISO 27002 guidance expects the document to say: Requires security perimeters to be defined and used to protect any area holding information and the assets associated with it.

Evidence an auditor accepts: Definition of the security perimeters, with site plans or drawings showing the boundary of each area holding information and associated assets; the basis for each perimeter, tied to the classification and criticality of what it protects; evidence the perimeter is physically sound, covering walls, doors, windows, roof and floor voids
Common gap: outdated floor plans
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.10 Storage media

Manage storage media across acquisition, use, transport and disposal per classification and handling rules.

What the ISO 27002 guidance expects the document to say: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.

Evidence an auditor accepts: Procedures covering media across acquisition, use, transportation and disposal, tied to the classification scheme; the media register or tracking record for removable and archival media, showing location and content classification; evidence of protection in transit, including packaging, carrier selection and receipt confirmation
Common gap: No documented classification for media
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.14 Secure disposal or re-use of equipment

Verify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.

What the ISO 27002 guidance expects the document to say: Requires items of equipment containing storage media to be verified before disposal or re-use, confirming that sensitive data and licensed software have been removed or securely overwritten.

Evidence an auditor accepts: The procedure for disposal and re-use of equipment containing storage media, defining the sanitisation method per media type; verification records confirming sensitive data and licensed software were removed or securely overwritten, per item; asset register entries showing the transition from in use to sanitised to disposed or reissued
Common gap: Relying on visual inspection only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.2 Physical entry

Protect secure areas with appropriate entry controls and access points.

What the ISO 27002 guidance expects the document to say: Requires secure areas to be protected by appropriate entry controls and by control over the access points themselves.

Evidence an auditor accepts: Entry control configuration for each secure area, showing the authentication required and any multi factor or dual control; the authorisation list per area, with the basis for each person's access; access logs for the period, retained and reviewed, with evidence of what the review looked for
Common gap: Use of informal sign-in sheets instead of controlled logs
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.4 Physical security monitoring

Continuously monitor premises for unauthorized physical access.

What the ISO 27002 guidance expects the document to say: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.

Evidence an auditor accepts: The design of physical monitoring, covering surveillance, intrusion detection, alarms and guarding, and its coverage against the areas defined; evidence monitoring is continuous, including out of hours and during holidays; records of alarms and detections in the period, with the response taken and the time to respond
Common gap: logs not retained for required period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.5 Protecting against physical and environmental threats

Design and apply protection against natural disasters and other physical and environmental threats.

What the ISO 27002 guidance expects the document to say: Requires designed and implemented protection against physical and environmental threats. These include natural disasters as well as other physical threats to infrastructure, whether deliberate or accidental.

Evidence an auditor accepts: The assessment of physical and environmental threats relevant to each site, covering natural hazards and deliberate and accidental threats; the protective measures selected against that assessment, such as fire detection and suppression, water detection, and protection against extreme weather; testing and maintenance records for protective systems, including fire suppression and detection
Common gap: risk assessments not updated after infrastructure changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.7 Clear desk and clear screen

Enforce clear-desk rules for papers and media and clear-screen rules for processing facilities.

What the ISO 27002 guidance expects the document to say: Requires defined and enforced rules for clearing papers and removable storage media from desks, and for clearing the screens of facilities used to process information.

Evidence an auditor accepts: The clear desk and clear screen rules, defining what must be cleared and to what standard; technical enforcement evidence for screens, such as enforced screen lock timeout configuration across the estate; evidence of physical checks or sweeps, with findings and follow up
Common gap: Policy exists but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.1 User end point devices

Protect information stored on, processed by or reachable through user endpoints.

What the ISO 27002 guidance expects the document to say: Requires information stored on, processed by or accessible through user endpoint devices to be protected.

Evidence an auditor accepts: The endpoint device policy covering corporate and personally owned devices, registration, permitted use and required protections; configuration baselines for each device type and evidence of compliance across the estate, with the percentage of devices compliant; evidence of the protective measures in force, such as full disk encryption, endpoint detection, screen lock, patch currency and restriction of administrative rights
Common gap: Incomplete device inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.10 Information deletion

Delete information in systems, devices and media when no longer required.

What the ISO 27002 guidance expects the document to say: Requires information held in information systems, devices or any other storage media to be deleted once it is no longer required. Supporting material frames this as procedures for secure deletion at the point the information ceases to be needed.

Evidence an auditor accepts: Deletion rules tied to retention requirements, per information type and per system; evidence of deletion actually performed, such as job records, deletion logs or reports of records removed; the method used for each medium, and evidence it renders the information unrecoverable to the required standard
Common gap: Retaining data beyond approved period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.11 Data masking

Use data masking in line with access policy, business need and applicable law.

What the ISO 27002 guidance expects the document to say: Requires data masking to be used in accordance with the topic specific policy on access control, other related topic specific policies and business requirements, taking applicable legislation into account. Supporting material notes the common case of protecting sensitive data used for testing or development.

Evidence an auditor accepts: The rules on masking, pseudonymisation and anonymisation, tied to the access control policy and to applicable legislation; identification of the environments and use cases where masking applies, such as development, testing, training, analytics and support; technical evidence of the masking applied, including the technique and evidence it resists re-identification
Common gap: Masking applied inconsistently across data stores
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

What the ISO 27002 guidance expects the document to say: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.

Evidence an auditor accepts: The backup policy setting scope, frequency, retention and recovery objectives per system; backup job records for the period showing successes and failures, and the follow up on failures; restoration test records showing actual restores performed, what was restored and whether it met the recovery objective
Common gap: infrequent restore testing
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.14 Redundancy of information processing facilities

Build enough redundancy into processing facilities to meet availability requirements.

What the ISO 27002 guidance expects the document to say: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.

Evidence an auditor accepts: Availability requirements per service, expressed as measurable objectives; the redundancy design showing how each requirement is met, and where single points of failure remain; evidence of failover testing, with results measured against the objective and the date of the last test
Common gap: reliance on undocumented manual backups
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.15 Logging

Produce, store, protect and analyse logs of activities, exceptions and faults.

What the ISO 27002 guidance expects the document to say: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.

Evidence an auditor accepts: The logging standard, defining what events are logged per system type, including access, privileged action, change and failure; evidence of logging enabled, sampled across systems, with the retention period applied; evidence logs are protected against alteration and deletion, including restriction of administrator ability to modify them
Common gap: Inconsistent log collection across systems
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.16 Monitoring activities

Monitor networks, systems and applications for anomalies and act on potential incidents.

What the ISO 27002 guidance expects the document to say: Requires networks, systems and applications to be monitored for anomalous behaviour, with appropriate action taken to evaluate whether what is observed constitutes an information security incident. Secondary commentary notes the deliberate shift to anomalous behaviour as the trigger, responding to cloud era risk.

Evidence an auditor accepts: The monitoring design showing what is monitored across networks, systems and applications, and against which baseline of normal behaviour; the detection rules or analytics in use, with evidence of how they were derived and their coverage of relevant threat behaviour; the tuning record, showing rules adjusted over time, false positives reduced and gaps closed
Common gap: alerts not correlated across sources
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.19 Installation of software on operational systems

Securely manage software installation on production systems.

What the ISO 27002 guidance expects the document to say: Requires procedures and measures to be implemented to manage software installation on operational systems securely. Secondary commentary notes that this replaces a narrower restriction on software installation and is oriented to remote working and mobile devices.

Evidence an auditor accepts: Procedures governing installation of software on operational systems, including who may install and under what authorisation; evidence of technical restriction, such as removal of installation rights, application allow listing or package repository control; records of installations performed in the period, tied to an approved change
Common gap: Missing formal approval for installations
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.2 Privileged access rights

Restrict and manage the allocation and use of privileged access.

What the ISO 27002 guidance expects the document to say: Requires the allocation and use of privileged access rights to be restricted and actively managed.

Evidence an auditor accepts: The definition of what counts as privileged in each system, and the register of privileged accounts and their holders; authorisation records for each privileged allocation, showing the business justification and the approver; evidence of restriction, such as separate administrative accounts, multi factor authentication, session recording, vaulting or time bound elevation
Common gap: Outdated privileged account inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

What the ISO 27002 guidance expects the document to say: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.

Evidence an auditor accepts: Network documentation showing the current topology, zones, connections and the security controls at each boundary; configuration standards for network devices and evidence of compliance, including management plane protection; firewall and access control rule sets, with evidence of periodic review and removal of obsolete or overly permissive rules
Common gap: outdated topology diagrams
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.21 Security of network services

Identify, implement and monitor security mechanisms and service levels for network services.

What the ISO 27002 guidance expects the document to say: Requires the security mechanisms for network services, along with their service levels and the requirements placed on them, to be identified, implemented and monitored, whether provision is in house or outsourced.

Evidence an auditor accepts: Identification of network services in use, whether in house or outsourced, with their owners; the security mechanisms, service levels and management requirements defined for each service; evidence of implementation of those mechanisms, such as encryption, authentication and connection controls
Common gap: Out‑of‑date service inventory missing recent cloud assets
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

What the ISO 27002 guidance expects the document to say: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.

Evidence an auditor accepts: The segregation design, showing the defined zones and the criteria placing systems, services and users into each; enforcement evidence at each boundary, such as firewall rules, access control lists or micro segmentation policy; evidence of segregation for wireless, guest, third party, management and operational technology networks
Common gap: Informal or outdated network maps used instead of documented diagrams
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.23 Web filtering

Manage access to external websites to reduce exposure to malicious content.

What the ISO 27002 guidance expects the document to say: Requires access to external websites to be managed so as to reduce exposure to malicious content.

Evidence an auditor accepts: The web filtering policy defining the categories blocked and the basis for blocking; configuration evidence showing the filtering in force, including its coverage across office, remote and mobile users; evidence of handling encrypted traffic, and any decisions taken about inspection, with the privacy considerations
Common gap: Outdated URL category lists
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

What the ISO 27002 guidance expects the document to say: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.

Evidence an auditor accepts: The cryptography rules, defining approved algorithms, key lengths and protocols, and where cryptography must be used; evidence of implementation, sampled across data at rest, data in transit and any application layer encryption; the key management procedures covering generation, distribution, storage, rotation, revocation, archival and destruction
Common gap: Missing documented key lifecycle
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.25 Secure development life cycle

Establish and apply rules for secure development of software and systems.

What the ISO 27002 guidance expects the document to say: Requires rules covering the secure development of both software and systems to be established and applied.

Evidence an auditor accepts: The secure development rules covering the full lifecycle, from requirements through design, build, test and release; evidence the rules apply to all development, including agile teams, integration work and vendor delivered code; evidence of security activities at each stage, such as threat modelling, secure design review, code review and security testing
Common gap: Policy exists but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.26 Application security requirements

Identify, specify and approve security requirements when developing or acquiring applications.

What the ISO 27002 guidance expects the document to say: Requires information security requirements to be identified, specified and approved when applications are being developed or acquired.

Evidence an auditor accepts: The method for identifying security requirements for applications, whether developed or acquired; documented and approved security requirements for applications delivered in the period, covering authentication, authorisation, data protection, logging and error handling; evidence requirements were derived from risk, from the data classification and from applicable legal obligations
Common gap: Security requirements not formally approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.27 Secure system architecture and engineering principles

Establish and apply secure engineering principles to system development.

What the ISO 27002 guidance expects the document to say: Requires principles for engineering secure systems to be established, documented and maintained, then applied across all information system development work.

Evidence an auditor accepts: The documented secure engineering principles, such as defence in depth, least privilege, secure defaults, fail secure and minimising trust; evidence of maintenance, showing the principles are reviewed against current technology and threat; design documentation for systems delivered in the period showing the principles were applied
Common gap: Design reviews not documented
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.28 Secure coding

Apply secure coding principles to software development.

What the ISO 27002 guidance expects the document to say: Requires secure coding principles to be applied to software development.

Evidence an auditor accepts: The secure coding standard in use, per language and framework, and evidence it was communicated to developers; evidence of application, such as static analysis configuration and results, peer review records and the treatment of findings; evidence of control over third party and open source components, including inventory, known vulnerability checking and update process
Common gap: inconsistent application of coding standards
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.29 Security testing in development and acceptance

Define and run security testing across the development life cycle.

What the ISO 27002 guidance expects the document to say: Requires security testing processes to be defined and implemented within the development life cycle.

Evidence an auditor accepts: The security testing process defining what testing is performed at which stage, and the acceptance criteria; test results for the period, covering the techniques used such as static analysis, dynamic testing, dependency scanning and penetration testing; evidence testing occurs in the development lifecycle and again at acceptance, rather than only before a major release
Common gap: testing only after release
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.3 Information access restriction

Restrict access to information and assets per the access control policy.

What the ISO 27002 guidance expects the document to say: Requires access to information and other associated assets to be restricted in accordance with the established topic specific policy on access control.

Evidence an auditor accepts: Evidence access to information is restricted per the access control policy, sampled at the system and data level rather than only at the network level; configuration of the restriction mechanisms, such as application roles, database permissions, file share permissions and cloud storage policies; evidence of restriction on functions as well as data, including read against write against delete and export
Common gap: infrequent or missing access reviews
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.30 Outsourced development

Direct, monitor and review outsourced system development.

What the ISO 27002 guidance expects the document to say: Requires the organisation to direct, monitor and review the activities involved in outsourced system development. Secondary commentary notes that explicit direction and review were added in the 2022 revision in response to third party risk.

Evidence an auditor accepts: Contractual security requirements imposed on the development supplier, covering secure development practice, testing, code ownership and the right to review; evidence of direction given, such as agreed standards, architecture constraints and acceptance criteria; evidence of monitoring during delivery, including progress and security reviews rather than acceptance testing alone
Common gap: contracts lack specific security obligations
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.32 Change management

Put changes to facilities and systems through change management procedures.

What the ISO 27002 guidance expects the document to say: Requires change management procedures to govern changes made to information systems and to the facilities that process information. Older source material adds that changes should be controlled by formal, documented and enforced procedures, with risk assessed as part of the process.

Evidence an auditor accepts: The change management procedure covering the types of change, the authorisation required and the route for emergency change; change records for the period, showing risk and security impact assessment, testing evidence, approval and implementation record; evidence of segregation between the person requesting, approving and implementing a change
Common gap: missing formal approval
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.33 Test information

Select, protect and manage test information appropriately.

What the ISO 27002 guidance expects the document to say: Requires test information to be appropriately selected, protected and managed.

Evidence an auditor accepts: Rules on selecting test information, showing preference for synthetic or masked data over production copies; authorisation records where production information is used for testing, including who approved and for how long; evidence of protection of test information equivalent to its classification, including access control and deletion after use
Common gap: Treating test data like production data without classification
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.5 Secure authentication

Implement authentication technologies and procedures based on access restrictions and policy.

What the ISO 27002 guidance expects the document to say: Requires secure authentication technologies and procedures to be implemented, driven by the information access restrictions and the topic specific policy on access control.

Evidence an auditor accepts: The authentication standard, setting required methods against the sensitivity of the information and the access route; configuration evidence per system showing the enforced authentication, including multi factor coverage and the factors accepted; evidence of protection against brute force and credential stuffing, such as lockout, rate limiting and anomaly detection
Common gap: Reliance on static passwords only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.7 Protection against malware

Implement malware protection backed by user awareness.

What the ISO 27002 guidance expects the document to say: Requires malware protection to be put in place and reinforced by suitable awareness among users.

Evidence an auditor accepts: Malware protection deployment records showing coverage across servers, endpoints, mobile devices, email and web gateways; configuration evidence including update frequency, scanning scope, real time protection and the action taken on detection; coverage reporting showing devices without protection or with outdated definitions, and the follow up on them
Common gap: Outdated malware signatures not regularly updated
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.8 Management of technical vulnerabilities

Obtain vulnerability information, evaluate exposure, and take appropriate remediation.

What the ISO 27002 guidance expects the document to say: Requires information about technical vulnerabilities in the information systems in use to be obtained, the organisation's exposure to them to be evaluated, and appropriate measures to be taken. Older source material sets out the surrounding process: named roles and responsibilities, identified information sources, a defined reaction timeline, assessment of the risk posed by the vulnerability against the risk of applying the patch, testing before deployment, alternative measures where no patch exists, an audit log of actions taken, and highest risk systems addressed first.

Evidence an auditor accepts: Defined roles and information sources for vulnerability identification, and the asset scope they cover; scan results and vulnerability inventory for the period, with authenticated scanning where applicable; the defined reaction timeline by severity, and measurement of actual remediation against it
Common gap: Relying on ad-hoc scans only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

What the ISO 27002 guidance expects the document to say: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.

Evidence an auditor accepts: Documented secure configuration baselines per platform and service, and their basis such as a recognised benchmark; evidence baselines are implemented, sampled across live systems rather than assumed from the build image; automated compliance monitoring output showing conformance and drift, with the frequency of measurement
Common gap: outdated baselines
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

See what it expects of your list

Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.

Build a register