ISO/IEC 27001:2022
9 of the 93 clauses of ISO/IEC 27001:2022 are cited by this register, on Asset inventory sync, Audit evidence pack export, Audit log retention and archive, Backup restore test, Card environment log review, Configuration baseline and drift check, Database snapshot, Dormant account disable and more. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Provision, review, modify and remove access rights in line with the access control policy.
Guidance beside it, ISO 27002 5.18: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.
What an assessor asks to see: access_provision_records; access_review_reports; access_revocation_logs; role_definition_documents. Where it usually falls short: Reviews lack documented corrective actions
Have procedures to identify, collect, acquire and preserve evidence related to security events.
Guidance beside it, ISO 27002 5.28: Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.
What an assessor asks to see: evidence_collection_policy; incident_response_log; forensic_preservation_report; chain_of_custody_form. Where it usually falls short: Procedures not aligned with legal requirements
Maintain and regularly test backups of information, software and systems per the backup policy.
Guidance beside it, ISO 27002 8.13: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
What an assessor asks to see: backup_policy; backup_schedule; backup_test_reports; retention_records. Where it usually falls short: infrequent restore testing
Build enough redundancy into processing facilities to meet availability requirements.
Guidance beside it, ISO 27002 8.14: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
What an assessor asks to see: redundancy_design; capacity_planning; failover_testing; maintenance_records. Where it usually falls short: reliance on undocumented manual backups
Produce, store, protect and analyse logs of activities, exceptions and faults.
Guidance beside it, ISO 27002 8.15: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.
What an assessor asks to see: log_collection_policy; log_storage_and_protection; log_review_and_analysis; log_retention_and_disposal. Where it usually falls short: Inconsistent log collection across systems
Monitor networks, systems and applications for anomalies and act on potential incidents.
Guidance beside it, ISO 27002 8.16: Requires networks, systems and applications to be monitored for anomalous behaviour, with appropriate action taken to evaluate whether what is observed constitutes an information security incident. Secondary commentary notes the deliberate shift to anomalous behaviour as the trigger, responding to cloud era risk.
What an assessor asks to see: network_anomaly_detection_logs; system_integrity_monitoring_reports; application_behavior_alerts; incident_response_records. Where it usually falls short: alerts not correlated across sources
Put changes to facilities and systems through change management procedures.
Guidance beside it, ISO 27002 8.32: Requires change management procedures to govern changes made to information systems and to the facilities that process information. Older source material adds that changes should be controlled by formal, documented and enforced procedures, with risk assessed as part of the process.
What an assessor asks to see: change_requests; change_approvals; implementation_testing; post_implementation_reviews. Where it usually falls short: missing formal approval
Obtain vulnerability information, evaluate exposure, and take appropriate remediation.
Guidance beside it, ISO 27002 8.8: Requires information about technical vulnerabilities in the information systems in use to be obtained, the organisation's exposure to them to be evaluated, and appropriate measures to be taken. Older source material sets out the surrounding process: named roles and responsibilities, identified information sources, a defined reaction timeline, assessment of the risk posed by the vulnerability against the risk of applying the patch, testing before deployment, alternative measures where no patch exists, an audit log of actions taken, and highest risk systems addressed first.
What an assessor asks to see: vulnerability_feed_logs; risk_assessment_reports; remediation_ticket_records; patch_deployment_evidence. Where it usually falls short: Relying on ad-hoc scans only
Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
Guidance beside it, ISO 27002 8.9: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
What an assessor asks to see: baseline_configurations; change_control_records; configuration_audit_reports; secure_hardening_guidelines. Where it usually falls short: outdated baselines
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.