All 93 Annex A controls
Grouped by the four Annex A themes, same order your Statement of Applicability will follow.
Organizational
- A.5.1Policies for information security
- A.5.2Information security roles and responsibilities
- A.5.3Segregation of duties
- A.5.4Management responsibilities
- A.5.5Contact with authorities
- A.5.6Contact with special interest groups
- A.5.7Threat intelligence
- A.5.8Information security in project management
- A.5.9Inventory of information and other associated assets
- A.5.10Acceptable use of information and other associated assets
- A.5.11Return of assets
- A.5.12Classification of information
- A.5.13Labelling of information
- A.5.14Information transfer
- A.5.15Access control
- A.5.16Identity management
- A.5.17Authentication information
- A.5.18Access rights
- A.5.19Information security in supplier relationships
- A.5.20Addressing information security within supplier agreements
- A.5.21Managing information security in the ICT supply chain
- A.5.22Monitoring, review and change management of supplier services
- A.5.23Information security for use of cloud services
- A.5.24Information security incident management planning and preparation
- A.5.25Assessment and decision on information security events
- A.5.26Response to information security incidents
- A.5.27Learning from information security incidents
- A.5.28Collection of evidence
- A.5.29Information security during disruption
- A.5.30ICT readiness for business continuity
- A.5.31Legal, statutory, regulatory and contractual requirements
- A.5.32Intellectual property rights
- A.5.33Protection of records
- A.5.34Privacy and protection of PII
- A.5.35Independent review of information security
- A.5.36Compliance with policies, rules and standards for information security
- A.5.37Documented operating procedures
People
- A.6.1Screening
- A.6.2Terms and conditions of employment
- A.6.3Information security awareness, education and training
- A.6.4Disciplinary process
- A.6.5Responsibilities after termination or change of employment
- A.6.6Confidentiality or non-disclosure agreements
- A.6.7Remote working
- A.6.8Information security event reporting
Physical
- A.7.1Physical security perimeters
- A.7.2Physical entry
- A.7.3Securing offices, rooms and facilities
- A.7.4Physical security monitoring
- A.7.5Protecting against physical and environmental threats
- A.7.6Working in secure areas
- A.7.7Clear desk and clear screen
- A.7.8Equipment siting and protection
- A.7.9Security of assets off-premises
- A.7.10Storage media
- A.7.11Supporting utilities
- A.7.12Cabling security
- A.7.13Equipment maintenance
- A.7.14Secure disposal or re-use of equipment
Technological
- A.8.1User end point devices
- A.8.2Privileged access rights
- A.8.3Information access restriction
- A.8.4Access to source code
- A.8.5Secure authentication
- A.8.6Capacity management
- A.8.7Protection against malware
- A.8.8Management of technical vulnerabilities
- A.8.9Configuration management
- A.8.10Information deletion
- A.8.11Data masking
- A.8.12Data leakage prevention
- A.8.13Information backup
- A.8.14Redundancy of information processing facilities
- A.8.15Logging
- A.8.16Monitoring activities
- A.8.17Clock synchronization
- A.8.18Use of privileged utility programs
- A.8.19Installation of software on operational systems
- A.8.20Networks security
- A.8.21Security of network services
- A.8.22Segregation of networks
- A.8.23Web filtering
- A.8.24Use of cryptography
- A.8.25Secure development life cycle
- A.8.26Application security requirements
- A.8.27Secure system architecture and engineering principles
- A.8.28Secure coding
- A.8.29Security testing in development and acceptance
- A.8.30Outsourced development
- A.8.31Separation of development, test and production environments
- A.8.32Change management
- A.8.33Test information
- A.8.34Protection of information systems during audit testing