International

ISO 27001:2013

140 controls. 1 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

140 controls 1 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

If you runShared controls
ISO 27001:2022114measure it →

Every control

CodeControlAlso in
A.10.1.1Policy on the use of cryptographic controls1
A.10.1.2Key management1
A.11.1.1Physical security perimeter1
A.11.1.2Physical entry controls1
A.11.1.3Securing offices, rooms and facilities1
A.11.1.4Protecting against external and environmental threats1
A.11.1.5Working in secure areas1
A.11.1.6Delivery and loading areas1
A.11.2.1Equipment siting and protection1
A.11.2.2Supporting utilities1
A.11.2.3Cabling security1
A.11.2.4Equipment maintenance1
A.11.2.5Removal of assets1
A.11.2.6Security of equipment and assets off-premises1
A.11.2.7Secure disposal or reuse of equipment1
A.11.2.8Unattended user equipment1
A.11.2.9Clear desk and clear screen policy1
A.12.1.1Documented operating procedures1
A.12.1.2Change management1
A.12.1.3Capacity management1
A.12.1.4Separation of development, testing and operational environments1
A.12.2.1Controls against malware1
A.12.3.1Information backup1
A.12.4.1Event logging1
A.12.4.2Protection of log information1
A.12.4.3Administrator and operator logs1
A.12.4.4Clock synchronisation1
A.12.5.1Installation of software on operational systems1
A.12.6.1Management of technical vulnerabilities1
A.12.6.2Restrictions on software installation1
A.12.7.1Information systems audit controls1
A.13.1.1Network controls1
A.13.1.2Security of network services1
A.13.1.3Segregation in networks1
A.13.2.1Information transfer policies and procedures1
A.13.2.2Agreements on information transfer1
A.13.2.3Electronic messaging1
A.13.2.4Confidentiality or nondisclosure agreements1
A.14.1.1Information security requirements analysis and specification1
A.14.1.2Securing application services on public networks1
A.14.1.3Protecting application services transactions1
A.14.2.1Secure development policy1
A.14.2.2System change control procedures1
A.14.2.3Technical review of applications after operating platform changes1
A.14.2.4Restrictions on changes to software packages1
A.14.2.5Secure system engineering principles1
A.14.2.6Secure development environment1
A.14.2.7Outsourced development1
A.14.2.8System security testing1
A.14.2.9System acceptance testing1
A.14.3.1Protection of test data1
A.15.1.1Information security policy for supplier relationships1
A.15.1.2Addressing security within supplier agreements1
A.15.1.3Information and communication technology supply chain1
A.15.2.1Monitoring and review of supplier services1
A.15.2.2Managing changes to supplier services1
A.16.1.1Responsibilities and procedures1
A.16.1.2Reporting information security events1
A.16.1.3Reporting information security weaknesses1
A.16.1.4Assessment of and decision on information security events1
A.16.1.5Response to information security incidents1
A.16.1.6Learning from information security incidents1
A.16.1.7Collection of evidence1
A.17.1.1Planning information security continuity1
A.17.1.2Implementing information security continuity1
A.17.1.3Verify, review and evaluate information security continuity1
A.17.2.1Availability of information processing facilities1
A.18.1.1Identification of applicable legislation and contractual requirements1
A.18.1.2Intellectual property rights1
A.18.1.3Protection of records1
A.18.1.4Privacy and protection of personally identifiable information1
A.18.1.5Regulation of cryptographic controls1
A.18.2.1Independent review of information security1
A.18.2.2Compliance with security policies and standards1
A.18.2.3Technical compliance review1
A.5.1.1Policies for information security1
A.5.1.2Review of the policies for information security1
A.6.1.1Information security roles and responsibilities1
A.6.1.2Segregation of duties1
A.6.1.3Contact with authorities1
A.6.1.4Contact with special interest groups1
A.6.1.5Information security in project management1
A.6.2.1Mobile device policy1
A.6.2.2Teleworking1
A.7.1.1Screening1
A.7.1.2Terms and conditions of employment1
A.7.2.1Management responsibilities1
A.7.2.2Information security awareness, education and training1
A.7.2.3Disciplinary process1
A.7.3.1Termination or change of employment responsibilities1
A.8.1.1Inventory of assets1
A.8.1.2Ownership of assets1
A.8.1.3Acceptable use of assets1
A.8.1.4Return of assets1
A.8.2.1Classification of information1
A.8.2.2Labelling of information1
A.8.2.3Handling of assets1
A.8.3.1Management of removable media1
A.8.3.2Disposal of media1
A.8.3.3Physical media transfer1
A.9.1.1Access control policy1
A.9.1.2Access to networks and network services1
A.9.2.1User registration and de-registration1
A.9.2.2User access provisioning1
A.9.2.3Management of privileged access rights1
A.9.2.4Management of secret authentication information of users1
A.9.2.5Review of user access rights1
A.9.2.6Removal or adjustment of access rights1
A.9.3.1Use of secret authentication information1
A.9.4.1Information access restriction1
A.9.4.2Secure log-on procedures1
A.9.4.3Password management system1
A.9.4.4Use of privileged utility programs1
A.9.4.5Access control to program source code1
clause-10.1Nonconformity and corrective action0
clause-10.2Continual improvement0
clause-4.1Understanding the organization and its context0
clause-4.2Understanding the needs and expectations of interested parties0
clause-4.3Determining the scope of the information security management system0
clause-4.4Information security management system0
clause-5.1Leadership and commitment0
clause-5.2Policy0
clause-5.3Organizational roles, responsibilities and authorities0
clause-6.1.1Actions to address risks and opportunities: general0
clause-6.1.2Information security risk assessment0
clause-6.1.3Information security risk treatment0
clause-6.2Information security objectives and planning to achieve them0
clause-7.1Resources0
clause-7.2Competence0
clause-7.3Awareness0
clause-7.4Communication0
clause-7.5.1Documented information: general0
clause-7.5.2Documented information: creating and updating0
clause-7.5.3Documented information: control0
clause-8.1Operational planning and control0
clause-8.2Information security risk assessment0
clause-8.3Information security risk treatment0
clause-9.1Monitoring, measurement, analysis and evaluation0
clause-9.2Internal audit0
clause-9.3Management review0

Tell me when ISO 27001:2013 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO 27001:2013, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition