5.1 | Policies for information security | 42 |
5.10 | Acceptable use of information and other associated assets | 30 |
5.11 | Return of assets | 23 |
5.12 | Classification of information | 32 |
5.13 | Labelling of information | 19 |
5.14 | Information transfer | 38 |
5.15 | Access control | 40 |
5.16 | Identity management | 32 |
5.17 | Authentication information | 33 |
5.18 | Access rights | 32 |
5.19 | Information security in supplier relationships | 38 |
5.2 | Information security roles and responsibilities | 42 |
5.20 | Addressing information security within supplier agreements | 35 |
5.21 | Managing information security in the ICT supply chain | 34 |
5.22 | Monitoring, review and change management of supplier services | 34 |
5.23 | Information security for use of cloud services | 33 |
5.24 | Information security incident management planning and preparation | 43 |
5.25 | Assessment and decision on information security events | 38 |
5.26 | Response to information security incidents | 39 |
5.27 | Learning from information security incidents | 35 |
5.28 | Collection of evidence | 30 |
5.29 | Information security during disruption | 30 |
5.3 | Segregation of duties | 37 |
5.30 | ICT readiness for business continuity | 32 |
5.31 | Legal, statutory, regulatory and contractual requirements | 34 |
5.32 | Intellectual property rights | 14 |
5.33 | Protection of records | 35 |
5.34 | Privacy and protection of personal identifiable information (PII) | 26 |
5.35 | Independent review of information security | 41 |
5.36 | Compliance with policies, rules and standards for information security | 40 |
5.37 | Documented operating procedures | 33 |
5.4 | Management responsibilities | 32 |
5.5 | Contact with authorities | 34 |
5.6 | Contact with special interest groups | 23 |
5.7 | Threat intelligence | 35 |
5.8 | Information security in project management | 32 |
5.9 | Inventory of information and other associated assets | 37 |
6.1 | Screening | 34 |
6.2 | Terms and conditions of employment | 33 |
6.3 | Information security awareness, education and training | 43 |
6.4 | Disciplinary process | 21 |
6.5 | Responsibilities after termination or change of employment | 25 |
6.6 | Confidentiality or non-disclosure agreements | 30 |
6.7 | Remote working | 26 |
6.8 | Information security event reporting | 39 |
7.1 | Physical security perimeters | 39 |
7.10 | Storage media | 24 |
7.11 | Supporting utilities | 17 |
7.12 | Cabling security | 13 |
7.13 | Equipment maintenance | 19 |
7.14 | Secure disposal or re-use of equipment | 27 |
7.2 | Physical entry | 34 |
7.3 | Securing offices, rooms and facilities | 30 |
7.4 | Physical security monitoring | 39 |
7.5 | Protecting against physical and environmental threats | 20 |
7.6 | Working in secure areas | 18 |
7.7 | Clear desk and clear screen | 18 |
7.8 | Equipment siting and protection | 18 |
7.9 | Security of assets off-premises | 22 |
8.1 | User end point devices | 30 |
8.10 | Information deletion | 29 |
8.11 | Data masking | 15 |
8.12 | Data leakage prevention | 22 |
8.13 | Information backup | 34 |
8.14 | Redundancy of information processing facilities | 22 |
8.15 | Logging | 38 |
8.16 | Monitoring activities | 36 |
8.17 | Clock synchronization | 18 |
8.18 | Use of privileged utility programs | 25 |
8.19 | Installation of software on operational systems | 32 |
8.2 | Privileged access rights | 33 |
8.20 | Networks security | 32 |
8.21 | Security of network services | 29 |
8.22 | Segregation of networks | 29 |
8.23 | Web filtering | 22 |
8.24 | Use of cryptography | 31 |
8.25 | Secure development life cycle | 29 |
8.26 | Application security requirements | 25 |
8.27 | Secure system architecture and engineering principles | 29 |
8.28 | Secure coding | 24 |
8.29 | Security testing in development and acceptance | 31 |
8.3 | Information access restriction | 35 |
8.30 | Outsourced development | 25 |
8.31 | Separation of development, test and production environments | 28 |
8.32 | Change management | 31 |
8.33 | Test information | 17 |
8.34 | Protection of information systems during audit testing | 23 |
8.4 | Access to source code | 23 |
8.5 | Secure authentication | 33 |
8.6 | Capacity management | 24 |
8.7 | Protection against malware | 31 |
8.8 | Management of technical vulnerabilities | 36 |
8.9 | Configuration management | 34 |
9.2.2 | Internal audit programme | 32 |
9.3.2 | Management review inputs | 31 |
9.3.3 | Management review results | 32 |
clause-10.1 | Continual improvement | 1 |
clause-10.2 | Nonconformity and corrective action | 1 |
clause-4.1 | Understanding the organization and its context | 1 |
clause-4.2 | Understanding the needs and expectations of interested parties | 0 |
clause-4.3 | Determining the scope of the information security management system | 1 |
clause-4.4 | Information security management system | 1 |
clause-5.1 | Leadership and commitment | 0 |
clause-5.2 | Policy | 1 |
clause-5.3 | Organizational roles, responsibilities and authorities | 1 |
clause-6.1.1 | Actions to address risks and opportunities: general | 0 |
clause-6.1.2 | Information security risk assessment | 1 |
clause-6.1.3 | Information security risk treatment | 1 |
clause-6.2 | Information security objectives and planning to achieve them | 1 |
clause-6.3 | Planning of changes | 0 |
clause-7.1 | Resources | 1 |
clause-7.2 | Competence | 1 |
clause-7.3 | Awareness | 0 |
clause-7.4 | Communication | 1 |
clause-7.5.1 | Documented information: general | 0 |
clause-7.5.2 | Documented information: creating and updating | 0 |
clause-7.5.3 | Documented information: control | 0 |
clause-8.1 | Operational planning and control | 0 |
clause-8.2 | Information security risk assessment | 1 |
clause-8.3 | Information security risk treatment | 1 |
clause-9.1 | Monitoring, measurement, analysis and evaluation | 1 |