495 lines
12 KiB
JSON
495 lines
12 KiB
JSON
{
|
|
"name": "ISO/IEC 27001:2022",
|
|
"controls": [
|
|
{
|
|
"id": "C.4.1",
|
|
"name": "Context of the organization - Understanding the organization and its context"
|
|
},
|
|
{
|
|
"id": "C.4.2",
|
|
"name": "Context of the organization - Understanding the needs of interested parties"
|
|
},
|
|
{
|
|
"id": "C.4.3",
|
|
"name": "Context of the organization - Determining the scope of the information security management system"
|
|
},
|
|
{
|
|
"id": "C.4.4",
|
|
"name": "Context of the organization - Information security management system"
|
|
},
|
|
{
|
|
"id": "C.5.1",
|
|
"name": "Leadership - Leadership and commitment"
|
|
},
|
|
{
|
|
"id": "C.5.2",
|
|
"name": "Leadership - Policy"
|
|
},
|
|
{
|
|
"id": "C.5.3",
|
|
"name": "Leadership - Organizational roles, responsibilities and authorities"
|
|
},
|
|
{
|
|
"id": "C.6.1.1",
|
|
"name": "Planning - General actions to address risks and opportunities"
|
|
},
|
|
{
|
|
"id": "C.6.1.2",
|
|
"name": "Planning - Information security risk assessment"
|
|
},
|
|
{
|
|
"id": "C.6.1.3",
|
|
"name": "Planning - Information security risk treatment"
|
|
},
|
|
{
|
|
"id": "C.6.2",
|
|
"name": "Planning - Information security objective and planning to achieve them"
|
|
},
|
|
{
|
|
"id": "C.6.3",
|
|
"name": "Planning - Planning of Changes"
|
|
},
|
|
{
|
|
"id": "C.7.1",
|
|
"name": "Support - Resources"
|
|
},
|
|
{
|
|
"id": "C.7.2",
|
|
"name": "Support - Competence"
|
|
},
|
|
{
|
|
"id": "C.7.3",
|
|
"name": "Support - Awareness"
|
|
},
|
|
{
|
|
"id": "C.7.4",
|
|
"name": "Support - Communication"
|
|
},
|
|
{
|
|
"id": "C.7.5.1",
|
|
"name": "Support - Documented information"
|
|
},
|
|
{
|
|
"id": "C.7.5.2",
|
|
"name": "Support - Creating and Updating",
|
|
"id": "C.7.5.3",
|
|
"name": "Support - Control of documented information"
|
|
},
|
|
{
|
|
"id": "C.8.1",
|
|
"name": "Operation - Operation planning and control"
|
|
},
|
|
{
|
|
"id": "C.8.2",
|
|
"name": "Operation - Information security risk assessment"
|
|
},
|
|
{
|
|
"id": "C.8.3",
|
|
"name": "Operation - Information security risk treatment"
|
|
},
|
|
{
|
|
"id": "C.9.1",
|
|
"name": "Performance evaluation - Monitoring, measurement, analysis, and evaluation"
|
|
},
|
|
{
|
|
"id": "C.9.2.1",
|
|
"name": "Performance evaluation - Internal Audit - General"
|
|
},
|
|
{
|
|
"id": "C.9.2.2",
|
|
"name": "Performance evaluation - Internal Audit Program"
|
|
},
|
|
{
|
|
"id": "C.9.3.1",
|
|
"name": "Performance evaluation - Management review - General"
|
|
},
|
|
{
|
|
"id": "C.9.3.2",
|
|
"name": "Performance evaluation - Management review inputs"
|
|
},
|
|
{
|
|
"id": "C.9.3.3",
|
|
"name": "Performance evaluation - Management review results"
|
|
},
|
|
{
|
|
"id": "C.10.1",
|
|
"name": "Improvement - Continual Improvement"
|
|
},
|
|
{
|
|
"id": "C.10.2",
|
|
"name": "Improvement - Nonconformity and corrective action"
|
|
},
|
|
{
|
|
"id": "A.5.1",
|
|
"name": "Organizational - Policies for information security"
|
|
},
|
|
{
|
|
"id": "A.5.2",
|
|
"name": "Organizational - Information security roles and responsibilities"
|
|
},
|
|
{
|
|
"id": "A.5.3",
|
|
"name": "Organizational - Segregation of duties"
|
|
},
|
|
{
|
|
"id": "A.5.4",
|
|
"name": "Organizational - Management responsibilities"
|
|
},
|
|
{
|
|
"id": "A.5.5",
|
|
"name": "Organizational - Contact with authorities"
|
|
},
|
|
{
|
|
"id": "A.5.6",
|
|
"name": "Organizational - Contact with special interest groups"
|
|
},
|
|
{
|
|
"id": "A.5.7",
|
|
"name": "Organizational - Threat Intelligence"
|
|
},
|
|
{
|
|
"id": "A.5.8",
|
|
"name": "Organizational - Information security in project management"
|
|
},
|
|
{
|
|
"id": "A.5.9",
|
|
"name": "Organizational - Inventory of information and other associated assets"
|
|
},
|
|
{
|
|
"id": "A.5.10",
|
|
"name": "Organizational - Acceptable use of information and other associated assets"
|
|
},
|
|
{
|
|
"id": "A.5.11",
|
|
"name": "Organizational - Return of assets"
|
|
},
|
|
{
|
|
"id": "A.5.12",
|
|
"name": "Organizational - Classification of information"
|
|
},
|
|
{
|
|
"id": "A.5.13",
|
|
"name": "Organizational - Labelling of information"
|
|
},
|
|
{
|
|
"id": "A.5.14",
|
|
"name": "Organizational - Information transfer"
|
|
},
|
|
{
|
|
"id": "A.5.15",
|
|
"name": "Organizational - Access control"
|
|
},
|
|
{
|
|
"id": "A.5.16",
|
|
"name": "Organizational - Identity management"
|
|
},
|
|
{
|
|
"id": "A.5.17",
|
|
"name": "Organizational - Authentication information"
|
|
},
|
|
{
|
|
"id": "A.5.18",
|
|
"name": "Organizational - Access rights"
|
|
},
|
|
{
|
|
"id": "A.5.19",
|
|
"name": "Organizational - Information security in supplier relationships"
|
|
},
|
|
{
|
|
"id": "A.5.20",
|
|
"name": "Organizational - Addressing information security within supplier agreements"
|
|
},
|
|
{
|
|
"id": "A.5.21",
|
|
"name": "Organizational - Managing information security in the ICT supply chain"
|
|
},
|
|
{
|
|
"id": "A.5.22",
|
|
"name": "Organizational - Monitoring, review and change management of supplier services"
|
|
},
|
|
{
|
|
"id": "A.5.23",
|
|
"name": "Organizational - Information security for use of cloud services"
|
|
},
|
|
{
|
|
"id": "A.5.24",
|
|
"name": "Organizational - Information security incident management planning and preparation"
|
|
},
|
|
{
|
|
"id": "A.5.25",
|
|
"name": "Organizational - Assessment and decision on information security events"
|
|
},
|
|
{
|
|
"id": "A.5.26",
|
|
"name": "Organizational - Response to information security incidents"
|
|
},
|
|
{
|
|
"id": "A.5.27",
|
|
"name": "Organizational - Learning from information security incidents"
|
|
},
|
|
{
|
|
"id": "A.5.28",
|
|
"name": "Organizational - Collection of evidence"
|
|
},
|
|
{
|
|
"id": "A.5.29",
|
|
"name": "Organizational - Information security during disruption"
|
|
},
|
|
{
|
|
"id": "A.5.30",
|
|
"name": "Organizational - ICT readiness for business continuity"
|
|
},
|
|
{
|
|
"id": "A.5.31",
|
|
"name": "Organizational - Legal, statutory, regulatory and contractual requirements"
|
|
},
|
|
{
|
|
"id": "A.5.32",
|
|
"name": "Organizational - Intellectual property rights"
|
|
},
|
|
{
|
|
"id": "A.5.33",
|
|
"name": "Organizational - Protection of records"
|
|
},
|
|
{
|
|
"id": "A.5.34",
|
|
"name": "Organizational - Privacy and protection of PII"
|
|
},
|
|
{
|
|
"id": "A.5.35",
|
|
"name": "Organizational - Independent review of information security"
|
|
},
|
|
{
|
|
"id": "A.5.36",
|
|
"name": "Organizational - Compliance with policies, rules and standards for information security"
|
|
},
|
|
{
|
|
"id": "A.5.37",
|
|
"name": "Organizational - Documented operating procedures"
|
|
},
|
|
{
|
|
"id": "A.6.1",
|
|
"name": "People - Screening"
|
|
},
|
|
{
|
|
"id": "A.6.2",
|
|
"name": "People - Terms and conditions of employment"
|
|
},
|
|
{
|
|
"id": "A.6.3",
|
|
"name": "People - Information security awareness, education and training"
|
|
},
|
|
{
|
|
"id": "A.6.4",
|
|
"name": "People - Disciplinary process"
|
|
},
|
|
{
|
|
"id": "A.6.5",
|
|
"name": "People - Responsibilities after termination or change of employment"
|
|
},
|
|
{
|
|
"id": "A.6.6",
|
|
"name": "People - Confidentiality or non-disclosure agreements"
|
|
},
|
|
{
|
|
"id": "A.6.7",
|
|
"name": "People - Remote working"
|
|
},
|
|
{
|
|
"id": "A.6.8",
|
|
"name": "People - Information security event reporting"
|
|
},
|
|
{
|
|
"id": "A.7.1",
|
|
"name": "Physical - Physical security perimeters"
|
|
},
|
|
{
|
|
"id": "A.7.2",
|
|
"name": "Physical - Physical entry"
|
|
},
|
|
{
|
|
"id": "A.7.3",
|
|
"name": "Physical - Securing offices, rooms and facilities"
|
|
},
|
|
{
|
|
"id": "A.7.4",
|
|
"name": "Physical - Physical security monitoring"
|
|
},
|
|
{
|
|
"id": "A.7.5",
|
|
"name": "Physical - Protecting against physical and environmental threats"
|
|
},
|
|
{
|
|
"id": "A.7.6",
|
|
"name": "Physical - Working in secure areas"
|
|
},
|
|
{
|
|
"id": "A.7.7",
|
|
"name": "Physical - Clear desk and clear screen"
|
|
},
|
|
{
|
|
"id": "A.7.8",
|
|
"name": "Physical - Equipment siting and protection"
|
|
},
|
|
{
|
|
"id": "A.7.9",
|
|
"name": "Physical - Security of assets off-premises"
|
|
},
|
|
{
|
|
"id": "A.7.10",
|
|
"name": "Physical - Storage media"
|
|
},
|
|
{
|
|
"id": "A.7.11",
|
|
"name": "Physical - Supporting utilities"
|
|
},
|
|
{
|
|
"id": "A.7.12",
|
|
"name": "Physical - Cabling security"
|
|
},
|
|
{
|
|
"id": "A.7.13",
|
|
"name": "Physical - Equipment maintenance"
|
|
},
|
|
{
|
|
"id": "A.7.14",
|
|
"name": "Physical - Secure disposal or re-use of equipment"
|
|
},
|
|
{
|
|
"id": "A.8.1",
|
|
"name": "Technological - User endpoint devices"
|
|
},
|
|
{
|
|
"id": "A.8.2",
|
|
"name": "Technological - Privileged access rights"
|
|
},
|
|
{
|
|
"id": "A.8.3",
|
|
"name": "Technological - Information access restriction"
|
|
},
|
|
{
|
|
"id": "A.8.4",
|
|
"name": "Technological - Access to source code"
|
|
},
|
|
{
|
|
"id": "A.8.5",
|
|
"name": "Technological - Secure authentication"
|
|
},
|
|
{
|
|
"id": "A.8.6",
|
|
"name": "Technological - Capacity management"
|
|
},
|
|
{
|
|
"id": "A.8.7",
|
|
"name": "Technological - Protection against malware"
|
|
},
|
|
{
|
|
"id": "A.8.8",
|
|
"name": "Technological - Management of technical vulnerabilities"
|
|
},
|
|
{
|
|
"id": "A.8.9",
|
|
"name": "Technological - Configuration management"
|
|
},
|
|
{
|
|
"id": "A.8.10",
|
|
"name": "Technological - Information deletion"
|
|
},
|
|
{
|
|
"id": "A.8.11",
|
|
"name": "Technological - Data masking"
|
|
},
|
|
{
|
|
"id": "A.8.12",
|
|
"name": "Technological - Data leakage prevention"
|
|
},
|
|
{
|
|
"id": "A.8.13",
|
|
"name": "Technological - Information backup"
|
|
},
|
|
{
|
|
"id": "A.8.14",
|
|
"name": "Technological - Redundancy of information processing facilities"
|
|
},
|
|
{
|
|
"id": "A.8.15",
|
|
"name": "Technological - Logging"
|
|
},
|
|
{
|
|
"id": "A.8.16",
|
|
"name": "Technological - Monitoring activities"
|
|
},
|
|
{
|
|
"id": "A.8.17",
|
|
"name": "Technological - Clock synchronization"
|
|
},
|
|
{
|
|
"id": "A.8.18",
|
|
"name": "Technological - Use of privileged utility programs"
|
|
},
|
|
{
|
|
"id": "A.8.19",
|
|
"name": "Technological - Installation of software on operational systems"
|
|
},
|
|
{
|
|
"id": "A.8.20",
|
|
"name": "Technological - Networks security"
|
|
},
|
|
{
|
|
"id": "A.8.21",
|
|
"name": "Technological - Security of network services"
|
|
},
|
|
{
|
|
"id": "A.8.22",
|
|
"name": "Technological - Segregation of networks"
|
|
},
|
|
{
|
|
"id": "A.8.23",
|
|
"name": "Technological - Web filtering"
|
|
},
|
|
{
|
|
"id": "A.8.24",
|
|
"name": "Technological - Use of cryptography"
|
|
},
|
|
{
|
|
"id": "A.8.25",
|
|
"name": "Technological - Secure development life cycle"
|
|
},
|
|
{
|
|
"id": "A.8.26"
|
|
},
|
|
{
|
|
"id": "A.8.27",
|
|
"name": "Technological - Secure system architecture and engineering principles"
|
|
},
|
|
{
|
|
"id": "A.8.28",
|
|
"name": "Technological - Secure coding"
|
|
},
|
|
{
|
|
"id": "A.8.29",
|
|
"name": "Technological - Security testing in development and acceptance"
|
|
},
|
|
{
|
|
"id": "A.8.30",
|
|
"name": "Technological - Outsourced development"
|
|
},
|
|
{
|
|
"id": "A.8.31",
|
|
"name": "Technological - Separation of development, test and production environments"
|
|
},
|
|
{
|
|
"id": "A.8.32",
|
|
"name": "Technological - Change management"
|
|
},
|
|
{
|
|
"id": "A.8.33",
|
|
"name": "Technological - Test information"
|
|
},
|
|
{
|
|
"id": "A.8.34",
|
|
"name": "Technological - Protection of information systems during audit testing"
|
|
}
|
|
]
|
|
}
|