{
  "name": "ISO/IEC 27001:2022 Annex A control reference",
  "version": "1.0.0",
  "reviewed": "2026-08-03",
  "licence": "CC BY 4.0",
  "source": "https://www.pk-sharma.com/tools/iso-27001-annex-a",
  "note": "Control numbers and short titles are identifiers used as references. No text from ISO/IEC 27001 or 27002 is reproduced: the intent, auditor note and common finding fields are original writing, and the type, property and concept classifications are our own analysis aligned to the shape of the ISO 27002 attribute model rather than a reproduction of its tables. The standard itself must be purchased from ISO or a national standards body.",
  "counts": {
    "total": 93,
    "organisational": 37,
    "people": 8,
    "physical": 14,
    "technological": 34,
    "new": 11
  },
  "controls": [
    {
      "ref": "5.1",
      "slug": "policies-for-information-security",
      "title": "Policies for information security",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "5.1.1",
        "5.1.2"
      ],
      "intent": "A defined set of security policies exists, is approved at the right level, is communicated to the people it binds, and is reviewed on a schedule.",
      "auditorNote": "Expect to show the approval record, evidence that staff have seen the policy, and the last review with its outcome. A policy nobody can produce evidence of reading is a finding regardless of how well it is written.",
      "commonFinding": "The policy set exists but has not been reviewed since certification, or the review is minuted with no substantive change considered.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.2",
      "slug": "information-security-roles-and-responsibilities",
      "title": "Information security roles and responsibilities",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "6.1.1"
      ],
      "intent": "Security responsibilities are allocated to named roles, and the people holding them know what they own.",
      "auditorNote": "Assessors test this by asking a named individual what they are responsible for and comparing the answer to the documentation. Alignment between the two matters more than the elegance of the chart.",
      "commonFinding": "Responsibilities are documented centrally but the individuals named cannot describe them, or the named person has left.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.3",
      "slug": "segregation-of-duties",
      "title": "Segregation of duties",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "6.1.2"
      ],
      "intent": "Conflicting duties are separated so no single person can both perform and conceal a damaging action.",
      "auditorNote": "Show which combinations of duties you consider conflicting and how the separation is enforced. Small organisations are expected to document compensating controls rather than claim separation that headcount does not permit.",
      "commonFinding": "Segregation is asserted but the same administrator can grant access, use it, and edit the log of having done so.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.4",
      "slug": "management-responsibilities",
      "title": "Management responsibilities",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "7.2.1"
      ],
      "intent": "Management actively requires staff to apply security in the way the organisation has defined.",
      "auditorNote": "Evidence is behavioural: objectives that mention security, management communications, and action taken when procedures were not followed. A signed policy alone does not demonstrate this control.",
      "commonFinding": "No record of management acting on a known deviation, which reads as tolerance rather than requirement.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.5",
      "slug": "contact-with-authorities",
      "title": "Contact with authorities",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "6.1.3"
      ],
      "intent": "Relevant authorities are identified in advance, with named contacts and the circumstances requiring contact.",
      "auditorNote": "Show who you would contact, for what, and how quickly, including the regulator and law enforcement routes. Statutory reporting deadlines should appear here rather than being discovered mid-incident.",
      "commonFinding": "Authority contacts are listed generically with no thresholds, so nobody can tell from the document when contact is actually required.",
      "types": [
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "respond"
      ]
    },
    {
      "ref": "5.6",
      "slug": "contact-with-special-interest-groups",
      "title": "Contact with special interest groups",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "6.1.4"
      ],
      "intent": "The organisation maintains contact with security forums and professional bodies so it learns of threats and practice from outside itself.",
      "auditorNote": "Memberships, advisory feeds subscribed to, and any evidence that something learned externally changed something internally. The last point is what separates this from a list of newsletters.",
      "commonFinding": "Subscriptions exist but nothing demonstrates that external information ever reached a decision.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify"
      ]
    },
    {
      "ref": "5.7",
      "slug": "threat-intelligence",
      "title": "Threat intelligence",
      "theme": "organisational",
      "isNew": true,
      "from2013": [],
      "intent": "Information about threats is collected and analysed so that it informs the controls the organisation actually operates.",
      "auditorNote": "New in 2022, and frequently misread as buying a feed. Show the sources, who reviews them, and at least one case where intelligence changed a control, a priority, or a risk rating.",
      "commonFinding": "A commercial feed is purchased and nobody can point to a decision it influenced, which demonstrates procurement rather than the control.",
      "types": [
        "detective",
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "detect"
      ]
    },
    {
      "ref": "5.8",
      "slug": "information-security-in-project-management",
      "title": "Information security in project management",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "6.1.5",
        "14.1.1"
      ],
      "intent": "Security requirements are considered within projects, whatever methodology the organisation uses.",
      "auditorNote": "Pick a recent project and trace where security entered it. A gate, a requirement, a risk assessment, a review. If security appears only at go-live, this control is not operating.",
      "commonFinding": "The process describes a security gate that recent projects bypassed without an exception being recorded.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.9",
      "slug": "inventory-of-information-and-other-associated-assets",
      "title": "Inventory of information and other associated assets",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "8.1.1",
        "8.1.2"
      ],
      "intent": "An inventory of information and supporting assets exists, with an owner for each.",
      "auditorNote": "Completeness is tested by sampling in the opposite direction: an assessor picks a device or system they observed and checks whether it appears. Ownership must resolve to a person, not a department.",
      "commonFinding": "The inventory covers servers and laptops but omits SaaS tenancies, data held by suppliers, and anything acquired outside procurement.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify"
      ]
    },
    {
      "ref": "5.10",
      "slug": "acceptable-use-of-information-and-other-associated-assets",
      "title": "Acceptable use of information and other associated assets",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "8.1.3",
        "8.2.3"
      ],
      "intent": "Rules for acceptable use are defined, communicated, and accepted by the people they apply to.",
      "auditorNote": "Show the rules and the acceptance record. Where AI tools, personal devices or removable media are in use, expect the rules to address them specifically rather than by silence.",
      "commonFinding": "The acceptable use policy predates the technology in use, most visibly on generative AI tools staff have already adopted.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.11",
      "slug": "return-of-assets",
      "title": "Return of assets",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "8.1.4"
      ],
      "intent": "Assets are returned when employment or a contract ends.",
      "auditorNote": "Trace a recent leaver end to end: what they held, what came back, and what was done about anything that did not. The exception path is what gets tested.",
      "commonFinding": "Hardware is recovered but accounts, tokens and data held on personal devices are not addressed.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.12",
      "slug": "classification-of-information",
      "title": "Classification of information",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "8.2.1"
      ],
      "intent": "Information is classified according to its sensitivity and to legal and business requirements.",
      "auditorNote": "The scheme must be simple enough that staff apply it consistently. Assessors test consistency by asking two people to classify the same document.",
      "commonFinding": "A five-tier scheme exists and everything in practice is filed at the middle tier, which means the scheme is decorative.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.13",
      "slug": "labelling-of-information",
      "title": "Labelling of information",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "8.2.2"
      ],
      "intent": "Information carries labels reflecting its classification, in line with the scheme adopted.",
      "auditorNote": "Show labelling in the formats you actually use, including email and collaboration tools rather than documents alone. Automated labelling needs evidence that it is applied and not merely available.",
      "commonFinding": "Labelling applies to formal documents while the majority of sensitive information moves through chat and email unlabelled.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.14",
      "slug": "information-transfer",
      "title": "Information transfer",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "13.2.1",
        "13.2.2",
        "13.2.3"
      ],
      "intent": "Rules and agreements govern transfers of information inside the organisation and to external parties.",
      "auditorNote": "Cover every channel in use: electronic, physical and verbal. Expect questions about how sensitive information reaches third parties in practice, not only about the approved mechanism.",
      "commonFinding": "An approved secure transfer method exists alongside widespread informal use of consumer file sharing that nobody has addressed.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.15",
      "slug": "access-control",
      "title": "Access control",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "9.1.1",
        "9.1.2"
      ],
      "intent": "Rules controlling physical and logical access are established on business and security requirements.",
      "auditorNote": "The policy must state the basis for granting access, typically role and need to know, and reality must match it. Assessors sample accounts against the stated rules.",
      "commonFinding": "The policy states least privilege while access is granted by copying the permissions of an existing colleague.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.16",
      "slug": "identity-management",
      "title": "Identity management",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "9.2.1"
      ],
      "intent": "The full life cycle of identities is managed, from creation to removal.",
      "auditorNote": "Expect scrutiny of non-human identities: service accounts, API keys, integration credentials and now AI agents. These are routinely created outside the joiners process and never reviewed.",
      "commonFinding": "Human identity management is sound while service accounts have no owner, no expiry and no review.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.17",
      "slug": "authentication-information",
      "title": "Authentication information",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "9.2.4",
        "9.3.1",
        "9.4.3"
      ],
      "intent": "Allocation and management of authentication information is controlled, including guidance to users.",
      "auditorNote": "Show how credentials are issued, how they are transmitted to the user, and what happens on reset. Multi-factor coverage and its exceptions attract particular attention.",
      "commonFinding": "Multi-factor authentication is enforced for staff and quietly excluded for administrators, legacy protocols, or service accounts.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.18",
      "slug": "access-rights",
      "title": "Access rights",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "9.2.2",
        "9.2.5",
        "9.2.6"
      ],
      "intent": "Access rights are provisioned, reviewed, modified and removed in line with policy.",
      "auditorNote": "The review is the tested part. Show who performed the last review, what they changed as a result, and how quickly access was removed for a sample leaver.",
      "commonFinding": "An access review is completed and approves everything unchanged, which suggests the reviewer lacked the context to challenge anything.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect",
        "detect"
      ]
    },
    {
      "ref": "5.19",
      "slug": "information-security-in-supplier-relationships",
      "title": "Information security in supplier relationships",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "15.1.1"
      ],
      "intent": "Processes exist to manage the security risks of using supplier products and services.",
      "auditorNote": "Show how suppliers enter the process, how they are tiered, and what assessment each tier receives. Tiering by spend rather than by data access is a common weakness worth pre-empting.",
      "commonFinding": "Low-cost suppliers holding highly sensitive data receive no assessment because the trigger is contract value.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.20",
      "slug": "addressing-information-security-within-supplier-agreements",
      "title": "Addressing information security within supplier agreements",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "15.1.2"
      ],
      "intent": "Relevant security requirements are established and agreed with each supplier.",
      "auditorNote": "Produce actual signed agreements containing the requirements, not a template. Incident notification timing, sub-processing and audit rights are the clauses most often examined.",
      "commonFinding": "The clause library is strong and the executed contracts for older suppliers contain none of it.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.21",
      "slug": "managing-information-security-in-the-ict-supply-chain",
      "title": "Managing information security in the ICT supply chain",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "15.1.3"
      ],
      "intent": "Risks associated with the ICT supply chain, including a supplier's own suppliers, are managed.",
      "auditorNote": "Expect questions about sub-processors and about components inside products you buy. Knowing who your suppliers depend on is the substance here.",
      "commonFinding": "Direct suppliers are assessed and no visibility exists beyond the first tier, so concentration risk is unknown.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.22",
      "slug": "monitoring-review-and-change-management-of-supplier-services",
      "title": "Monitoring, review and change management of supplier services",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "15.2.1",
        "15.2.2"
      ],
      "intent": "Supplier service delivery is monitored and reviewed, and changes to it are managed.",
      "auditorNote": "Onboarding assessment is not enough. Show the ongoing review cadence, what it examines, and how a supplier's own change was handled.",
      "commonFinding": "Suppliers are assessed once at onboarding and never revisited, so an assessment three years old is presented as current assurance.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "detect"
      ]
    },
    {
      "ref": "5.23",
      "slug": "information-security-for-use-of-cloud-services",
      "title": "Information security for use of cloud services",
      "theme": "organisational",
      "isNew": true,
      "from2013": [],
      "intent": "Acquisition, use, management and exit of cloud services are governed by defined security requirements.",
      "auditorNote": "New in 2022. The exit half is where organisations are least prepared: show how you would retrieve your data and terminate a service, and what the provider is contractually obliged to do.",
      "commonFinding": "Cloud services are well configured and no exit plan exists, so the organisation cannot describe how it would leave.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "5.24",
      "slug": "information-security-incident-management-planning-and-preparation",
      "title": "Information security incident management planning and preparation",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "16.1.1"
      ],
      "intent": "The organisation plans and prepares for incident management, with defined processes, roles and responsibilities.",
      "auditorNote": "Show the plan, the named roles, and evidence of preparation such as an exercise. A plan never tested against a scenario is a document rather than a capability.",
      "commonFinding": "The plan names roles that no longer exist and has never been exercised.",
      "types": [
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "respond"
      ]
    },
    {
      "ref": "5.25",
      "slug": "assessment-and-decision-on-information-security-events",
      "title": "Assessment and decision on information security events",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "16.1.4"
      ],
      "intent": "Events are assessed and a decision is taken on whether each is an incident.",
      "auditorNote": "Show the triage criteria and a sample of events assessed, including ones judged not to be incidents. The discarded events demonstrate the control as clearly as the escalated ones.",
      "commonFinding": "Only confirmed incidents are recorded, so there is no evidence that assessment happens at all.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect",
        "respond"
      ]
    },
    {
      "ref": "5.26",
      "slug": "response-to-information-security-incidents",
      "title": "Response to information security incidents",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "16.1.5"
      ],
      "intent": "Incidents are responded to in accordance with documented procedures.",
      "auditorNote": "Walk a real incident through the record: detection, decisions, actions, communications and closure. Timeline gaps invite questions about whether the procedure was followed.",
      "commonFinding": "The incident record documents the technical fix and omits the decisions taken and by whom.",
      "types": [
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "respond"
      ]
    },
    {
      "ref": "5.27",
      "slug": "learning-from-information-security-incidents",
      "title": "Learning from information security incidents",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "16.1.6"
      ],
      "intent": "Knowledge from incidents is used to strengthen controls.",
      "auditorNote": "Trace at least one incident to a control change, a risk reassessment or a training update. The link from lesson to change is exactly what is being tested.",
      "commonFinding": "Post-incident reviews produce actions that are never assigned, tracked or closed.",
      "types": [
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "recover",
        "identify"
      ]
    },
    {
      "ref": "5.28",
      "slug": "collection-of-evidence",
      "title": "Collection of evidence",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "16.1.7"
      ],
      "intent": "Procedures exist for identifying, collecting and preserving evidence relating to incidents.",
      "auditorNote": "Show who is authorised to collect evidence, how integrity and chain of custody are preserved, and when external expertise would be engaged.",
      "commonFinding": "Responders remediate immediately and destroy the evidence needed for investigation, insurance or prosecution.",
      "types": [
        "corrective"
      ],
      "properties": [
        "integrity"
      ],
      "concepts": [
        "respond"
      ]
    },
    {
      "ref": "5.29",
      "slug": "information-security-during-disruption",
      "title": "Information security during disruption",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "17.1.1",
        "17.1.2",
        "17.1.3"
      ],
      "intent": "Security is maintained at an appropriate level during disruption, rather than suspended to restore service.",
      "auditorNote": "Show that continuity plans preserve controls, including any temporary access granted during recovery and how it is revoked afterwards.",
      "commonFinding": "Recovery procedures grant broad emergency access with no mechanism to remove it once normal service resumes.",
      "types": [
        "preventive",
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect",
        "recover"
      ]
    },
    {
      "ref": "5.30",
      "slug": "ict-readiness-for-business-continuity",
      "title": "ICT readiness for business continuity",
      "theme": "organisational",
      "isNew": true,
      "from2013": [],
      "intent": "ICT readiness is planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements.",
      "auditorNote": "New in 2022. Expect recovery objectives derived from a business impact analysis rather than asserted, and test results at meaningful scale rather than a single-system restore.",
      "commonFinding": "A recovery time objective was set years ago, has never been validated by testing, and is contradicted by the actual restore throughput.",
      "types": [
        "preventive",
        "corrective"
      ],
      "properties": [
        "availability"
      ],
      "concepts": [
        "recover"
      ]
    },
    {
      "ref": "5.31",
      "slug": "legal-statutory-regulatory-and-contractual-requirements",
      "title": "Legal, statutory, regulatory and contractual requirements",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.1.1",
        "18.1.5"
      ],
      "intent": "Applicable legal and contractual requirements are identified, documented and kept current.",
      "auditorNote": "Produce the register and show the process that keeps it current. Emerging AI regulation is a live example of whether the process is working or the register is static.",
      "commonFinding": "The register lists long-standing obligations and has not been updated for anything enacted in the last two years.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify"
      ]
    },
    {
      "ref": "5.32",
      "slug": "intellectual-property-rights",
      "title": "Intellectual property rights",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.1.2"
      ],
      "intent": "Procedures protect intellectual property rights, including licensing compliance.",
      "auditorNote": "Cover software licensing and open-source obligations. Expect increasing attention to the provenance of AI-generated content and code.",
      "commonFinding": "Commercial licensing is tracked while open-source components carrying obligations are not inventoried at all.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.33",
      "slug": "protection-of-records",
      "title": "Protection of records",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.1.3"
      ],
      "intent": "Records are protected from loss, destruction, falsification, unauthorised access and unauthorised release.",
      "auditorNote": "Show retention periods, where records are held, and how they are protected for the whole retention period including in archive and backup.",
      "commonFinding": "Retention schedules exist and nothing is ever deleted, so the organisation holds records well beyond the period it defined.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "5.34",
      "slug": "privacy-and-protection-of-pii",
      "title": "Privacy and protection of personally identifiable information",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.1.4"
      ],
      "intent": "Privacy requirements are identified and met in line with applicable law and contracts.",
      "auditorNote": "Expect the interface with data protection work to be examined: records of processing, impact assessments, and how a subject request is handled in practice.",
      "commonFinding": "Data protection is treated as a separate programme with no traceable link to the management system.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect",
        "identify"
      ]
    },
    {
      "ref": "5.35",
      "slug": "independent-review-of-information-security",
      "title": "Independent review of information security",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.2.1"
      ],
      "intent": "The approach to managing information security is reviewed independently at planned intervals and on significant change.",
      "auditorNote": "Independence is the point. Show that the reviewer did not operate the controls being reviewed, and show what the review found.",
      "commonFinding": "The internal audit is performed by the person who runs the management system, which is not an independent review.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify"
      ]
    },
    {
      "ref": "5.36",
      "slug": "compliance-with-policies-rules-and-standards",
      "title": "Compliance with policies, rules and standards for information security",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "18.2.2",
        "18.2.3"
      ],
      "intent": "Compliance with the organisation's own security policies and standards is regularly reviewed.",
      "auditorNote": "Show the checks performed, what they found, and what was done about the exceptions. A review reporting full compliance every time invites scrutiny of its method.",
      "commonFinding": "Compliance checking is performed only ahead of the certification audit rather than at the stated interval.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect",
        "identify"
      ]
    },
    {
      "ref": "5.37",
      "slug": "documented-operating-procedures",
      "title": "Documented operating procedures",
      "theme": "organisational",
      "isNew": false,
      "from2013": [
        "12.1.1"
      ],
      "intent": "Operating procedures for information processing facilities are documented and available to those who need them.",
      "auditorNote": "Procedures must be current and reachable by the people performing the task, including during an incident when normal systems may be unavailable.",
      "commonFinding": "Procedures are stored only in a system that would itself be unavailable in the scenario requiring them.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.1",
      "slug": "screening",
      "title": "Screening",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "7.1.1"
      ],
      "intent": "Background verification is carried out before employment, proportionate to the sensitivity of the role.",
      "auditorNote": "Show the checks performed for a sample of recent joiners and the rationale for what each role requires. Contractors and agency staff are expected to be covered too.",
      "commonFinding": "Employees are screened while contractors with equivalent or greater access are not.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.2",
      "slug": "terms-and-conditions-of-employment",
      "title": "Terms and conditions of employment",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "7.1.2"
      ],
      "intent": "Employment agreements state the security responsibilities of the individual and the organisation.",
      "auditorNote": "Produce an executed contract containing the clauses, not the template. Obligations that survive termination should be explicit.",
      "commonFinding": "Recent contracts include the clauses while long-serving staff are on older terms that do not.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.3",
      "slug": "information-security-awareness-education-and-training",
      "title": "Information security awareness, education and training",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "7.2.2"
      ],
      "intent": "Staff receive appropriate awareness, education and training, updated as policy and threat change.",
      "auditorNote": "Completion records alone are weak evidence. Show that content is refreshed to reflect current threats, and that role-specific training exists where roles carry specific risk.",
      "commonFinding": "The same annual module has been issued unchanged for years and reflects neither current threats nor the organisation's own incidents.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.4",
      "slug": "disciplinary-process",
      "title": "Disciplinary process",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "7.2.3"
      ],
      "intent": "A formalised, communicated process exists for acting on security policy violations.",
      "auditorNote": "The process must be documented and known to staff. Evidence of it being applied is persuasive; evidence that a violation was ignored undermines several other controls.",
      "commonFinding": "The process exists in HR documentation and no security violation has ever been routed into it.",
      "types": [
        "corrective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect",
        "respond"
      ]
    },
    {
      "ref": "6.5",
      "slug": "responsibilities-after-termination-or-change-of-employment",
      "title": "Responsibilities after termination or change of employment",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "7.3.1"
      ],
      "intent": "Security responsibilities that remain valid after employment ends or changes are defined and enforced.",
      "auditorNote": "Internal movers are the weak point more often than leavers. Show that a change of role removes access no longer needed rather than only adding what is.",
      "commonFinding": "Staff who change roles accumulate permissions indefinitely because only the joiner and leaver paths are automated.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.6",
      "slug": "confidentiality-or-non-disclosure-agreements",
      "title": "Confidentiality or non-disclosure agreements",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "13.2.4"
      ],
      "intent": "Confidentiality agreements reflecting the organisation's needs are identified, documented, reviewed and signed.",
      "auditorNote": "Show signed agreements for staff and third parties, and evidence that the wording is periodically reviewed rather than inherited indefinitely.",
      "commonFinding": "Agreements are held for employees but not for contractors, visitors or supplier personnel with equivalent access.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.7",
      "slug": "remote-working",
      "title": "Remote working",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "6.2.2"
      ],
      "intent": "Security measures are applied when staff work remotely.",
      "auditorNote": "Cover the home and travel cases: device protection, network assumptions, physical security of the working environment, and handling of printed material.",
      "commonFinding": "The policy addresses corporate laptops on home networks and says nothing about shared or public spaces.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "6.8",
      "slug": "information-security-event-reporting",
      "title": "Information security event reporting",
      "theme": "people",
      "isNew": false,
      "from2013": [
        "16.1.2",
        "16.1.3"
      ],
      "intent": "Staff can report observed or suspected security events through appropriate channels, in a timely way.",
      "auditorNote": "Ask a member of staff how they would report something. If they cannot answer without looking it up, the channel is not effective however well it is documented.",
      "commonFinding": "A reporting channel exists and receives almost nothing, which usually indicates fear of blame rather than absence of events.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect"
      ]
    },
    {
      "ref": "7.1",
      "slug": "physical-security-perimeters",
      "title": "Physical security perimeters",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.1.1"
      ],
      "intent": "Perimeters are defined and used to protect areas containing information and other associated assets.",
      "auditorNote": "Show where the perimeters are and what each protects. Assessors typically walk them, so documentation and the building need to agree.",
      "commonFinding": "The documented perimeter no longer matches the premises after an office move or reconfiguration.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.2",
      "slug": "physical-entry",
      "title": "Physical entry",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.1.2",
        "11.1.6"
      ],
      "intent": "Secure areas are protected by appropriate entry controls and access points.",
      "auditorNote": "Show the access list for secure areas, how visitors are handled, and how leavers are removed. Tailgating controls are commonly probed.",
      "commonFinding": "Physical access lists are not reviewed, so former staff and contractors retain working cards.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.3",
      "slug": "securing-offices-rooms-and-facilities",
      "title": "Securing offices, rooms and facilities",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.1.3"
      ],
      "intent": "Physical security for offices, rooms and facilities is designed and applied.",
      "auditorNote": "Expect attention to rooms where sensitive discussion or processing happens, including whether they are identifiable from outside.",
      "commonFinding": "Sensitive areas are signposted, advertising their location to anyone who reaches the building.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.4",
      "slug": "physical-security-monitoring",
      "title": "Physical security monitoring",
      "theme": "physical",
      "isNew": true,
      "from2013": [],
      "intent": "Premises are continuously monitored for unauthorised physical access.",
      "auditorNote": "New in 2022. Show what is monitored, who reviews it, how long recordings are retained, and the privacy basis for the monitoring.",
      "commonFinding": "Cameras are installed with nobody reviewing the footage and no retention period defined.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect"
      ]
    },
    {
      "ref": "7.5",
      "slug": "protecting-against-physical-and-environmental-threats",
      "title": "Protecting against physical and environmental threats",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.1.4"
      ],
      "intent": "Protection is designed against physical and environmental threats such as fire, flood and natural hazards.",
      "auditorNote": "Show which threats you assessed as relevant to each location and what protection follows. Flood risk for ground floor and basement facilities is regularly overlooked.",
      "commonFinding": "Fire protection is addressed while other locally relevant hazards were never assessed.",
      "types": [
        "preventive"
      ],
      "properties": [
        "availability",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.6",
      "slug": "working-in-secure-areas",
      "title": "Working in secure areas",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.1.5"
      ],
      "intent": "Security measures for working in secure areas are designed and applied.",
      "auditorNote": "Show the rules for those areas, including restrictions on recording devices and on unsupervised third-party work.",
      "commonFinding": "Rules exist for staff and are not applied to maintenance contractors working unaccompanied.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.7",
      "slug": "clear-desk-and-clear-screen",
      "title": "Clear desk and clear screen",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.9"
      ],
      "intent": "Clear desk rules for papers and removable media, and clear screen rules for processing facilities, are defined and applied.",
      "auditorNote": "This is verified by observation during the site visit, so the state of the office on the day is the evidence.",
      "commonFinding": "Screen locking is enforced technically while printed material is left unattended on desks and at printers.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.8",
      "slug": "equipment-siting-and-protection",
      "title": "Equipment siting and protection",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.1"
      ],
      "intent": "Equipment is sited securely and protected.",
      "auditorNote": "Expect attention to overlooking: screens visible from windows or public areas, and equipment sited where it can be tampered with.",
      "commonFinding": "Reception and open-plan screens displaying sensitive information are visible to visitors.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.9",
      "slug": "security-of-assets-off-premises",
      "title": "Security of assets off-premises",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.6"
      ],
      "intent": "Assets used away from the organisation's premises are protected.",
      "auditorNote": "Cover home working equipment, devices in transit and anything held at a third-party site. Encryption status of portable devices is routinely tested.",
      "commonFinding": "Off-premises assets are not tracked, so the organisation cannot say what is off site or with whom.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.10",
      "slug": "storage-media",
      "title": "Storage media",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "8.3.1",
        "8.3.2",
        "8.3.3",
        "11.2.5"
      ],
      "intent": "Storage media are managed through acquisition, use, transport and disposal in line with classification and handling requirements.",
      "auditorNote": "Cover the full life cycle including removable media policy, transport of media, and disposal records.",
      "commonFinding": "Removable media are prohibited by policy and remain technically enabled with no monitoring of use.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.11",
      "slug": "supporting-utilities",
      "title": "Supporting utilities",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.2"
      ],
      "intent": "Facilities are protected from power failures and other disruption caused by failures of supporting utilities.",
      "auditorNote": "Show protection appropriate to your dependence, and evidence it is tested. An untested generator is an assumption.",
      "commonFinding": "Uninterruptible power supplies are installed and their batteries have never been load tested.",
      "types": [
        "preventive"
      ],
      "properties": [
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.12",
      "slug": "cabling-security",
      "title": "Cabling security",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.3"
      ],
      "intent": "Cabling carrying power, data or supporting services is protected from interception, interference and damage.",
      "auditorNote": "Show physical protection of cable routes and patch areas. Where cabling is shared or in common parts, expect questions about who else has access.",
      "commonFinding": "Communications rooms are unlocked or shared with other building tenants.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.13",
      "slug": "equipment-maintenance",
      "title": "Equipment maintenance",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.4"
      ],
      "intent": "Equipment is maintained correctly to ensure availability, integrity and confidentiality of information.",
      "auditorNote": "Show maintenance records and how data is protected when equipment is serviced by third parties or removed from site.",
      "commonFinding": "Equipment is sent for repair with storage still installed and no agreement covering the data on it.",
      "types": [
        "preventive"
      ],
      "properties": [
        "availability",
        "integrity",
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "7.14",
      "slug": "secure-disposal-or-re-use-of-equipment",
      "title": "Secure disposal or re-use of equipment",
      "theme": "physical",
      "isNew": false,
      "from2013": [
        "11.2.7"
      ],
      "intent": "Equipment containing storage media is verified to ensure sensitive data and licensed software are removed or securely overwritten before disposal or re-use.",
      "auditorNote": "Verification is the operative word. Show disposal certificates, the sanitisation method used for each media type, and how you confirmed it happened rather than trusting the supplier's word.",
      "commonFinding": "A disposal supplier is used and the organisation holds no certificates, no asset-level records, and no evidence of verification.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.1",
      "slug": "user-endpoint-devices",
      "title": "User endpoint devices",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "6.2.1",
        "11.2.8"
      ],
      "intent": "Information stored on, processed by or accessible via user endpoint devices is protected.",
      "auditorNote": "Show device inventory, encryption status, patch state and configuration baseline. Personally owned devices with access to organisational information must be addressed explicitly.",
      "commonFinding": "Corporate devices are managed while personal devices accessing email and documents fall outside every control.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.2",
      "slug": "privileged-access-rights",
      "title": "Privileged access rights",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "9.2.3"
      ],
      "intent": "The allocation and use of privileged access rights is restricted and managed.",
      "auditorNote": "Show who holds privilege, why, and how use is logged and reviewed. Standing administrative access attracts more scrutiny than time-bound elevation.",
      "commonFinding": "Administrators use privileged accounts for routine work, so privileged activity cannot be distinguished in the logs.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.3",
      "slug": "information-access-restriction",
      "title": "Information access restriction",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "9.4.1"
      ],
      "intent": "Access to information and other associated assets is restricted in accordance with the access control policy.",
      "auditorNote": "Assessors sample: they pick a sensitive repository and ask who can reach it and why. Broad inherited permissions in collaboration platforms are a frequent weak point.",
      "commonFinding": "Shared drives and collaboration sites are open to all staff because restricting them retrospectively was judged too disruptive.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.4",
      "slug": "access-to-source-code",
      "title": "Access to source code",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "9.4.5"
      ],
      "intent": "Read and write access to source code, development tools and software libraries is appropriately managed.",
      "auditorNote": "Show repository permissions, branch protection and who can release. Expect questions about secrets committed to repositories.",
      "commonFinding": "Repository access is broad and unreviewed, and historical commits contain credentials that were never rotated.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.5",
      "slug": "secure-authentication",
      "title": "Secure authentication",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "9.4.2"
      ],
      "intent": "Secure authentication technologies and procedures are implemented based on access restrictions and the access control policy.",
      "auditorNote": "Show the authentication mechanisms in use and where stronger authentication is required. Every exception should be documented with a rationale and a review date.",
      "commonFinding": "Legacy systems that cannot support modern authentication remain in use with no compensating control and no plan.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.6",
      "slug": "capacity-management",
      "title": "Capacity management",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.1.3"
      ],
      "intent": "Use of resources is monitored and adjusted in line with current and expected capacity requirements.",
      "auditorNote": "Show monitoring, thresholds and evidence of acting on a trend before it became an incident.",
      "commonFinding": "Capacity is monitored and alerts fire routinely without action, so the alerting has been normalised.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "availability"
      ],
      "concepts": [
        "protect",
        "detect"
      ]
    },
    {
      "ref": "8.7",
      "slug": "protection-against-malware",
      "title": "Protection against malware",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.2.1"
      ],
      "intent": "Protection against malware is implemented and supported by appropriate user awareness.",
      "auditorNote": "Show coverage across the estate, not just the managed portion, plus update status and what happens on detection.",
      "commonFinding": "Coverage reporting shows a percentage below one hundred and nobody can identify which devices are missing.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect",
        "detect"
      ]
    },
    {
      "ref": "8.8",
      "slug": "management-of-technical-vulnerabilities",
      "title": "Management of technical vulnerabilities",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.6.1",
        "18.2.3"
      ],
      "intent": "Information about technical vulnerabilities is obtained, exposure evaluated, and appropriate measures taken.",
      "auditorNote": "Show the scanning cadence, how findings are prioritised, and remediation against your own service levels. Overdue critical vulnerabilities need a documented risk acceptance.",
      "commonFinding": "Scanning runs reliably and remediation service levels are routinely breached without exception records.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "8.9",
      "slug": "configuration-management",
      "title": "Configuration management",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.",
      "auditorNote": "New in 2022. Show baselines, how systems are built to them, and how drift is detected. Manual builds without a baseline are the usual gap.",
      "commonFinding": "Baselines are documented and no mechanism exists to detect systems that have drifted away from them.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.10",
      "slug": "information-deletion",
      "title": "Information deletion",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Information stored in systems, devices or other storage media is deleted when no longer required.",
      "auditorNote": "New in 2022. Show deletion in practice across primary systems, backups and any copies held by suppliers, along with how deletion is verified.",
      "commonFinding": "Deletion is performed in the live system while backups retain the data indefinitely, so nothing is genuinely deleted.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.11",
      "slug": "data-masking",
      "title": "Data masking",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Data masking is used in line with the access control policy and business requirements, taking applicable legislation into account.",
      "auditorNote": "New in 2022. The obvious application is non-production environments. Show what is masked, how, and who can reverse it.",
      "commonFinding": "Test environments are populated with a copy of production data, unmasked, and accessible to a wider group than production.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.12",
      "slug": "data-leakage-prevention",
      "title": "Data leakage prevention",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Measures are applied to systems, networks and devices to prevent unauthorised disclosure and extraction of information.",
      "auditorNote": "New in 2022. Show which channels are covered and what happens when something is detected. Coverage of generative AI tools is now an expected question.",
      "commonFinding": "Controls cover email while cloud storage, messaging platforms and AI assistants are unaddressed.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "confidentiality"
      ],
      "concepts": [
        "protect",
        "detect"
      ]
    },
    {
      "ref": "8.13",
      "slug": "information-backup",
      "title": "Information backup",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.3.1"
      ],
      "intent": "Backup copies of information, software and systems are maintained and regularly tested in line with an agreed policy.",
      "auditorNote": "Testing is the tested part. Show restore tests at meaningful scale, their results, and immutability or offline protection against ransomware.",
      "commonFinding": "Backups run successfully and restores have only ever been tested on a single file, so recovery capability at scale is unknown.",
      "types": [
        "corrective"
      ],
      "properties": [
        "availability",
        "integrity"
      ],
      "concepts": [
        "recover"
      ]
    },
    {
      "ref": "8.14",
      "slug": "redundancy-of-information-processing-facilities",
      "title": "Redundancy of information processing facilities",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "17.2.1"
      ],
      "intent": "Information processing facilities are implemented with sufficient redundancy to meet availability requirements.",
      "auditorNote": "Show that redundancy matches stated availability requirements and that failover has been exercised rather than assumed.",
      "commonFinding": "Redundant infrastructure exists and failover has never been tested, or shares a dependency that makes it not redundant.",
      "types": [
        "preventive"
      ],
      "properties": [
        "availability"
      ],
      "concepts": [
        "protect",
        "recover"
      ]
    },
    {
      "ref": "8.15",
      "slug": "logging",
      "title": "Logging",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.4.1",
        "12.4.2",
        "12.4.3"
      ],
      "intent": "Logs recording activities, exceptions, faults and other relevant events are produced, stored, protected and analysed.",
      "auditorNote": "Show what is logged, retention, and protection of the logs from alteration by those they record. Administrator activity must be covered.",
      "commonFinding": "Logs are collected and retained for a period shorter than the time it typically takes to detect an intrusion.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect"
      ]
    },
    {
      "ref": "8.16",
      "slug": "monitoring-activities",
      "title": "Monitoring activities",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Networks, systems and applications are monitored for anomalous behaviour and appropriate action taken to evaluate potential incidents.",
      "auditorNote": "New in 2022, and distinct from logging: this is about actively looking. Show what is monitored, the baseline for normal, who watches, and what happened to recent alerts.",
      "commonFinding": "Logs are collected into a platform that nobody reviews, so collection is presented as monitoring.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "detect"
      ]
    },
    {
      "ref": "8.17",
      "slug": "clock-synchronisation",
      "title": "Clock synchronisation",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.4.4"
      ],
      "intent": "Clocks of information processing systems are synchronised to approved time sources.",
      "auditorNote": "Small control, disproportionate consequences. Without it, correlating logs across systems during an investigation becomes unreliable.",
      "commonFinding": "Most systems synchronise correctly while a few drift, which is discovered only during an investigation.",
      "types": [
        "detective"
      ],
      "properties": [
        "integrity"
      ],
      "concepts": [
        "detect",
        "protect"
      ]
    },
    {
      "ref": "8.18",
      "slug": "use-of-privileged-utility-programs",
      "title": "Use of privileged utility programs",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "9.4.4"
      ],
      "intent": "Use of utility programs capable of overriding system and application controls is restricted and tightly controlled.",
      "auditorNote": "Show which utilities are restricted, who may use them, and how use is logged.",
      "commonFinding": "Powerful administrative tooling is installed broadly because it is convenient, with no restriction or logging.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.19",
      "slug": "installation-of-software-on-operational-systems",
      "title": "Installation of software on operational systems",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.5.1",
        "12.6.2"
      ],
      "intent": "Procedures and measures are implemented to securely manage software installation on operational systems.",
      "auditorNote": "Show who may install software, what controls prevent unapproved installation, and how installed software is inventoried.",
      "commonFinding": "Users hold local administrator rights, so software installation is uncontrolled in practice whatever the policy states.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.20",
      "slug": "networks-security",
      "title": "Networks security",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "13.1.1"
      ],
      "intent": "Networks and network devices are secured, managed and controlled to protect information in systems and applications.",
      "auditorNote": "Show network documentation matching reality, device configuration management, and control of remote access paths.",
      "commonFinding": "Network diagrams are years out of date and omit connections added since.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.21",
      "slug": "security-of-network-services",
      "title": "Security of network services",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "13.1.2"
      ],
      "intent": "Security mechanisms, service levels and requirements of network services are identified, implemented and monitored.",
      "auditorNote": "Show what you require of network service providers and how delivery against it is monitored.",
      "commonFinding": "Network services are procured on availability terms alone with no security requirements stated.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.22",
      "slug": "segregation-of-networks",
      "title": "Segregation of networks",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "13.1.3"
      ],
      "intent": "Groups of information services, users and systems are segregated in networks.",
      "auditorNote": "Show the segregation design and evidence it is enforced rather than intended. Guest, operational technology and management networks receive particular attention.",
      "commonFinding": "Segregation exists on the diagram while permissive rules between segments make it ineffective.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.23",
      "slug": "web-filtering",
      "title": "Web filtering",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Access to external websites is managed to reduce exposure to malicious content.",
      "auditorNote": "New in 2022. Show what is filtered, how the categories were chosen, and how exceptions are requested and approved.",
      "commonFinding": "Filtering applies on the corporate network only and is absent for remote workers, who are the majority.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.24",
      "slug": "use-of-cryptography",
      "title": "Use of cryptography",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "10.1.1",
        "10.1.2"
      ],
      "intent": "Rules for effective use of cryptography, including key management, are defined and implemented.",
      "auditorNote": "Key management is where this control is won or lost. Show generation, storage, rotation, and what happens if a key is compromised.",
      "commonFinding": "Encryption is deployed correctly and keys have never been rotated, with no documented process for doing so.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.25",
      "slug": "secure-development-life-cycle",
      "title": "Secure development life cycle",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.2.1"
      ],
      "intent": "Rules for the secure development of software and systems are established and applied.",
      "auditorNote": "Show the defined life cycle and evidence that a recent change followed it, including where AI coding assistants are used in development.",
      "commonFinding": "A documented life cycle exists that current delivery practice no longer resembles.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.26",
      "slug": "application-security-requirements",
      "title": "Application security requirements",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.1.2",
        "14.1.3"
      ],
      "intent": "Security requirements are identified, specified and approved when developing or acquiring applications.",
      "auditorNote": "Show security requirements captured for a recent application alongside functional ones, and their approval.",
      "commonFinding": "Security requirements are raised at testing, after design decisions have already fixed the outcome.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "protect"
      ]
    },
    {
      "ref": "8.27",
      "slug": "secure-system-architecture-and-engineering-principles",
      "title": "Secure system architecture and engineering principles",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.2.5"
      ],
      "intent": "Principles for engineering secure systems are established, documented, maintained and applied.",
      "auditorNote": "Show the principles and a design that demonstrably applied them. Principles nobody references during design are not operating.",
      "commonFinding": "Principles are documented and no architecture decision record references them.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.28",
      "slug": "secure-coding",
      "title": "Secure coding",
      "theme": "technological",
      "isNew": true,
      "from2013": [],
      "intent": "Secure coding principles are applied to software development.",
      "auditorNote": "New in 2022. Show standards, tooling in the pipeline, and how developers are trained. Where AI assistants generate code, expect questions about review of their output.",
      "commonFinding": "Static analysis runs in the pipeline and its findings are not gating, so they accumulate unaddressed.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.29",
      "slug": "security-testing-in-development-and-acceptance",
      "title": "Security testing in development and acceptance",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.2.8",
        "14.2.9"
      ],
      "intent": "Security testing processes are defined and implemented in the development life cycle.",
      "auditorNote": "Show what testing occurs at which stage, and the acceptance criteria that must be met before release.",
      "commonFinding": "Penetration testing happens annually and is disconnected from the release cycle, so changes ship untested between tests.",
      "types": [
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "identify",
        "detect"
      ]
    },
    {
      "ref": "8.30",
      "slug": "outsourced-development",
      "title": "Outsourced development",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.2.7"
      ],
      "intent": "Outsourced system development is directed, monitored and reviewed.",
      "auditorNote": "Show the security requirements placed on the developer, and how their work is verified rather than accepted.",
      "commonFinding": "Outsourced code is accepted on delivery with no security review by the commissioning organisation.",
      "types": [
        "preventive",
        "detective"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.31",
      "slug": "separation-of-development-test-and-production-environments",
      "title": "Separation of development, test and production environments",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.1.4",
        "14.2.6"
      ],
      "intent": "Development, testing and production environments are separated and secured.",
      "auditorNote": "Show the separation technically and in terms of access. Shared credentials or an identity crossing all three undermine the control however the infrastructure is arranged.",
      "commonFinding": "Environments are separate while the same administrators and the same credentials span all of them.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.32",
      "slug": "change-management",
      "title": "Change management",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.1.2",
        "14.2.2",
        "14.2.3",
        "14.2.4"
      ],
      "intent": "Changes to information processing facilities and systems are subject to change management procedures.",
      "auditorNote": "Sample recent changes and check they followed the process, including emergency changes and their retrospective approval.",
      "commonFinding": "Emergency change is used routinely to bypass approval, so the standard process governs only the changes nobody was in a hurry to make.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity",
        "availability"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.33",
      "slug": "test-information",
      "title": "Test information",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "14.3.1"
      ],
      "intent": "Test information is appropriately selected, protected and managed.",
      "auditorNote": "Show where test data comes from and how it is protected. Production data used for testing requires authorisation, protection and a defined lifespan.",
      "commonFinding": "Production data is copied into test environments without authorisation, masking, or any deletion schedule.",
      "types": [
        "preventive"
      ],
      "properties": [
        "confidentiality",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    },
    {
      "ref": "8.34",
      "slug": "protection-of-information-systems-during-audit-testing",
      "title": "Protection of information systems during audit testing",
      "theme": "technological",
      "isNew": false,
      "from2013": [
        "12.7.1"
      ],
      "intent": "Audit tests and other assurance activities involving operational systems are planned and agreed to minimise disruption.",
      "auditorNote": "Show that audit and testing activity on live systems is planned, agreed with system owners, scoped, and logged.",
      "commonFinding": "Assurance activity is conducted on production without agreed scope or timing, and causes disruption that was avoidable.",
      "types": [
        "preventive"
      ],
      "properties": [
        "availability",
        "integrity"
      ],
      "concepts": [
        "protect"
      ]
    }
  ]
}