ISO/IEC 27001:2022, with the 27002:2022 guidance beside it
Attaches to every site: the off-premises, equipment, media, endpoint, backup, redundancy, network and continuity controls of Annex A, by the site's exposure, link, data and plant. With nothing ticked these rows render as the default.
On the register, tick "ISO/IEC 27001:2022" and these rows appear on every site. Source framework: ISO/IEC 27001:2022, with the 27002:2022 guidance beside it.
How the duties attach
| Reaches | Every site. |
|---|---|
| every site | 7.9, 7.13, 8.9 |
| site unattended | 7.4, 7.8 |
| site public | 7.4, 7.8 |
| site in a hostile place | 7.8 |
| link intermittent | 5.30, 8.13, 8.14 |
| no link | 5.14, 5.30, 8.13 |
| holds personal data | 5.14, 7.10, 8.24 |
| holds payment data | 7.10, 8.20, 8.24 |
| holds health data | 5.14, 7.10, 8.24 |
| holds controlled data (CUI) | 7.10, 8.24 |
| runs plant | 8.7, 8.20, 8.22 |
| remote access named | 8.20, 8.22 |
| Home and remote worker | 6.7, 8.1, 8.7 |
| Field and temporary site | 6.7, 8.1, 7.10 |
| Vehicle, vessel and aircraft | 8.1, 7.10 |
| Unattended kiosk and terminal | 8.20, 8.7, 8.22 |
| Ground station and telemetry site | 8.20, 8.14 |
The 27002 guidance beside every row
Every ISO 27001 clause the register attaches carries the matching ISO/IEC 27002:2022 guidance beside it, on the open row and on the standards page, so the reader sees what the control expects and how the guidance says to meet it. The guidance quoted.
The clauses, quoted
16 of 93 in the frameworkRequirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.
ISO 27001 5.14 Information transferPut rules, procedures or agreements in place for every way information moves, inside and outside the organization.
ISO 27002 5.14 guidance: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.
Common gap: Reliance on informal verbal agreements
Source framework: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuityPlan, implement, maintain and test ICT readiness against business continuity objectives.
ISO 27002 5.30 guidance: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.
Common gap: Testing frequency not aligned with risk
Source framework: ISO/IEC 27001:2022
ISO 27001 6.7 Remote workingApply security measures when people access, process or store information outside the organization's premises.
ISO 27002 6.7 guidance: Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.
Common gap: Missing MFA for remote access
Source framework: ISO/IEC 27001:2022
ISO 27001 7.4 Physical security monitoringContinuously monitor premises for unauthorized physical access.
ISO 27002 7.4 guidance: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.
Common gap: logs not retained for required period
Source framework: ISO/IEC 27001:2022
ISO 27001 7.8 Equipment siting and protectionSite equipment securely and protect it.
ISO 27002 7.8 guidance: Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.
Common gap: Assuming perimeter security covers equipment
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premisesProtect assets used or held off-site.
ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.10 Storage mediaManage storage media across acquisition, use, transport and disposal per classification and handling rules.
ISO 27002 7.10 guidance: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.
Common gap: No documented classification for media
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenanceMaintain equipment correctly to preserve availability, integrity and confidentiality.
ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.1 User end point devicesProtect information stored on, processed by or reachable through user endpoints.
ISO 27002 8.1 guidance: Requires information stored on, processed by or accessible through user endpoint devices to be protected.
Common gap: Incomplete device inventory
Source framework: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malwareImplement malware protection backed by user awareness.
ISO 27002 8.7 guidance: Requires malware protection to be put in place and reinforced by suitable awareness among users.
Common gap: Outdated malware signatures not regularly updated
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
ISO 27002 8.13 guidance: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
Common gap: infrequent restore testing
Source framework: ISO/IEC 27001:2022
ISO 27001 8.14 Redundancy of information processing facilitiesBuild enough redundancy into processing facilities to meet availability requirements.
ISO 27002 8.14 guidance: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
Common gap: reliance on undocumented manual backups
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks securitySecure, manage and control networks and network devices.
ISO 27002 8.20 guidance: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networksSegregate groups of services, users and systems in the network.
ISO 27002 8.22 guidance: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptographyDefine and implement rules for effective use of cryptography and key management.
ISO 27002 8.24 guidance: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.
Common gap: Missing documented key lifecycle
Source framework: ISO/IEC 27001:2022
See what it attaches to your list
Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.
Build my edge register