Edge Register
Standards ยท ISO 27001

ISO/IEC 27001:2022

Rendered when the buyer ticks "ISO/IEC 27001:2022". The register cites 16 of its 93 clauses, behind 8 findings: regulated data at a site with nobody there, intermittent or no link, and no backup stated, personal data at a site outside the home area, plant with no segregation stated, remote access to plant, home and field devices with encryption not stated, concentration in one class or one link type, hardware questions unanswered, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: ISO/IEC 27001:2022. What it attaches to a site: the ISO 27001 regime page.

Clauses cited

16 of 93
ISO 27001 5.14 Information transfer

Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.

ISO 27002 5.14 guidance: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.

Evidence an auditor accepts: transfer_policy; transfer_agreements; transfer_procedures
Common gap: Reliance on informal verbal agreements
Source framework: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

ISO 27002 5.30 guidance: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.

Evidence an auditor accepts: ict_continuity_plan; readiness_test_results; resource_allocation_records
Common gap: Testing frequency not aligned with risk
Source framework: ISO/IEC 27001:2022
ISO 27001 6.7 Remote working

Apply security measures when people access, process or store information outside the organization's premises.

ISO 27002 6.7 guidance: Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.

Evidence an auditor accepts: remote_access_policy; secure_connection_mechanisms; endpoint_security
Common gap: Missing MFA for remote access
Source framework: ISO/IEC 27001:2022
ISO 27001 7.4 Physical security monitoring

Continuously monitor premises for unauthorized physical access.

ISO 27002 7.4 guidance: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.

Evidence an auditor accepts: cctv_logs; access_control_logs; incident_reports
Common gap: logs not retained for required period
Source framework: ISO/IEC 27001:2022
ISO 27001 7.8 Equipment siting and protection

Site equipment securely and protect it.

ISO 27002 7.8 guidance: Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.

Evidence an auditor accepts: site_layout_plans; environmental_controls; physical_security_measures
Common gap: Assuming perimeter security covers equipment
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premises

Protect assets used or held off-site.

ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.

Evidence an auditor accepts: offsite_asset_inventory; transport_security_procedures; third_party_agreements
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.10 Storage media

Manage storage media across acquisition, use, transport and disposal per classification and handling rules.

ISO 27002 7.10 guidance: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.

Evidence an auditor accepts: media_inventory; media_handling_procedures; media_transport_logs
Common gap: No documented classification for media
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenance

Maintain equipment correctly to preserve availability, integrity and confidentiality.

ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.

Evidence an auditor accepts: maintenance_schedule; maintenance_logs; calibration_records
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.1 User end point devices

Protect information stored on, processed by or reachable through user endpoints.

ISO 27002 8.1 guidance: Requires information stored on, processed by or accessible through user endpoint devices to be protected.

Evidence an auditor accepts: device_inventory; endpoint_security_settings; encryption_and_data_protection
Common gap: Incomplete device inventory
Source framework: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malware

Implement malware protection backed by user awareness.

ISO 27002 8.7 guidance: Requires malware protection to be put in place and reinforced by suitable awareness among users.

Evidence an auditor accepts: anti_malware_policy; endpoint_protection; user_awareness_program
Common gap: Outdated malware signatures not regularly updated
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.

Evidence an auditor accepts: baseline_configurations; change_control_records; configuration_audit_reports
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

ISO 27002 8.13 guidance: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.

Evidence an auditor accepts: backup_policy; backup_schedule; backup_test_reports
Common gap: infrequent restore testing
Source framework: ISO/IEC 27001:2022
ISO 27001 8.14 Redundancy of information processing facilities

Build enough redundancy into processing facilities to meet availability requirements.

ISO 27002 8.14 guidance: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.

Evidence an auditor accepts: redundancy_design; capacity_planning; failover_testing
Common gap: reliance on undocumented manual backups
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

ISO 27002 8.20 guidance: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.

Evidence an auditor accepts: network_topology_diagrams; firewall_rule_sets; network_access_control_lists
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

ISO 27002 8.22 guidance: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.

Evidence an auditor accepts: network_segmentation_policy; network_topology_diagrams; firewall_rule_set_documents
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

ISO 27002 8.24 guidance: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.

Evidence an auditor accepts: encryption_policy; key_management_procedures; algorithm_inventory
Common gap: Missing documented key lifecycle
Source framework: ISO/IEC 27001:2022

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register