ISO/IEC 27002:2022
Rendered beside every ISO 27001 clause the register attaches: the guidance for the control, on the open row and on the ISO 27001 standards page. The register cites 16 of its 93 clauses, behind 0 findings, and on the duty rows of every site it reaches.
Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: ISO/IEC 27002:2022.
Clauses cited
16 of 93ISO 27002 5.14 Information transferRequires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.
Common gap: Rules cover email while file sharing services, application programming interfaces and system to system feeds are undocumented
Source framework: ISO/IEC 27002:2022
ISO 27002 5.30 ICT readiness for business continuityRequires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.
Common gap: Recovery objectives set by IT with no business impact analysis behind them
Source framework: ISO/IEC 27002:2022
ISO 27002 6.7 Remote workingRequires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.
Common gap: Rules assume the corporate laptop while personally owned devices access the same information under no measure
Source framework: ISO/IEC 27002:2022
ISO 27002 7.4 Physical security monitoringRequires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.
Common gap: Cameras installed and recording with nobody watching and no alert on anything
Source framework: ISO/IEC 27002:2022
ISO 27002 7.8 Equipment siting and protectionRequires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.
Common gap: Screens in reception areas, open plan seating and meeting rooms visible to visitors and to windows
Source framework: ISO/IEC 27002:2022
ISO 27002 7.9 Security of assets off-premisesRequires assets located away from the organisation's premises to be protected.
Common gap: Register of what is off site does not exist, so exposure after a theft cannot be determined
Source framework: ISO/IEC 27002:2022
ISO 27002 7.10 Storage mediaRequires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.
Common gap: Disposal certificates accepted from a contractor with no serial level reconciliation to what was sent
Source framework: ISO/IEC 27002:2022
ISO 27002 7.13 Equipment maintenanceRequires equipment to be maintained correctly, so that information stays available, intact and confidential.
Common gap: Equipment sent for warranty repair with the drive still in it and no confidentiality agreement in place
Source framework: ISO/IEC 27002:2022
ISO 27002 8.1 User endpoint devicesRequires information stored on, processed by or accessible through user endpoint devices to be protected.
Common gap: Compliance reported for devices that check in, silently excluding devices that have not connected for months
Source framework: ISO/IEC 27002:2022
ISO 27002 8.7 Protection against malwareRequires malware protection to be put in place and reinforced by suitable awareness among users.
Common gap: Coverage measured only across managed devices, so the unmanaged remainder is invisible
Source framework: ISO/IEC 27002:2022
ISO 27002 8.9 Configuration managementRequires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
Common gap: Baseline applied at build with no ongoing measurement, so configuration drifts unchecked from day one
Source framework: ISO/IEC 27002:2022
ISO 27002 8.13 Information backupRequires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
Common gap: Backup success reported by the job while restoration was never attempted, which is the classic and most damaging gap
Source framework: ISO/IEC 27002:2022
ISO 27002 8.14 Redundancy of information processing facilitiesRequires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
Common gap: Redundancy present in the platform while a shared dependency, such as a single directory, database or network path, remains a single point of failure
Source framework: ISO/IEC 27002:2022
ISO 27002 8.20 Networks securityRequires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.
Common gap: Rule sets grown by addition over years with no review, containing permissive any to any rules nobody will remove
Source framework: ISO/IEC 27002:2022
ISO 27002 8.22 Segregation of networksRequires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.
Common gap: Segregation designed and undermined by broad permit rules between zones that were added for a project and never removed
Source framework: ISO/IEC 27002:2022
ISO 27002 8.24 Use of cryptographyRequires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.
Common gap: Rules defined while deprecated protocols and cipher suites remain enabled on live services
Source framework: ISO/IEC 27002:2022
See which clauses your list engages
Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.
Build my edge register