Edge Register
Standards ยท ISO 27002

ISO/IEC 27002:2022

Rendered beside every ISO 27001 clause the register attaches: the guidance for the control, on the open row and on the ISO 27001 standards page. The register cites 16 of its 93 clauses, behind 0 findings, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: ISO/IEC 27002:2022.

Clauses cited

16 of 93
ISO 27002 5.14 Information transfer

Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.

Evidence an auditor accepts: Transfer rules covering each transfer type in use, being electronic, physical and verbal; Transfer agreements with external parties, setting out protection, liability and traceability requirements; Technical evidence of protection in transit, such as enforced transport encryption, secure file transfer configuration and managed file transfer logs
Common gap: Rules cover email while file sharing services, application programming interfaces and system to system feeds are undocumented
Source framework: ISO/IEC 27002:2022
ISO 27002 5.30 ICT readiness for business continuity

Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.

Evidence an auditor accepts: ICT continuity requirements derived from the business impact analysis, expressed as recovery time and recovery point objectives per service; The ICT continuity plans and the technical capability supporting them, such as replication, failover and alternative capacity; Test plans and results for the period, showing objectives were measured against the requirement rather than assumed
Common gap: Recovery objectives set by IT with no business impact analysis behind them
Source framework: ISO/IEC 27002:2022
ISO 27002 6.7 Remote working

Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.

Evidence an auditor accepts: The remote working rules, covering approval, permitted locations, equipment, network use and handling of physical material; Technical measures evidence, such as device encryption, endpoint protection, secure remote access configuration and enforced patching for remote devices; Evidence of protection where personally owned devices are used, including separation of organisational information
Common gap: Rules assume the corporate laptop while personally owned devices access the same information under no measure
Source framework: ISO/IEC 27002:2022
ISO 27002 7.4 Physical security monitoring

Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.

Evidence an auditor accepts: The design of physical monitoring, covering surveillance, intrusion detection, alarms and guarding, and its coverage against the areas defined; Evidence monitoring is continuous, including out of hours and during holidays; Records of alarms and detections in the period, with the response taken and the time to respond
Common gap: Cameras installed and recording with nobody watching and no alert on anything
Source framework: ISO/IEC 27002:2022
ISO 27002 7.8 Equipment siting and protection

Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.

Evidence an auditor accepts: Siting records or floor plans showing equipment placement and the reasoning, including restriction of unnecessary access to work areas; Evidence of viewing angle and screen positioning control where sensitive information is displayed; Evidence of isolation for items needing special protection, and of protection against hazards such as fire, water, dust, vibration and electrical interference
Common gap: Screens in reception areas, open plan seating and meeting rooms visible to visitors and to windows
Source framework: ISO/IEC 27002:2022
ISO 27002 7.9 Security of assets off-premises

Requires assets located away from the organisation's premises to be protected.

Evidence an auditor accepts: Rules covering assets taken off site, including authorisation, permitted use and the protection required; Records of assets held off premises, covering laptops, mobile devices, removable media and physical records; Evidence of protection appropriate to the location, such as encryption, tracking, remote wipe capability and rules for leaving equipment unattended
Common gap: Register of what is off site does not exist, so exposure after a theft cannot be determined
Source framework: ISO/IEC 27002:2022
ISO 27002 7.10 Storage media

Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.

Evidence an auditor accepts: Procedures covering media across acquisition, use, transportation and disposal, tied to the classification scheme; The media register or tracking record for removable and archival media, showing location and content classification; Evidence of protection in transit, including packaging, carrier selection and receipt confirmation
Common gap: Disposal certificates accepted from a contractor with no serial level reconciliation to what was sent
Source framework: ISO/IEC 27002:2022
ISO 27002 7.13 Equipment maintenance

Requires equipment to be maintained correctly, so that information stays available, intact and confidential.

Evidence an auditor accepts: The maintenance schedule per equipment type, aligned to supplier recommendation and to criticality; Maintenance records for the period, showing what was done, by whom and when; Controls over maintenance personnel, including authorisation, supervision and escorting where they access secure areas
Common gap: Equipment sent for warranty repair with the drive still in it and no confidentiality agreement in place
Source framework: ISO/IEC 27002:2022
ISO 27002 8.1 User endpoint devices

Requires information stored on, processed by or accessible through user endpoint devices to be protected.

Evidence an auditor accepts: The endpoint device policy covering corporate and personally owned devices, registration, permitted use and required protections; Configuration baselines for each device type and evidence of compliance across the estate, with the percentage of devices compliant; Evidence of the protective measures in force, such as full disk encryption, endpoint detection, screen lock, patch currency and restriction of administrative rights
Common gap: Compliance reported for devices that check in, silently excluding devices that have not connected for months
Source framework: ISO/IEC 27002:2022
ISO 27002 8.7 Protection against malware

Requires malware protection to be put in place and reinforced by suitable awareness among users.

Evidence an auditor accepts: Malware protection deployment records showing coverage across servers, endpoints, mobile devices, email and web gateways; Configuration evidence including update frequency, scanning scope, real time protection and the action taken on detection; Coverage reporting showing devices without protection or with outdated definitions, and the follow up on them
Common gap: Coverage measured only across managed devices, so the unmanaged remainder is invisible
Source framework: ISO/IEC 27002:2022
ISO 27002 8.9 Configuration management

Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.

Evidence an auditor accepts: Documented secure configuration baselines per platform and service, and their basis such as a recognised benchmark; Evidence baselines are implemented, sampled across live systems rather than assumed from the build image; Automated compliance monitoring output showing conformance and drift, with the frequency of measurement
Common gap: Baseline applied at build with no ongoing measurement, so configuration drifts unchecked from day one
Source framework: ISO/IEC 27002:2022
ISO 27002 8.13 Information backup

Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.

Evidence an auditor accepts: The backup policy setting scope, frequency, retention and recovery objectives per system; Backup job records for the period showing successes and failures, and the follow up on failures; Restoration test records showing actual restores performed, what was restored and whether it met the recovery objective
Common gap: Backup success reported by the job while restoration was never attempted, which is the classic and most damaging gap
Source framework: ISO/IEC 27002:2022
ISO 27002 8.14 Redundancy of information processing facilities

Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.

Evidence an auditor accepts: Availability requirements per service, expressed as measurable objectives; The redundancy design showing how each requirement is met, and where single points of failure remain; Evidence of failover testing, with results measured against the objective and the date of the last test
Common gap: Redundancy present in the platform while a shared dependency, such as a single directory, database or network path, remains a single point of failure
Source framework: ISO/IEC 27002:2022
ISO 27002 8.20 Networks security

Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.

Evidence an auditor accepts: Network documentation showing the current topology, zones, connections and the security controls at each boundary; Configuration standards for network devices and evidence of compliance, including management plane protection; Firewall and access control rule sets, with evidence of periodic review and removal of obsolete or overly permissive rules
Common gap: Rule sets grown by addition over years with no review, containing permissive any to any rules nobody will remove
Source framework: ISO/IEC 27002:2022
ISO 27002 8.22 Segregation of networks

Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.

Evidence an auditor accepts: The segregation design, showing the defined zones and the criteria placing systems, services and users into each; Enforcement evidence at each boundary, such as firewall rules, access control lists or micro segmentation policy; Evidence of segregation for wireless, guest, third party, management and operational technology networks
Common gap: Segregation designed and undermined by broad permit rules between zones that were added for a project and never removed
Source framework: ISO/IEC 27002:2022
ISO 27002 8.24 Use of cryptography

Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.

Evidence an auditor accepts: The cryptography rules, defining approved algorithms, key lengths and protocols, and where cryptography must be used; Evidence of implementation, sampled across data at rest, data in transit and any application layer encryption; The key management procedures covering generation, distribution, storage, rotation, revocation, archival and destruction
Common gap: Rules defined while deprecated protocols and cipher suites remain enabled on live services
Source framework: ISO/IEC 27002:2022

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register