Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

ISO 27001 Annex A

42 controls
123 checks mapped

ISO/IEC 27001 Annex A specifies the controls used to establish, operate, and continually improve an information security management system (ISMS).

Controls assessed

A.16.1.1 Responsibilities & Procedures7

Management must establish responsibilities and procedures for a quick, effective, and orderly response to weaknesses, events, and security incidents. Procedures for incident, event, and weakness response planning should be clearly defined, approved by leadership, and documented. Auditors will expect to see these procedures in place and evidence of their effectiveness.

A.16.1.2 Reporting Information Security Events10

Information security incidents and events must be reportable through appropriate channels as soon as possible. Employees and associated parties should be aware of their obligations to report security incidents. The procedures for reporting should be clear, and the auditor will look for evidence of awareness and reporting procedures among staff.

A.17.1.2 Implementing Information Security Continuity11

Organizations need to establish, document, implement, and maintain processes and controls to ensure information security continuity during disruptive situations. This includes defining responsibilities, activities, owners, timescales, and mitigation work. A management structure and escalation trigger points should be identified to manage the severity of events effectively. The process should also define when to return to business as usual and stop any BCP processes.

A.17.2.1 Availability of Information Processing Facilities4

Redundancy must be implemented in information processing facilities to meet availability requirements. This typically involves duplicate hardware to ensure system availability in case of failure. Regular testing of redundant components and systems is crucial to ensure effective fail-over. Redundant components should be protected at least as much as primary components. For organizations using cloud-based services, redundancy should be addressed in contracts and policies in line with A.15. Auditors will expect periodic testing of redundant systems.

A.18.1.3 Protection of Records26

Records must be protected from loss, destruction, falsification, unauthorized access, and unauthorized release, in accordance with legal, regulatory, contractual, and business requirements. The level and method of protection should be appropriate to the type of record. Considerations include the duration of record retention and technical or physical challenges over time. Auditors will check for compliance with business, legal, regulatory, and contractual obligations in the protection of records.

A.18.1.4 Privacy & Protection of Personally Identifiable Information23

Privacy and protection of personally identifiable information (PII) must comply with relevant legislation and regulation. High standards of confidentiality and integrity are required for PII, with additional controls for sensitive information as defined by laws like the GDPR. Awareness campaigns should emphasize individual responsibility for protecting PII and privacy. Auditors will assess how PII is handled, including the implementation, monitoring, and improvement of controls, compliance with handling requirements, and the adequacy of audits, especially under regulations like the GDPR.

A.18.1.5 Regulation of Cryptographic Controls3

Cryptographic controls must comply with all relevant agreements, legislation, and regulations. Organizations need to understand and comply with the legal and regulatory requirements applicable to cryptographic technologies, particularly when used across borders. Considerations include trans-border import/export laws relating to cryptography. Auditors will look for compliance with the regulation of cryptographic controls and the implementation of relevant controls and awareness programs.

A.6.1.2 Segregation of Duties8

Conflicting duties and areas of responsibility must be segregated to reduce the risk of unauthorized or unintentional modification or misuse of the organization’s assets. The organization should assess whether segregation of duties has been implemented appropriately, especially for higher risk or value information assets. This is crucial even in smaller organizations, where the principle should be applied as far as possible, with good governance and controls for risk management.

A.6.1.5 Information Security in Project Management2

Information security must be integrated into project management for all types of projects. Using template frameworks with checklists can help ensure that information security is consistently considered. Auditors will look for evidence that project participants are considering information security throughout the project lifecycle. This should align with education and awareness programs in HR Security (A.7.2.2) and include considerations for personal data security, compliance with GDPR, and Data Protection Impact Assessments (DPIA).

A.8.1.1 Inventory of Assets1

Assets associated with information and information processing facilities must be identified and managed throughout their lifecycle. An up-to-date inventory or register of these assets is essential, showing management and control based on their importance. The lifecycle typically includes creation, processing, storage, transmission, deletion, and destruction stages. This inventory process is integral to effective asset management and information classification.

A.8.1.2 Ownership of Assets1

Every information asset must have an assigned owner. Asset management ownership, which can differ from legal ownership, can be designated to individuals, departments, or other entities. The ownership assignment should occur at asset creation. The asset owner is responsible for the asset’s effective management throughout its lifecycle, although management responsibilities can be delegated. Documentation of ownership and any changes or delegation throughout the asset’s lifecycle is crucial.

A.9.1.1 Access Control Policy7

An access control policy must be established, documented, and regularly reviewed, considering the business requirements for assets in scope. It should reflect the information security risks and the organization's approach to managing them. Access controls, both digital and physical, should align with Annex A.11 and consider security requirements of business applications, management of access rights, and privileged access. The policy should clarify who needs access to information, supported by formal procedures and responsibilities. Regular reviews and adjustments in response to role changes or during employee exit processes are essential, in alignment with Annex A.7 Human Resource Security.

A.9.1.2 Access to Networks and Network Services29

Access to networks and network services should be guided by the principle of least access, granting users only the access they need for their job roles. The policy should address which networks and services are in scope, authorization procedures for access, and management controls to prevent and monitor access. This includes considerations during onboarding and offboarding processes and is closely related to the overall access control policy.

A.9.2.1 User Registration and Deregistration34

A formal user registration and deregistration process is necessary, including associating individual IDs with actual people and limiting shared access IDs, which should be approved and recorded. This process should tie in with A7 Human Resource Security, ensuring quick registration/deregistration and avoiding reissuing old IDs. Regular reviews of user IDs demonstrate good control and are part of ongoing management, which can be integrated with internal audits and periodic reviews by asset or application owners.

A.9.2.2 User Access Provisioning34

A documented process must be in place for assigning or revoking user access rights to systems and services. This process should include authorization by the owner of the information system or service, verification that access is relevant to the user's role, and protection against premature provisioning. User access should be based on business requirements, with role-based access for systems and services, ensuring efficiency and effectiveness.

A.9.2.3 Management of Privileged Access Rights34

Management of privileged access rights, such as system administration permissions, requires strict control due to their higher level of access over information assets and systems. This includes system-specific clarity on privileges, allocation based on necessity, maintaining a record of all privileges allocated, and regular review of user competence. Good practices include separating system administrator roles from day-to-day user roles and having dual accounts for users performing different jobs on the same platform. Inappropriate use of system administration privileges can lead to significant breaches or failures, hence the need for a 'least access' approach.

A.9.4.1 Information Access Restriction26

Access to information and application system functions must be aligned with the access control policy. This includes role-based access control (RBAC), levels of access, design of menu systems in applications, read/write/delete/execute permissions, limiting information output, and physical/logical access controls to sensitive data and systems. Auditors will verify that access limitations within systems and applications support the access control policies, business requirements, risk levels, and segregation of duties.

A.9.4.4 Use of Privileged Utility Programmes29

Utility programs capable of overriding system and application controls must be strictly managed. Access to these powerful system and network utilities should be restricted to a minimal number of users. Additionally, controls should be in place to prevent unauthorized installation of software, including utilities downloadable from the internet. Use of such utility programs should be logged, and these logs should be periodically monitored and reviewed.

A.9.4.5 Access Control to Program Source Code26

Access to program source code and related items (designs, specifications, verification and validation plans) must be tightly controlled. Controls should include limiting access to as few people as possible, keeping source code off operational systems, implementing a deny-by-default approach for access, logging access and reviewing logs periodically, enforcing strong change control procedures, and conducting frequent audits and reviews. This is crucial to protect against attacks and preserve business value.

A.10.1.1 Policy on the use of Cryptographic Controls18

Encryption and cryptographic controls are key elements in security, but they are not a complete solution on their own. Incorrect selection of cryptographic technologies and poor management of cryptographic material (e.g., keys and certificates) can create vulnerabilities. Encryption can slow down information processing and transmission, so it's important to understand all risks and balance controls adequately while meeting performance goals. A policy on the use of encryption should identify business requirements for encryption and the standards to be implemented, along with legal requirements around encryption.

A.10.1.2 Key Management3

A policy on the use and protection of Cryptographic Keys should be developed and implemented throughout their lifecycle. Key aspects include the creation, distribution, changes, backup, and storage of cryptographic key material up to its end of life and destruction. Managing key material is often the weakest point in encryption, and attackers may target this rather than the encryption itself. Therefore, having robust and secure processes for key management is crucial. Dealing with compromised keys is also important and should be tied into Annex A.16 Security Incident Management where appropriate.

A.12.1.2 Change Management2

Change management controls are essential for the organisation, business procedures, information processing facilities, and systems affecting information security. Properly controlled change management ensures that changes are appropriate, effective, properly authorised, and minimise potential compromise risks. This includes audit logs to evidence the correct use of change procedures. The complexity of change management procedures should correspond to the nature of the change.

A.12.1.3 Capacity Management12

Resource use must be monitored, tuned, and future capacity requirements projected to meet business objectives. Capacity management focuses on data storage, processing power, and communications capacity. It should be proactive, considering capacity in change management, and reactive, with triggers and alerts for critical capacity usage.

A.12.2.1 Controls Against Malware3

Detection, prevention, and recovery controls to protect against malware must be implemented, along with user awareness. Malware protection includes more than just anti-virus software; it also involves restrictions on removable media and software installation, and timely patching of system and software vulnerabilities. Malware protection must be kept up to date, including signature files and the software itself.

A.12.3.1 Information Backup15

Backup copies of information, software, and system images must be taken and tested regularly in accordance with an agreed backup policy. Backup regimes should align with business requirements and risk levels. Protection and storage of backups should be equivalent to or exceed that of live data. Regular testing and monitoring of backups are essential, and backup policies should account for various factors, including mobile and remote storage.

A.12.4.1 Event Logging18

Event logs recording user activities, exceptions, faults, and information security events must be produced, kept, and reviewed regularly. Logging and monitoring mechanisms are crucial for security management and incident investigation. Capacity considerations are important due to the potentially large volume of log data.

A.12.4.2 Protection of Log Information6

Logging facilities and log information must be protected against tampering and unauthorized access. Logs should be stored securely to provide provable evidence, especially in legal proceedings. Protection of logs containing sensitive or personally identifiable information is critical under data protection and privacy legislation.

A.12.4.3 Administrator & Operator Logs3

System administrator and operator activities must be logged, and the logs should be protected and regularly reviewed. Enhanced logging for privileged accounts, such as system administrators and operators, is recommended.

A.12.5.1 Installation of Software on Operational Systems2

Procedures must control the installation of software on operational systems. This includes managing risks of malware, capacity issues, or software enabling malicious activities. Good practices include formal change management, roll-back procedures, and secure storage of previous software versions. Software changes must balance business and security requirements. Auditors will expect to see records of software installations and changes.

A.12.6.1 Management of Technical Vulnerabilities6

Organizations must timely obtain information about technical vulnerabilities and evaluate exposure to address associated risks. Vulnerabilities must be managed effectively, balancing the need for quick patch implementation with thorough testing for system availability and integrity. Awareness and communication strategies are important for vulnerabilities manageable through user behavior. Auditors will look for processes identifying and detecting vulnerabilities, especially in critical systems.

A.12.6.2 Restrictions on Software Installation2

Rules must be established for software installation by users, addressing the risks of malware introduction and software licensing breaches. Ideally, users should not install software on organizational equipment. If full restriction is not feasible, a 'white-list' approach for permissible software is recommended. Auditors will check the restrictions and complementary controls like software audits.

A.13.1.1 Network Controls22

Networks must be managed and controlled to protect information within systems and applications. Appropriate methods should be used for protection, considering all business operations, and designed and implemented based on business requirements, risk assessment, and segregation needs. Examples include connection control, firewalls, intrusion detection systems, access control lists, and segregation. Extra controls are needed for public networks or networks outside organizational control. Auditors will look for effective management of these controls and formal change management procedures.

A.13.1.3 Segregation in Networks23

Information services, users, and systems should be segregated on networks. Duties of network operations and computer/system operations should be segregated where possible. Network design and control should align with information classification policies and segregation requirements.

A.13.2.1 Information Transfer Policies & Procedures5

Formal policies, procedures, and controls must be established for the transfer of information using all communication facilities. These should consider the confidentiality, integrity, and availability of information, accounting for the type, nature, volume, and sensitivity of the information. Policies are especially important when transferring information to and from third parties. Controls should protect against interception, copying, modification, mis-routing, and destruction.

A.13.2.3 Electronic Messaging23

Information involved in electronic messaging must be protected to prevent unauthorized access. Organizations should create policies specifying the appropriate forms of electronic messaging based on the security needed for different types of information transfers. This includes considerations for voice and fax communications, as well as physical transfers (e.g., postal systems), aligning with access controls and secure authentication policies.

A.14.1.1 Information Security Requirements Analysis & Specification2

Information security requirements must be included in the requirements for new information systems or enhancements to existing systems. Security considerations should be aligned with the value of the information at risk and should be part of the project's earliest stages. Security requirements need to be documented and agreed upon before selecting or developing a solution, following a secure by design philosophy. Auditors will look for evidence that security is considered throughout the project lifecycle and that confidentiality, integrity, and availability are prioritized.

A.14.1.2 Securing Application Services on Public Networks11

Application services over public networks, such as the internet, need protection against fraudulent activities, contract disputes, and unauthorized disclosure and modification. Especially in the case of financial transactions or sensitive personal information, security measures must meet GDPR requirements and be monitored constantly. Auditors will expect to see that the level of security for these services is determined based on risk assessments and legal, regulatory, and contractual requirements.

A.14.2.1 Secure Development Policy3

A secure development policy ensures secure development environments and promotes secure coding practices. This policy should cover security at all stages of the development lifecycle, including identifying vulnerabilities specific to coding languages and development tools. Policies should address security checkpoints, secure repositories, version control, application security knowledge, and vulnerability management. Auditors will check that security is appropriately integrated throughout the development lifecycle and that developers are trained and equipped to implement secure practices.

A.14.2.2 System Change Control Procedures3

Formal change control procedures are required to manage changes in the development lifecycle, aligning with operational change control. These procedures aim to reduce the risk of introducing vulnerabilities during development. System owners should be involved in authorisation, pre-live testing, and checking of changes, with audit logs evidencing correct use of change procedures. This control aligns with A.12.1.2 and includes elements from ISO 27002 regarding documentation and deployment timing.

A.14.2.3 Technical Review of Applications After Operating Platform Changes3

When operating platforms change, business-critical applications must be reviewed and tested to ensure compatibility and no adverse impact on organisational operations or security. Testing for compatibility issues should be conducted in a development or test environment, following standard change management control procedures.

A.14.2.4 Restrictions on Changes to Software Packages2

Modifications to software packages should be discouraged, limited to necessary changes, and strictly controlled. Vendor-supplied software is generally not designed for external modifications, and customizations should be within vendor-provided parameters. For open-source software, changes should be restricted and controlled to ensure they do not negatively impact the software's internal integrity or security.

A.14.2.7 Outsourced Development2

Organisations must supervise and monitor outsourced system development. Security requirements for outsourced development should be specified in contracts or agreements, aligning with Annex A 15.1 and A.13.2.4 for confidentiality. It's important to ensure that outsourced partners meet organisational standards for security, including staff vetting and participation in security awareness programs. Auditors will look for evidence of due diligence and information security considerations throughout the outsourcing engagement.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.