Preventive

The list of ISO 27001 Preventive Controls.

Preventive is an ISO 27001 Control Type.

The Control Type is an attribute that allows us to view controls from the perspective of when and how the control modifies a risk in relation to the timing of the occurrence of an information security incident.

ISO 27001 attributes

ISO 27001 Attributes Explained

ISO 27001 Attributes Introduced in the 2022 update to the standard, in this ultimate guide to ISO 27001 Attributes you will learn What are ISO 27001 Attributes? ISO 27001 Attributes are a way to categorise, view and report on the ISO 27001 Annex A Controls. Why are ISO 27001 Attributes important? Attributes can be used […]

ISO 27001 Attributes Explained Read More »

ISO 27001 Annex A 8.31 Separation of Development, Test and Production Environments

ISO 27001:2022 Annex A 8.31 Separation of development, test and production environments

In this guide, I will show you exactly how to implement ISO 27001 Annex A 8.31 and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates and toolkit that make compliance easy. I am Stuart Barker, an ISO 27001 Lead

ISO 27001:2022 Annex A 8.31 Separation of development, test and production environments Read More »

ISO 27001 Annex A 5.37 Documented operating procedures

ISO 27001 Annex A 5.37: A Practical Guide to Documented Operating Procedures

Key Takeaways: ISO 27001 Annex A 5.37 Documented Operating Procedures ISO 27001 Annex A 5.37 is a control that requires organizations to create, maintain, and follow detailed written instructions for all information security tasks. Its primary goal is to minimize the risk of human error and ensure that critical security processes—like backups and system updates—are

ISO 27001 Annex A 5.37: A Practical Guide to Documented Operating Procedures Read More »

ISO 27001 Annex A 5.36 Compliance with policies and standards for information security

ISO 27001:2022 Annex A 5.36 Compliance with policies, rules and standards for information security

Key Takeaways: ISO 27001 Annex A 5.36 Compliance with Policies, Rules and Standards ISO 27001 Annex A 5.36 mandates that organizations verify at regular intervals that their information security procedures are actually being followed. Unlike an independent audit, this control is often performed by internal managers to ensure their own teams are adhering to the

ISO 27001:2022 Annex A 5.36 Compliance with policies, rules and standards for information security Read More »

ISO 27001 Annex A 5.35 Independent review of information security

ISO 27001:2022 Annex A 5.35 Independent review of information security

Key Takeaways: ISO 27001 Annex A 5.35 Independent Review of Information Security ISO 27001 Annex A 5.35 mandates that an organization’s approach to information security is assessed objectively. The goal is to prevent “marking your own homework” ensuring that security controls are evaluated by someone who has no direct influence over the operations being checked.

ISO 27001:2022 Annex A 5.35 Independent review of information security Read More »

ISO 27001 Annex A 5.34 Privacy and protection of PII

ISO 27001:2022 Annex A 5.34 Privacy and protection of PII

Key Takeaways: ISO 27001 Annex A 5.34 Privacy and Protection of PII ISO 27001 Annex A 5.34 requires organizations to identify and protect Personally Identifiable Information (PII) in accordance with applicable laws, regulations, and contracts. It acts as the bridge between your information security management system (ISMS) and privacy frameworks like GDPR, ensuring that personal

ISO 27001:2022 Annex A 5.34 Privacy and protection of PII Read More »

ISO 27001 Annex A 5.32 Intellectual property rights

ISO 27001:2022 Annex A 5.32 Intellectual property rights

Key Takeaways: ISO 27001 Annex A 5.32 Intellectual Property Rights ISO 27001 Annex A 5.32 is the “anti-piracy” and legal compliance control. It requires organizations to implement procedures ensuring they do not violate intellectual property laws (such as copyright or software licensing) and, conversely, that their own proprietary assets are legally protected. Core requirements for

ISO 27001:2022 Annex A 5.32 Intellectual property rights Read More »

ISO 27001 Annex A 5.31 Identification of legal, statutory, regulatory and contractual requirements

ISO 27001:2022 Annex A 5.31 Legal, statutory, regulatory and contractual requirements

Key Takeaways: ISO 27001 Annex A 5.31 Legal, Statutory, Regulatory and Contractual Requirements ISO 27001 Annex A 5.31 requires organizations to identify, document, and keep up-to-date all external rules that impact their information security. Its purpose is to ensure you don’t just “feel” secure, but that you are actually compliant with the specific laws (like

ISO 27001:2022 Annex A 5.31 Legal, statutory, regulatory and contractual requirements Read More »

ISO 27001 Annex A 5.29 Information security during disruption

ISO 27001:2022 Annex A 5.29 Information security during disruption

ISO 27001 Information Security During Disruption In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.29 (Information Security During Disruption) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates and ISO 27001 toolkit that make

ISO 27001:2022 Annex A 5.29 Information security during disruption Read More »

ISO 27001 Annex A 5.27 Learning from information security incidents

ISO 27001:2022 Annex A 5.27 Learning from information security incidents

ISO 27001 Learning From Information Security Incidents In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.27 (Learning From Information Security Incidents) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates and ISO 27001

ISO 27001:2022 Annex A 5.27 Learning from information security incidents Read More »

ISO 27001 Annex A 5.22 Monitoring, review and change management of supplier services

ISO 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier services

ISO 27001 Monitor, Review And Change Management Of Supplier Services In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.22 (Monitor, Review And Change Management Of Supplier Services) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to

ISO 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier services Read More »

ISO 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain

ISO 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain

ISO 27001 Managing Information Security In The ICT Supply Chain In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.21 (Managing Information Security In The ICT Supply Chain) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to

ISO 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain Read More »

ISO 27001 Annex A 5.20 Addressing information security within supplier agreements

ISO 27001:2022 Annex A 5.20 Addressing information security within supplier agreements

ISO 27001 Addressing Information Security Within Supplier Agreements In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.20 (Addressing Information Security Within Supplier Agreements) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates

ISO 27001:2022 Annex A 5.20 Addressing information security within supplier agreements Read More »

ISO 27001 Annex A 5.19 Information security in supplier relationships

ISO 27001:2022 Annex A 5.19 Information security in supplier relationships

ISO 27001 Information Security In Supplier Relationships In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.19 (Information Security In Supplier Relationships) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates and ISO 27001

ISO 27001:2022 Annex A 5.19 Information security in supplier relationships Read More »

ISO 27001 Annex A 5.10

ISO 27001:2022 Annex A 5.10 Acceptable use of information and other associated assets

ISO 27001 Acceptable Use In this guide, I will show you exactly how to implement ISO 27001 Annex A 5.10 (Acceptable Use) and ensure you pass your audit. You will get a complete walkthrough of the control, practical implementation examples, and access to the ISO 27001 templates and ISO 27001 toolkit that make compliance easy. I am Stuart

ISO 27001:2022 Annex A 5.10 Acceptable use of information and other associated assets Read More »

Shopping Basket
Scroll to Top