ISO 27001 controls
The ISO 27001 standard is comprised of the standard itself, plus a second part, called Annex A, where all the controls (114 divided into 14 categories) exist:
- Information Security Policies
- Organization of Information Security
- Human Resources Security
- Asset Management
- Access Control
- Cryptography
- Physical and Environmental Security
- Operational Security
- Communications Security
- System Acquisition, Development, and Maintenance
- Supplier Relationships
- Information Security Incident Management
- Information Security Aspects of Business Continuity Management
- Compliance
Each of the 14 categories provide you with a clear explanation of the primary objective(s) of that category.
Control Category A.5 – Information Security Policies (1 objective and 2 controls)
This category’s aim is to give management guidance and assistance on information security in accordance with the...