Annex A Controls Explained
Annex A controls can be confusing
So we wrote a series of blogs AND created videos that explain what each control is expecting. Here we summarise them (as best we can) so that you have something you can refer to quickly.
If you’re still confused, please contact us. We know it’s all about ‘context’ and the examples we’ve provided might not make sense to you.
But I hope there’s something here that helps you gain ‘control’ of your controls! 😁
Organisational Controls
A5.1 Information Security Policies
Do I need an Information Security Policy?
Many organisations treat policies as paperwork created solely for auditors. The result is often a lengthy document that nobody reads, understands, or follows.
An Information Security Policy is much more than a compliance requirement. It sets the direction for how your organisation protects information, manages risk, and demonstrates its commitment to security. It doesn’t need to be ‘war and peace’. Focus on clarity and intent – what is the TRUTH? What do you EXPECT?
ISO27001 requires organisations to establish, approve, communicate, and regularly review information security policies. These policies should be appropriate to the organisation’s purpose, size, and risks – not copied from someone else’s template (or from ChatGPT!)
A good policy provides clarity for employees, confidence for customers, and evidence that security is being managed in a structured and consistent way.
A.5.2 Information Security Roles and Responsibilities
Who is responsible for cyber security in my organisation?
One of the most common mistakes organisations make is assuming that cyber security is “an IT problem”. The reality is that information security is everyone’s responsibility—but not everyone’s responsibility is the same.
Without clearly defined roles and responsibilities, important tasks can be overlooked, risks can go unmanaged, and accountability quickly becomes blurred. When something goes wrong, organisations often discover that nobody was actually responsible for the issue in the first place.
ISO27001 requires organisations to define and communicate information security roles and responsibilities. This means people should understand what is expected of them, who owns key security activities, and who is accountable for managing information security risks.
For smaller organisations, this doesn’t mean hiring a full-time security team. It simply means making sure security responsibilities are clearly assigned and understood.
Good security starts with clear ownership.
A5.3 Segregation of Duties
Should one person be responsible for everything?
In many organisations, especially smaller businesses, it’s common for one person to have complete control over a process. They might raise purchase orders, approve invoices, make payments, and reconcile accounts. It feels efficient—until something goes wrong.
When too much authority is concentrated in one role, the risk of mistakes, fraud, abuse, or unauthorised activity increases significantly. It also creates a single point of failure if that person is unavailable or leaves the organisation.
ISO27001 requires organisations to separate responsibilities where practical. This doesn’t mean creating unnecessary bureaucracy. It means ensuring that critical activities have appropriate oversight, checks, and balances.
The goal is simple: no single individual should have unchecked control over activities that could create significant risk for the organisation.
Good security isn’t about a lack of trust. It’s about reducing risk and protecting everyone involved.
A5.4 Management Responsibilities
What role should leadership play in information security?
Many organisations believe cyber security, data protection, and information security are technical problems that should be left to the IT team. Unfortunately, attackers, regulators, customers, and auditors don’t see it that way.
Information security starts with leadership.
If managers and senior leaders don’t demonstrate the right behaviours, employees are unlikely to take security seriously. When leadership ignores policies, delays security decisions, or treats compliance as a tick-box exercise, that attitude quickly spreads throughout the organisation.
ISO27001 requires management to actively support and promote information security. This includes ensuring employees understand their responsibilities, follow established policies and procedures, and recognise the importance of protecting information.
Good leadership creates a culture where security becomes part of everyday business, rather than something people only think about during audits or after an incident.
Because when security is led from the top, it becomes everyone’s responsibility.
A5.5 Contact with Authorities
Who should I contact if my business suffers a cyber attack or data breach?
When a security incident occurs, confusion can be just as damaging as the incident itself.
Many organisations don’t think about regulators, law enforcement, industry bodies, or government agencies until they’re facing a crisis. By then, valuable time has already been lost.
ISO27001 requires organisations to establish and maintain appropriate contacts with relevant authorities. This ensures that when an incident occurs, the right people can be contacted quickly for advice, support, reporting, or regulatory compliance.
Depending on your organisation, this may include the Information Commissioner’s Office (ICO), law enforcement agencies, the National Cyber Security Centre (NCSC), sector regulators, or other relevant authorities.
Knowing who to contact before you need them can significantly reduce the impact of an incident and help you meet your legal and regulatory obligations.
Preparation beats panic every time.
A5.6 Contact with Special Interest Groups
How do I stay informed about cyber threats, security risks, and industry best practice?
Cyber security doesn’t stand still.
New threats emerge daily, regulations change, vulnerabilities are discovered, and attackers constantly adapt their tactics. Trying to keep up on your own can feel overwhelming, especially when you’re already busy running a business.
ISO27001 encourages organisations to maintain contact with relevant special interest groups, professional associations, industry forums, and security communities. These groups provide valuable insights, threat intelligence, practical guidance, and lessons learned from others facing similar challenges.
The goal isn’t to join every networking group or attend every conference. It’s about ensuring your organisation has access to reliable information that helps you make better security decisions and stay ahead of emerging risks.
Because you can’t protect against threats you don’t know exist.
Learning from others is often faster, cheaper, and far less painful than learning everything the hard way.
Click here to read the full article.
A5.7 Threat Intelligence
How do I keep up with emerging cyber threats?
Most organisations are so busy dealing with today’s problems that they rarely have time to think about tomorrow’s threats.
Unfortunately, cyber criminals don’t stand still.
New vulnerabilities are discovered every day. Attack techniques evolve. Ransomware groups change their tactics. Criminals look for new ways to exploit organisations that aren’t paying attention.
ISO27001 encourages organisations to gather and analyse information about relevant threats, vulnerabilities, and attack methods. This is known as threat intelligence.
That doesn’t mean you need a team of analysts monitoring the dark web. It means understanding which threats are most likely to affect your organisation and using reliable information to make informed security decisions.
Good threat intelligence helps you prioritise your efforts, reduce risk, and avoid spending money solving problems you don’t actually have.
Because security is much easier when you’re looking ahead rather than constantly looking back.
Click here for the full article.
A5.8 Information Security in Project Management
Should cyber security be considered when planning projects?
Many organisations only think about security after a project has been completed.
A new system is launched. A new supplier is onboarded. A new website goes live.
Then someone asks:
“Have we thought about security?”
By that point, fixing the problem is usually more expensive, more disruptive, and far more frustrating than addressing it from the start.
ISO27001 requires organisations to consider information security throughout the entire project lifecycle. Whether you’re implementing new software, moving to the cloud, launching a customer portal, or changing business processes, security should be built into the project—not bolted on afterwards.
Good project management considers risks early, identifies security requirements before decisions are made, and ensures information security remains part of planning, implementation, testing, and delivery.
Because it’s always easier to build security in than retrofit it later.
Click here for the full article.
A5.9 Inventory of Information and other associated assets
Do I actually know what information and assets my business owns?
You can’t protect what you don’t know you have.
Many organisations invest in cyber security tools, policies, and controls without first understanding what they’re trying to protect. Customer data, laptops, mobile phones, software licences, cloud services, intellectual property, contracts, and financial records all have value—but many businesses don’t have a complete picture of where these assets are, who owns them, or how they’re being used.
ISO27001 requires organisations to identify and maintain an inventory of information and other associated assets. This helps ensure important assets are properly managed, protected, and accounted for throughout their lifecycle.
An asset inventory isn’t just a spreadsheet for auditors. It’s a fundamental part of understanding your risks and making informed decisions about security.
Because if you don’t know what assets you have, how can you know whether they’re adequately protected?
A5.10 Acceptable Use of Information and Other Associated Assets
Can employees use company devices, systems, and information however they want?
Most employees aren’t trying to cause a security incident.
The problem is that without clear guidance, people will make their own decisions about how they use company laptops, mobile phones, email accounts, cloud services, and business information. Sometimes those decisions create unnecessary risks.
ISO27001 requires organisations to establish rules for the acceptable use of information and other associated assets. This helps employees understand what they can do, what they shouldn’t do, and how to use business resources safely and responsibly.
An Acceptable Use Policy isn’t about restricting people unnecessarily. It’s about protecting the organisation, its information, and the people who use it.
Whether it’s installing unauthorised software, sharing files through personal accounts, using weak passwords, or accessing inappropriate websites, clear expectations help reduce risk and avoid misunderstandings.
Because if you don’t define the rules, people will create their own.
A5.11 Return of Assets
What should happen when an employee, contractor, or supplier leaves the organisation?
People don’t always leave your business when they leave your payroll.
When an employee resigns, a contractor finishes a project, or a supplier relationship ends, organisations often focus on the handover of work. What can be overlooked is the return of company assets, information, and access.
Laptops, mobile phones, access cards, keys, documents, software licences, and company data all need to be accounted for. If they aren’t, the organisation could face security risks, data breaches, compliance issues, or the loss of valuable information.
ISO27001 requires organisations to have processes in place to ensure that information and other associated assets are returned when a working relationship ends or changes.
The objective is simple: make sure the organisation retains control of its assets and information, regardless of who comes and goes.
Because people leave. Your information shouldn’t leave with them.
A5.12 Classification of information
How do I know which information needs the most protection?
Not all information is equal.
Your lunch menu, marketing brochure, employee records, customer database, and merger plans don’t all carry the same level of risk. Yet many organisations treat all information the same—or worse, they don’t think about classification at all.
ISO27001 requires organisations to classify information according to its value, sensitivity, criticality, and legal or regulatory requirements. This helps ensure that information receives the appropriate level of protection based on the potential impact if it were lost, altered, or disclosed.
Without classification, employees are left to guess what is important and what isn’t. That can lead to over-protecting low-risk information, under-protecting sensitive data, or creating unnecessary complexity.
A good classification scheme helps people make better decisions about how information should be stored, shared, protected, and disposed of.
Because if everything is labelled as important, then nothing is.
A5.13 Labelling of information
Should sensitive information be clearly marked and labelled?
Imagine finding a document on a desk, in an email, or on a shared drive.
Would you know whether it was public information, internal information, commercially sensitive, or confidential?
If not, how would you know how carefully it should be handled?
ISO27001 requires organisations to develop and implement procedures for labelling information in accordance with their information classification scheme. The purpose is to help people quickly recognise the sensitivity and importance of information so they can handle it appropriately.
Labelling doesn’t have to be complicated. In fact, the simpler it is, the more likely people are to use it consistently. Whether it’s a document marked “Confidential”, a folder labelled “Internal Use Only”, or an email containing sensitive data, clear labelling helps reduce mistakes and improves awareness.
Because people can’t be expected to protect information if they don’t know it’s sensitive.
Good labelling turns classification into action.
A5.14 Information transfer
Is it safe to send sensitive information by email?
Most information doesn’t stay in one place.
Every day, organisations share information with employees, customers, suppliers, partners, and third parties. Emails are sent. Files are uploaded. Documents are downloaded. Data moves between systems, devices, and people.
The challenge is that information is often at its most vulnerable when it’s being transferred.
ISO27001 requires organisations to establish rules, procedures, and controls to protect information whenever it is shared, transmitted, or exchanged. This applies whether information is sent electronically, physically, internally, or externally.
Without clear controls, information can be sent to the wrong person, intercepted during transmission, altered without authorisation, or exposed to people who shouldn’t have access to it.
The objective isn’t to stop people sharing information.
It’s to make sure they can do so safely.
Because information doesn’t lose its value simply because it leaves your network.
A5.15 Access Control
Who should have access to sensitive information?
One of the simplest ways to reduce risk is to ensure people only have access to the information they genuinely need to do their job.
Unfortunately, many organisations take the opposite approach.
Over time, employees accumulate permissions, shared folders become accessible to everyone, and nobody is quite sure who has access to what. The result is unnecessary risk, increased exposure to cyber attacks, and a greater chance of accidental or deliberate misuse of information.
ISO27001 requires organisations to establish and implement access control rules that ensure access to information and systems is granted based on business needs. This is often referred to as the principle of least privilegegiving people the minimum level of access necessary to perform their role.
Access control isn’t about stopping people from doing their jobs.
It’s about protecting information from being accessed, altered, or disclosed by people who shouldn’t have access to it.
Because the fewer people who can access sensitive information, the lower the risk of something going wrong.
Click here to read the full article.
A5.16 Identity Management
How do I control who can access my systems and information?
Before you can decide what someone should have access to, you first need to know who they are.
It sounds obvious, but many organisations struggle with identity management. Employees change roles, contractors come and go, suppliers need temporary access, and old accounts are often forgotten. Over time, this creates confusion, unnecessary risk, and opportunities for attackers to exploit weaknesses.
ISO27001 requires organisations to manage identities throughout their lifecycle. This includes creating, modifying, reviewing, and removing identities so that access to systems and information remains appropriate and controlled.
Identity management applies to employees, contractors, suppliers, service accounts, and anyone else who interacts with your systems. The goal is to ensure that every account can be linked to a legitimate user or purpose, and that access is reviewed whenever circumstances change.
Because if you don’t know who an account belongs to, you can’t be confident it’s being used appropriately.
Good identity management is the foundation upon which access control is built.
A5.17 Authentication Information
What makes a strong password policy—and is a password alone still enough?
Passwords remain one of the most common ways people access systems, applications, and data. Unfortunately, they’re also one of the most common ways attackers gain access.
Weak passwords, shared accounts, reused credentials, and poor password management practices continue to be responsible for countless security incidents every year. The problem isn’t that passwords are bad—it’s that people often use them badly.
ISO27001 requires organisations to establish and implement appropriate controls for the allocation, management, and protection of authentication information. This includes passwords, passphrases, PINs, security tokens, authentication apps, and other credentials used to verify identity.
The goal is to ensure authentication information is created, stored, shared, and managed securely throughout its lifecycle.
Good authentication practices help prevent unauthorised access, reduce the likelihood of compromised accounts, and improve overall security.
Because if an attacker can pretend to be you, many other security controls become irrelevant.
A5.18 Access Rights
How often should user access permissions be reviewed?
Granting access is easy.
The difficult part is making sure people still need that access six months, twelve months, or two years later.
As organisations grow and change, employees move roles, responsibilities evolve, contractors come and go, and systems are added or removed. Unfortunately, access rights often accumulate over time, resulting in people having far more access than they actually need.
ISO27001 requires organisations to manage and regularly review access rights to ensure they remain appropriate and aligned with business requirements.
The objective is simple: people should have access to what they need today—not what they needed three jobs ago.
Regular reviews help identify excessive permissions, unnecessary access, dormant accounts, and potential security risks before they become incidents.
Because every unnecessary permission increases your attack surface.
A5.19 Information security in supplier relationships
Could my suppliers be my biggest cyber security risk?
Most organisations spend a lot of time thinking about their own security.
Far fewer think about the security of the organisations they depend on.
Suppliers often have access to your systems, data, premises, employees, or customers. They may process personal data on your behalf, provide critical services, or support essential business operations. If they suffer a security incident, there’s a good chance you’ll feel the impact too.
ISO27001 requires organisations to identify and manage information security risks associated with supplier relationships. This means understanding who your suppliers are, what access they have, what risks they introduce, and what controls are needed to protect your information.
The objective isn’t to eliminate risk.
It’s to understand it and manage it appropriately.
Because your security is only as strong as the weakest link in your supply chain.
A5.20 Addressing Information Security Within Supplier Agreements
What cyber security requirements should I include in supplier contracts?
Many organisations carefully select suppliers, carry out due diligence, and assess risks before signing a contract.
Then they forget to document their security expectations.
The problem is that when information security requirements aren’t clearly defined, misunderstandings occur. Suppliers may assume they can handle information one way, while you expect something entirely different. Unfortunately, these assumptions often come to light only after an incident has occurred.
ISO27001 requires organisations to establish and agree appropriate information security requirements with suppliers. These requirements should reflect the level of risk, the type of service being provided, and the information being shared.
This might include requirements for access control, data protection, incident reporting, business continuity, confidentiality, encryption, employee screening, or compliance with specific standards and regulations.
The objective is simple: make sure both parties understand their security responsibilities before problems arise.
Because a contract isn’t just about defining what a supplier will do.
It’s also about defining how they’ll protect what you’ve entrusted to them.
A5.21 Managing Information Security in the ICT supply chain
How do I know the technology and services I buy are secure?
Most organisations rely on a complex network of suppliers, software providers, cloud services, managed service providers, and technology partners.
The challenge is that every product, service, and supplier you introduce into your organisation becomes part of your ICT supply chain—and potentially part of your risk profile.
A vulnerability in a software update, a compromised supplier, or a weakness in a third-party service can quickly become your problem, even if your own systems are well protected.
ISO27001 requires organisations to manage information security risks throughout the ICT supply chain. This means understanding where technology products and services come from, assessing the risks they introduce, and ensuring appropriate security measures are in place throughout the relationship.
The goal isn’t to eliminate suppliers.
It’s to understand the risks that come with them.
Because modern organisations don’t operate in isolation. They operate as part of an interconnected ecosystem.
And attackers know it.
A5.22 Monitoring, Review and Change Management of Supplier Services
How do I know my suppliers remain secure after I’ve hired them?
Many organisations carry out supplier checks before signing a contract.
Then they never look again.
The problem is that supplier risks don’t stand still. Businesses change. Services evolve. Staff come and go. New technologies are introduced. Suppliers may be acquired, outsource parts of their service, or suffer security incidents that affect their ability to protect your information.
ISO27001 requires organisations to monitor, review, and manage changes to supplier services throughout the relationship. This means regularly assessing whether suppliers continue to meet your security expectations and understanding how changes might affect your organisation.
The objective isn’t to create unnecessary oversight.
It’s to ensure that the security arrangements you agreed at the start of the relationship remain effective over time.
Because supplier security isn’t a one-time assessment.
It’s an ongoing responsibility.
A5.23 Information Security for Use of Cloud Services
Is my cloud provider secure enough for my business?
Cloud services have transformed the way organisations work.
From Microsoft 365 and Google Workspace to cloud backups, CRM systems, and file-sharing platforms, businesses are increasingly relying on cloud services to store, process, and manage their information.
The challenge is that many organisations assume that moving to the cloud means security is someone else’s responsibility.
It isn’t.
ISO27001 requires organisations to establish processes for the acquisition, use, management, and exit from cloud services. This means understanding what information is stored in the cloud, who has access to it, what security controls are in place, and what risks need to be managed.
While cloud providers are responsible for securing their infrastructure, you remain responsible for how your organisation uses their services.
The objective is to ensure cloud services support your business without introducing unnecessary risks.
Because moving information to the cloud doesn’t remove your responsibilities. It changes them.
A.5.24 Information Security Incident Management Planning and Preparation
What should I do if my business suffers a cyber attack or data breach?
Most organisations spend a lot of time trying to prevent incidents.
Far fewer spend time preparing for them.
The reality is that no organisation is immune to cyber attacks, data breaches, human error, system failures, or security incidents. The question isn’t whether an incident is possible. The question is whether you’re prepared when one happens.
ISO27001 requires organisations to establish and maintain processes for planning and preparing for information security incidents. This includes defining responsibilities, escalation routes, communication procedures, reporting mechanisms, and response activities before an incident occurs.
The objective is simple: when something goes wrong, people should know what to do.
Without planning, incidents often lead to confusion, delays, poor decision-making, and increased impact. With preparation, organisations can respond more effectively, reduce disruption, and recover more quickly.
Because when the pressure is on, nobody wants to be making up the plan as they go along.
A5.25 Assessment and Decision on Information Security Events
How do I know whether a security event is actually a security incident?
Not every unusual event is a cyber attack.
Employees mistype passwords. Systems generate alerts. Emails get flagged as suspicious. Software crashes. Files go missing. Every day, organisations experience events that may or may not indicate a security problem.
The challenge is knowing which events need attention and which can be safely ignored.
ISO27001 requires organisations to assess information security events and determine whether they should be classified as information security incidents. This helps ensure genuine threats are identified quickly, escalated appropriately, and handled effectively.
Without a structured assessment process, organisations can end up chasing false alarms while missing the events that really matter. Equally, treating every event as a major incident can overwhelm resources and create unnecessary disruption.
The objective is to make informed decisions based on evidence, risk, and impact.
Because not every event is an incident—but every incident starts as an event.
A5.26 Response to information security incidents
What should we do when a cyber security incident actually happens?
Discovering a security incident is only the beginning.
Once an incident has been identified, organisations need to act quickly, consistently, and effectively to minimise the impact on the business, its customers, and its reputation.
Unfortunately, many organisations don’t realise how important those first few hours can be. Delays, confusion, poor communication, or rushed decisions can often cause more damage than the incident itself.
ISO27001 requires organisations to establish procedures for responding to information security incidents. This includes containing the incident, assessing the impact, preserving evidence, communicating with relevant parties, and taking appropriate action to restore normal operations.
The objective isn’t to eliminate every problem immediately.
It’s to respond in a structured way that reduces harm, supports recovery, and helps the organisation make informed decisions under pressure.
Because when an incident occurs, people don’t rise to the occasion.
They fall back on their preparation.
A5.27 Learning from Information Security Incidents
How can we stop the same security incident happening again?
Once an incident has been resolved, many organisations breathe a sigh of relief and move on.
The problem is that if you don’t understand why the incident happened, there’s a good chance you’ll experience it again.
Whether it’s a phishing attack, a data breach, accidental disclosure, system failure, or human error, every incident contains valuable lessons. The organisations that improve their security posture aren’t necessarily the ones that avoid incidents altogether—they’re the ones that learn from them.
ISO27001 requires organisations to analyse information security incidents, identify lessons learned, and make improvements where necessary. This helps prevent similar incidents from occurring in the future and supports the continual improvement of the Information Security Management System (ISMS).
The objective isn’t to assign blame.
It’s to understand what happened, why it happened, and what can be done differently next time.
Because every incident is either a lesson learned or a lesson wasted.
A5.28 Collection of Evidence
How do I investigate a cyber incident without destroying the evidence?
When a security incident occurs, the natural instinct is to fix the problem as quickly as possible.
Unfortunately, that can sometimes destroy the very evidence needed to understand what happened.
Logs get deleted. Devices are wiped. Systems are restarted. Emails disappear. Before long, the information needed to investigate the incident, identify the root cause, or support legal action is gone.
ISO27001 requires organisations to establish procedures for identifying, collecting, preserving, and handling evidence relating to information security incidents.
This is particularly important where incidents may lead to legal action, regulatory investigations, disciplinary proceedings, insurance claims, or criminal investigations.
The objective isn’t to turn every organisation into a digital forensics team.
It’s to ensure that potentially important evidence is recognised, protected, and handled appropriately when an incident occurs.
Because once evidence is lost, it’s often impossible to get it back.
A5.29 Information Security During Disruption
How do we protect information when things go wrong?
Most organisations focus on information security during normal business operations.
The real test comes when things aren’t normal.
A cyber attack, power outage, flood, fire, supplier failure, pandemic, or major system outage can place enormous pressure on an organisation. During these moments, people are often focused on restoring services and keeping the business running. Unfortunately, security controls can be forgotten, bypassed, or weakened in the process.
ISO27001 requires organisations to ensure that information security is maintained during periods of disruption. This means considering how critical information, systems, and services will remain protected even when normal operations are unavailable or significantly affected.
The objective isn’t simply to recover quickly.
It’s to recover securely.
Because a disruption should not become an excuse to compromise the confidentiality, integrity, or availability of information.
A5.30 ICT Readiness for Business Continuity
Could my business continue operating if our IT systems failed tomorrow?
Most organisations rely heavily on technology.
Email, cloud services, customer databases, accounting systems, telephony, websites, and business applications have become so embedded in daily operations that many organisations simply couldn’t function without them.
The question is:
What happens if they’re unavailable?
Whether caused by a cyber attack, hardware failure, software issue, supplier outage, human error, or natural disaster, the loss of critical ICT services can bring a business to a standstill.
ISO27001 requires organisations to ensure that information and communication technology (ICT) services can support business continuity requirements. This means identifying critical systems, understanding recovery requirements, implementing appropriate resilience measures, and ensuring technology can be restored within acceptable timescales.
The objective isn’t to prevent every outage.
It’s to ensure the business can continue operating, recover quickly, and minimise disruption when technology fails.
Because it’s not a question of if something will go wrong.
It’s a question of how prepared you’ll be when it does.
A5.31 Legal, Statutory, Regulatory and Contractual Requirements
How do I know which laws, regulations, and contractual obligations apply to my business?
One of the biggest risks facing organisations isn’t what they know.
It’s what they don’t know.
Most businesses are aware of GDPR, but information security obligations rarely stop there. Depending on your industry, customers, suppliers, location, and services, you may also need to comply with sector regulations, contractual requirements, industry standards, intellectual property laws, employment legislation, and a host of other legal obligations.
ISO27001 requires organisations to identify, document, and keep up to date with the legal, statutory, regulatory, and contractual requirements that relate to information security.
The objective is to ensure that security controls aren’t implemented in isolation, but are aligned with the obligations your organisation is expected to meet.
Because compliance isn’t just about avoiding fines.
It’s about protecting your reputation, maintaining customer trust, and demonstrating that your organisation takes its responsibilities seriously.
A5.32 Intellectual Property Rights
How do I protect my intellectual property—and avoid infringing someone else’s?
Many organisations think of information security as protecting customer data, financial information, or IT systems.
But what about the information that gives your business its competitive advantage?
Your brand, training materials, software, designs, reports, methodologies, research, content, and innovations may all be valuable intellectual property. Equally, your organisation may use intellectual property owned by others, such as software, images, documents, music, trademarks, or licensed content.
ISO27001 requires organisations to implement appropriate procedures to protect intellectual property rights (IPR) and ensure compliance with legal, regulatory, and contractual obligations relating to intellectual property.
The objective is twofold: protect your own intellectual assets and avoid the legal, financial, and reputational consequences of misusing someone else’s.
Because information has value.
And sometimes that value is protected by law.
A5.33 Protection of records
How do I protect important business records and prove they’re trustworthy?
Every organisation relies on records.
Contracts, invoices, employee records, customer information, audit reports, meeting minutes, training records, financial data, and compliance evidence all help demonstrate what happened, when it happened, and who was involved.
The challenge is that records only have value if they remain accurate, complete, accessible, and trustworthy.
ISO27001 requires organisations to protect records from loss, unauthorised access, alteration, destruction, and misuse. This includes ensuring records are retained for the appropriate period, stored securely, and remain available when needed for legal, regulatory, contractual, or operational purposes.
The objective isn’t simply to keep records.
It’s to ensure those records can be trusted.
Because when a customer, regulator, auditor, insurer, or court asks for evidence, you need confidence that your records are accurate and complete.
After all, if you can’t prove it happened, proving compliance becomes much harder.
A5.34 Privacy and Protection of Personally Identifiable Information (PII)
How do I protect personal data and comply with GDPR?
Almost every organisation processes personal information.
Customer records, employee data, supplier contacts, marketing databases, website enquiries, and email addresses are all examples of Personally Identifiable Information (PII). The challenge is that collecting personal data creates responsibilities.
People trust organisations with their information. Regulators expect it to be protected. And when things go wrong, the consequences can include financial penalties, reputational damage, and loss of customer confidence.
ISO27001 requires organisations to identify and implement measures that protect Personally Identifiable Information in accordance with applicable laws, regulations, and contractual obligations.
For most UK organisations, this means ensuring compliance with the UK GDPR and the Data Protection Act 2018, whilst also implementing appropriate technical and organisational security controls.
The objective isn’t simply to avoid fines.
It’s to demonstrate respect for the information people have entrusted to you.
Because personal data doesn’t belong to your organisation.
It belongs to the individual.
A5.35 Independent Review of Information Security
How do I know if our information security is actually working?
It’s easy to assume everything is under control.
Policies have been written. Training has been delivered. Security controls have been implemented. Audits have been completed.
But how do you know they’re actually effective?
One of the biggest challenges organisations face is becoming too close to their own processes. When you’re involved in something every day, it’s easy to miss weaknesses, gaps, or opportunities for improvement.
ISO27001 requires organisations to carry out independent reviews of their approach to information security. The purpose is to obtain an objective assessment of whether security controls, processes, and governance arrangements are operating as intended.
This doesn’t always require an external consultant. Independence can often be achieved through internal audits, peer reviews, or assessments performed by individuals who are not directly responsible for the area being reviewed.
The objective is simple: provide assurance that information security remains effective, relevant, and aligned with business needs.
Because if nobody checks whether something is working, how can you be confident that it is?
A5.36 Compliance with Policies, Rules and Standards for Information Security
How do I know people are actually following our security policies?
Creating policies is relatively easy.
Getting people to follow them is where the real challenge begins.
Many organisations invest significant time developing information security policies, procedures, standards, and guidelines. They publish them, communicate them, and perhaps even provide training. Then they assume everyone is following them.
Unfortunately, assumptions are not evidence.
ISO27001 requires organisations to regularly review compliance with their information security policies, rules, and standards. The purpose is to verify that controls are operating as intended and that employees, contractors, and third parties are following the requirements that have been established.
The objective isn’t to catch people out.
It’s to identify gaps, improve behaviours, and ensure that policies are delivering the outcomes they were designed to achieve.
Because a policy that nobody follows offers very little protection.
Security isn’t measured by what’s written down.
It’s measured by what people actually do.
A5.37 Documented Operating Procedures
How do I make sure important tasks are carried out consistently and correctly?
Most organisations have processes that are critical to their success.
Creating user accounts. Processing customer information. Applying security updates. Backing up data. Responding to incidents. Managing suppliers.
The problem is that many of these activities exist only in people’s heads.
Everything works well until someone is on holiday, leaves the organisation, or simply forgets an important step.
ISO27001 requires organisations to document operating procedures where necessary to ensure activities are performed consistently, securely, and effectively.
The objective isn’t to create endless documentation.
It’s to provide clear guidance so that important tasks can be carried out correctly, regardless of who performs them.
Good procedures help reduce mistakes, improve consistency, support training, and make it easier to demonstrate compliance.
Because if a process is important to your business, it shouldn’t rely entirely on memory.
People Controls
A6.1 Screening
How do I know if I’m hiring people I can trust with my business, systems, and customer data?
A6.1 Screening requires organisations to carry out appropriate background checks on employees, contractors, and relevant third parties before granting them access to information, systems, information assets, or sensitive data.
The level of screening should be proportionate to the role, responsibilities, and associated risks. The objective is to reduce the likelihood of fraud, misuse of information, insider threats, or reputational damage by ensuring individuals are suitable for the positions they hold.
This isn’t about creating unnecessary bureaucracy.
It’s about applying sensible checks before trust is granted.
A6.2 Terms and Conditions of Employment
How do I make sure employees understand their security responsibilities from day one?
A6.2 requires organisations to ensure that employees, contractors, and relevant personnel understand their information security responsibilities as part of their employment or engagement.
These responsibilities should be clearly communicated and documented before access to information, systems, or assets is granted.
Typically, this is achieved through employment contracts, confidentiality agreements, acceptable use policies, staff handbooks, and onboarding processes.
The objective is simple:
People should know what is expected of them before they are trusted with company information.
This includes understanding their obligations to protect information, follow policies, handle data appropriately, and maintain confidentiality during and after their employment
A6.3 - Information Security Awareness, Eduction and Training
How do I ensure my people understand security risks and know how to protect the business?
A6.3 requires organisations to provide appropriate information security awareness, education, and training to employees and relevant interested parties.
The important word here is appropriate.
Different people have different responsibilities, different risks, and different levels of access. Therefore, training should reflect the role they perform and the information they handle.
The control specifically recognises three distinct but connected activities:
- Awareness
- Education
- Training
Awareness helps people recognise risks.
Education helps people understand why those risks matter.
Training gives people the skills needed to respond appropriately.
The objective is simple:
Ensure people understand their role in protecting information and are equipped to do so effectively.
Because information security isn’t just an IT issue.
It’s a people issue.
Click here to read the full article.
A6.4 - Disciplinary Process
What should happen if an employee deliberately or repeatedly ignores our security policies?
A6.4 requires organisations to establish and communicate a disciplinary process for addressing information security policy violations.
The purpose isn’t punishment.
The purpose is accountability.
Employees, contractors, and relevant personnel need to understand that information security responsibilities are important and that there are consequences when policies, procedures, or security requirements are deliberately ignored or repeatedly breached.
This control helps reinforce the message that information security is everyone’s responsibility.
The disciplinary process should be fair, proportionate, documented, and aligned with existing HR processes and employment obligations.
The objective is simple:
People need to understand both their security responsibilities and the consequences of failing to meet them
Click here to read the full article.
A6.5 Responsibilities After Termination or Change of Employment
What should happen to access, devices, and information when an employee leaves or changes role?
A6.5 requires organisations to define and manage information security responsibilities when employment, contracts, or roles change or come to an end.
The control recognises a simple reality:
Just because someone leaves the organisation doesn’t mean the risks leave with them.
Employees, contractors, consultants, and temporary staff may still possess knowledge, access credentials, devices, confidential information, customer data, intellectual property, or commercially sensitive information.
Organisations need a structured process to ensure these risks are appropriately managed when someone:
- Leaves the organisation
- Changes department
- Is promoted
- Takes on new responsibilities
- Finishes a contract
- Moves to a third-party supplier
The objective is simple:
Ensure access, responsibilities, and obligations are updated or removed when circumstances change.
A6.6 Confidentiality or Non-Disclosure Agreements
How do I protect sensitive business information when employees, contractors, or suppliers have access to it?
A6.6 requires organisations to identify, document, and manage confidentiality obligations that apply to employees, contractors, suppliers, and other relevant parties who have access to sensitive information.
In simple terms:
People should understand what information they are expected to protect, and what happens if they disclose it without authorisation.
For many organisations, this is achieved through confidentiality clauses in employment contracts, Non-Disclosure Agreements (NDAs), supplier agreements, consultancy contracts, or customer agreements.
The control isn’t about creating distrust.
It’s about setting clear expectations.
People need to know:
- What information is confidential
- How it should be handled
- Who it can be shared with
- What obligations continue after employment or contracts end
The objective is simple:
Protect the organisation’s information by ensuring confidentiality expectations are clearly understood and legally enforceable where appropriate.
A6.7 Remote Working
How do I keep information secure when employees work from home, on the road, or outside the office?
A6.7 requires organisations to establish and implement security measures that protect information when people work remotely.
The reality is that work no longer happens exclusively in the office.
People work from:
- Home offices
- Kitchen tables
- Hotels
- Coffee shops
- Client sites
- Airports
- Shared workspaces
While remote working creates flexibility and productivity benefits, it also introduces additional security risks.
For example:
- Unauthorised people viewing sensitive information
- Lost or stolen devices
- Unsecured Wi-Fi networks
- Family members accessing company equipment
- Poor document handling practices
- Increased phishing and social engineering risks
The objective is simple:
Ensure information remains protected regardless of where people are working.
Because information security shouldn’t stop when someone leaves the office.
A6.8 Information Security Event Reporting
How do I make sure employees report security issues before they become serious incidents?
A6.8 requires organisations to ensure that employees, contractors, and relevant personnel can recognise and report information security events promptly through appropriate reporting channels.
The emphasis here is on events, not incidents.
An event is something unusual that may indicate a security issue.
For example:
- A suspicious email
- A lost laptop
- An unexpected system alert
- Someone accessing information they shouldn’t
- A device behaving strangely
- An accidental disclosure of information
Not every event becomes an incident.
But every incident starts with an event.
The objective is simple:
Create a culture where people recognise potential security issues and know how to report them quickly.
Because the sooner you know about a problem, the sooner you can respond.
Physical Controls
A7.1 Physical Security Perimeters
How do I stop unauthorised people gaining physical access to my offices, facilities, and sensitive information?
A7.1 requires organisations to define and implement physical security perimeters that protect information, information assets, and supporting facilities from unauthorised physical access.
In simple terms:
You need to know where your sensitive areas are and control who can enter them.
This doesn’t mean every organisation needs fences, guards, and biometric scanners.
The controls should be proportionate to the risks you face.
For some organisations, this might mean:
- Locked office doors
- Reception controls
- Visitor sign-in procedures
- Access control systems
- Secure server rooms
- Restricted access areas
- CCTV monitoring
The objective is simple:
Prevent unauthorised people from gaining physical access to information, systems, equipment, and facilities.
Because information security isn’t just about protecting data online.
Sometimes the easiest way to access information is simply walking through an unlocked door.
Click here to read the full article
A7.2 Physical Entry Controls
How do I control who enters my premises and prevent unauthorised access to sensitive areas?
A7.2 requires organisations to implement physical entry controls that ensure only authorised individuals can access buildings, rooms, and areas where information and information assets are located.
While A7.1 focuses on defining the perimeter, A7.2 focuses on controlling who can cross it.
In simple terms:
Just because someone reaches your building doesn’t mean they should be able to access everything inside it.
Physical entry controls might include:
- Reception processes
- Visitor sign-in procedures
- Access cards or fobs
- PIN codes
- Keys
- Security guards
- Biometric controls
- Visitor badges
- Staff identification badges
The objective is simple:
Ensure only authorised people can access areas containing sensitive information, systems, equipment, or services.
Because good security isn’t just about keeping the wrong people out.
It’s about ensuring the right people only access the areas they genuinely need.
A7.3 Securing Offices, Rooms and Facilities
How do I protect sensitive information and assets within my offices, rooms, and facilities?
A7.3 requires organisations to secure offices, rooms, and facilities where information is processed, stored, or managed.
While A7.1 focuses on defining physical security boundaries, and A7.2 focuses on controlling entry, A7.3 focuses on protecting the environments where business activities actually take place.
In simple terms:
Once someone is inside the building, how are you protecting the information, equipment, and services inside it?
This could include:
- Securing offices containing confidential information
- Restricting access to server rooms
- Protecting meeting rooms used for sensitive discussions
- Preventing unauthorised viewing of information
- Ensuring confidential conversations cannot be overheard
- Protecting facilities from environmental risks
- Managing physical security during out-of-hours periods
The objective is simple:
Ensure information and information assets remain protected within the workplace environment.
Because physical security doesn’t stop at the front door.
A7.4 Physical Security Monitoring
How do I know if someone has accessed my premises, secure areas, or assets without authorisation?
A7.4 requires organisations to monitor physical premises for unauthorised access and suspicious activity.
The goal isn’t to spy on employees.
The goal is to provide visibility, deterrence, and evidence when physical security events occur.
In simple terms:
If someone enters an area they shouldn’t, how would you know?
Physical security monitoring may include:
- CCTV systems
- Security alarms
- Access control logs
- Visitor records
- Security patrols
- Reception monitoring
- Building management systems
The level of monitoring should reflect the risks faced by the organisation.
A small office may require very different controls to a data centre, manufacturing facility, or organisation handling highly sensitive information.
The objective is simple:
Detect, deter, and investigate unauthorised physical access or suspicious activity.
Because you cannot respond to risks you cannot see.
A7.5 Protecting Against Physical and Environmental Threats
How do I protect my business from fire, flooding, power failures, theft, and other physical threats?
A7.5 requires organisations to identify and protect against physical and environmental threats that could impact information, information assets, and supporting facilities.
When most people think about information security, they think about hackers.
ISO27001 takes a broader view.
Because sometimes your biggest threat isn’t a cyber attack.
It’s a burst pipe, a fire, a power outage, a leaking roof, extreme weather, theft, vandalism or simply equipment failing at the worst possible moment.
This control requires organisations to consider what could physically affect their ability to operate and take reasonable steps to reduce the likelihood or impact of those events.
Examples might include:
- Fire detection and suppression systems
- Flood protection measures
- Environmental monitoring
- Backup power supplies
- Equipment protection
- Building security controls
- Disaster recovery arrangements
- Business continuity planning
The objective is simple:
Protect information and information assets from physical events that could damage, destroy, disrupt, or compromise them.
Because information security isn’t just about protecting data.
It’s about protecting the environment that supports it.
A7.6 Working in secure areas
How do I ensure people working in sensitive areas don’t accidentally expose information or create security risks?
A7.6 requires organisations to establish and implement procedures for working in secure areas.
A secure area is any location where sensitive information, critical systems, or important business assets are processed, stored, or managed.
This could include:
- Server rooms
- Data centres
- Records storage areas
- Security operations centres
- Research and development facilities
- Archive rooms
- Areas containing confidential information
The purpose of this control is not simply to control who enters these areas.
That’s covered elsewhere.
This control focuses on how people behave once they’re inside.
The objective is simple:
Ensure activities carried out in secure areas do not introduce unnecessary risks to information, systems, or assets.
Because physical access is only part of the challenge.
What people do once they have access matters just as much.
A7.7 Clear Desk and Clear Screen
How do I stop sensitive information being exposed when nobody is actively using it?
A7.7 requires organisations to implement clear desk and clear screen practices to reduce the risk of unauthorised access, disclosure, loss, or compromise of information.
The principle is simple:
If you’re not using it, secure it.
This applies to both physical and digital information.
A clear desk approach may include:
- Locking away confidential documents
- Removing sensitive paperwork from desks
- Securing portable media
- Locking filing cabinets
- Shredding documents when no longer required
A clear screen approach may include:
- Locking screens when unattended
- Using automatic screen locks
- Preventing unauthorised viewing of information
- Logging out of systems when not in use
The objective is simple:
Reduce the likelihood of sensitive information being viewed, stolen, lost, or misused when employees are away from their workspace.
Because information doesn’t become less sensitive simply because you’ve gone for a coffee.
A7.8 Equipment Siting and Protection
How do I protect computers, servers, and other equipment from damage, theft, disruption, or unauthorised access?
A7.8 requires organisations to position and protect equipment in a way that reduces risks from physical threats, environmental hazards, unauthorised access, and accidental damage.
In simple terms:
Where your equipment is located matters.
You could have the best cyber security controls in the world, but if your server is sitting next to a leaking pipe or your laptop is visible through a ground-floor window, you’re creating unnecessary risk.
This control requires organisations to think about:
- Physical location of equipment
- Environmental risks
- Access restrictions
- Theft prevention
- Accidental damage
- Visibility of sensitive equipment
- Protection from power, heat, water, dust, and other hazards
The objective is simple:
Ensure equipment is located and protected appropriately so it can continue to support the business securely and reliably.
Because equipment can’t protect information if the equipment itself isn’t protected.
A7.9 Security of Assets Off-Premises
How do I protect company laptops, phones, documents, and information when they’re taken outside the office?
A7.9 requires organisations to protect information assets when they are used, stored, or transported outside the organisation’s premises.
In today’s world, assets rarely stay in one place.
- Laptops travel.
- Mobile phones travel.
- Documents travel.
- USB devices travel.
- Employees work remotely.
- Sales teams visit customers.
- Engineers work on-site.
- Executives travel internationally.
This creates additional risks that don’t exist within the controlled environment of an office.
For example:
- Theft
- Loss
- Damage
- Unauthorised access
- Eavesdropping
- Information disclosure
- Accidental exposure
The objective is simple:
Ensure information and assets remain protected regardless of where they are physically located.
Because information security shouldn’t end when someone walks out of the building
A7.10 Storage Media
How do I protect USB drives, hard drives, documents, and other storage media from loss, theft, or unauthorised access?
A7.10 requires organisations to manage and protect storage media throughout its lifecycle.
Storage media includes anything used to store information, whether physically or electronically.
Examples include:
- USB drives
- External hard drives
- Backup tapes
- CDs and DVDs
- Memory cards
- Printed documents
- Portable storage devices
- Archived records
The control requires organisations to think about how storage media is:
- Used
- Stored
- Transported
- Shared
- Reused
- Disposed of
The objective is simple:
Prevent information stored on media from being lost, stolen, altered, disclosed, or accessed by unauthorised individuals.
Because information doesn’t just live on servers and cloud platforms.
It often exists on devices that can fit in a pocket.
A7.11 Supporting Utilities
How do I ensure power, water, cooling, and other essential services don’t disrupt my business or compromise information security?
A7.11 requires organisations to protect information processing facilities from failures or disruptions to supporting utilities.
Supporting utilities are the services that keep your business operating, even though most people rarely think about them.
Examples include:
- Electricity
- Water
- Gas
- Air conditioning
- Heating
- Ventilation
- Telecommunications
- Internet connectivity
The reality is simple:
Your information systems depend on more than technology.
A server may be secure.
A network may be resilient.
Your cyber security controls may be excellent.
But if the power fails, the cooling stops working, or your internet connection disappears, your business could still grind to a halt.
The objective is simple:
Protect information and information processing facilities from utility failures that could affect availability, integrity, or security.
Because resilience starts long before an incident occurs.
A7.12 Cabling Security
How do I protect network and power cables from damage, tampering, or unauthorised access?
A7.12 requires organisations to protect cables that carry information or support information processing facilities from interception, interference, damage, or unauthorised access.
At first glance, this might seem like a control aimed only at large data centres or complex IT environments.
It isn’t.
The principle is simple:
If someone can access, damage, disconnect, or interfere with your cabling, they may be able to disrupt your business or compromise your information.
This applies to:
- Network cables
- Fibre connections
- Power cables
- Telecommunications cabling
- Data centre connections
- Office infrastructure cabling
The control expects organisations to consider risks such as:
- Accidental damage
- Deliberate tampering
- Interception of data
- Unauthorised connections
- Service disruption
- Environmental damage
The objective is simple:
Protect the infrastructure that information systems rely upon.
Because even the most secure system becomes unavailable if someone unplugs it.
A7.13 Equipment Maintenance
How do I maintain computers, servers, and other equipment without creating security risks or business disruption?
A7.13 requires organisations to ensure that equipment is maintained correctly so that it remains available, reliable, and secure throughout its lifecycle.
Most organisations understand the importance of maintaining vehicles, machinery, and buildings.
Yet IT equipment is often overlooked until something breaks.
This control recognises that information security depends on equipment functioning as intended.
Maintenance activities may include:
- Routine servicing
- Repairs
- Firmware updates
- Hardware replacement
- Manufacturer maintenance
- Third-party support activities
- Preventative maintenance schedules
The objective is simple:
Ensure equipment continues to operate securely and reliably while reducing the risk of failures, downtime, or security weaknesses.
Because equipment that isn’t maintained eventually becomes equipment that fails.
And failed equipment often creates business risks.
A7.14 Secure Disposal or Re-Use of Equipment
How do I safely dispose of or re-use computers, laptops, phones, and storage devices without exposing sensitive information?
A7.14 requires organisations to ensure that information stored on equipment is removed, destroyed, or securely overwritten before the equipment is disposed of, recycled, sold, returned, or re-used.
The reason is simple:
Deleting a file doesn’t necessarily delete the information.
Many organisations replace equipment regularly:
- Laptops
- Desktop computers
- Mobile phones
- Tablets
- Servers
- Printers
- Storage devices
- USB drives
The danger comes when organisations focus on the value of the equipment and forget about the value of the information stored on it.
This control requires organisations to consider:
- What information is stored on the device?
- Has the information been securely removed?
- Can the information be recovered?
- Who will have access to the equipment next?
- Is disposal being handled securely?
The objective is simple:
Prevent sensitive information from being exposed when equipment reaches the end of its useful life or changes ownership.
Because the data stored on a device is often worth far more than the device itself.
Technical Controls
A8.1 User Endpoint Devices
How do I secure laptops, desktops, mobile phones, and tablets that employees use every day?
A8.1 requires organisations to protect information stored, processed, or accessed on user endpoint devices.
An endpoint device is any device used by an individual to access organisational information and systems.
Examples include:
- Laptops
- Desktop computers
- Mobile phones
- Tablets
- Thin clients
- Workstations
These devices represent one of the biggest security risks faced by organisations because they sit at the intersection between people and information.
Think about it.
A laptop may contain:
- Customer information
- Financial records
- Emails
- Business documents
- Access credentials
- Intellectual property
And unlike servers, endpoint devices are often:
- Mobile
- Used remotely
- Connected to different networks
- Exposed to theft
- Used by human beings (always risky!)
The objective is simple:
Ensure endpoint devices are appropriately protected against loss, theft, misuse, compromise, and unauthorised access.
Because if an attacker gains control of an endpoint device, they often gain access to far more than just the device.
Click here to read the full article.
A8.2 Privileged Access Rights
How do I control administrator access and prevent people having more access than they need?
A8.2 requires organisations to control, restrict, manage, and review privileged access rights.
Privileged access refers to elevated permissions that allow users to perform actions ordinary users cannot.
Examples include:
- System administrator accounts
- Domain administrator accounts
- Database administrator access
- Cloud administration accounts
- Security management accounts
- Application administrator privileges
- Network administration rights
These accounts are incredibly powerful.
They can:
- Create users
- Delete data
- Change configurations
- Access sensitive information
- Disable security controls
- Modify systems
Which means they are also incredibly attractive to attackers.
The objective is simple:
Ensure privileged access is only granted when necessary, approved appropriately, and regularly reviewed.
Because the more privilege someone has, the greater the potential impact if something goes wrong.
A8.3 Information Access Restriction
How do I make sure employees only have access to the information they actually need?
A8.3 requires organisations to restrict access to information and information-related assets in accordance with business and information security requirements.
In simple terms:
Not everyone needs access to everything.
This control is based on a simple principle:
People should only have access to the information required to perform their role.
No more.
No less.
This applies to:
- Documents
- Databases
- Applications
- Shared drives
- Cloud platforms
- Customer records
- Financial information
- HR records
- Intellectual property
The objective is simple:
Prevent unauthorised access, accidental disclosure, and unnecessary exposure of information.
Because the more people who can access information, the greater the risk that information will be lost, exposed, altered, or misused.
A8.4 Access to Source Code
How do I protect source code from unauthorised access, changes, theft, or accidental damage?
A8.4 requires organisations to restrict and manage access to source code.
Source code is often one of an organisation’s most valuable assets.
It contains the logic, processes, functionality, and intellectual property that make applications, systems, and services work.
If source code is compromised, an organisation may face:
- Intellectual property theft
- Introduction of malicious code
- Accidental changes
- Service disruption
- Security vulnerabilities
- Loss of competitive advantage
The control requires organisations to ensure that access to source code is controlled, monitored, and limited to authorised individuals who genuinely need it.
The objective is simple:
Protect source code from unauthorised access, modification, disclosure, or destruction.
Because if attackers gain access to your source code, they may gain insight into how your systems work and where weaknesses exist.
A8.5 Secure Authentication
How do I ensure only the right people can access our systems, applications, and data?
A8.5 requires organisations to implement secure authentication methods to verify the identity of users before granting access to systems, applications, services, and information.
In simple terms:
How do you know someone is really who they claim to be?
Every security control built around access depends on authentication working effectively.
If authentication is weak, then access controls, permissions, and security policies become far less effective.
Authentication mechanisms may include:
- Passwords
- Multi-Factor Authentication (MFA)
- Biometrics
- Smart cards
- Security tokens
- Single Sign-On (SSO)
- Authentication applications
The control requires organisations to consider the level of risk and apply authentication methods that are appropriate to the information and systems being protected.
The objective is simple:
Prevent unauthorised individuals from accessing information and systems by ensuring users are properly authenticated.
Because before you decide what someone can access, you need confidence that they are who they say they are
A8.6 Capacity Management
How do I ensure my systems have enough capacity to support the business without causing outages, slowdowns, or security risks?
A8.6 requires organisations to monitor, manage, and plan the capacity of information processing facilities to ensure they can meet current and future business requirements.
In plain English:
Do you know whether your systems can cope with what you’re asking them to do?
Every system has limits. Storage fills up. Networks become congested. Databases grow. Applications consume more resources. User numbers increase.
The problem is that capacity issues rarely appear overnight.
They usually build gradually until performance degrades, services fail, or users start complaining.
This control requires organisations to monitor usage, understand trends, and take action before capacity becomes a problem.
The objective is simple:
Ensure systems remain available, reliable, and capable of supporting the organisation’s needs.
Because information security isn’t just about confidentiality.
Availability matters too.
A8.7 Protection Against Malware
How do I protect my business from viruses, ransomware, and other forms of malicious software?
A8.7 requires organisations to implement appropriate measures to protect against malware.
Malware is short for malicious software and includes threats such as:
- Viruses
- Ransomware
- Trojans
- Spyware
- Worms
- Keyloggers
- Malicious scripts
- Botnets
The reality is simple:
Attackers rarely need to break into your systems if they can trick someone into letting malware in.
This control requires organisations to implement preventative, detective, and corrective measures designed to reduce the risk of malware infecting systems and compromising information.
Examples include:
- Anti-malware software
- Endpoint protection
- Email filtering
- Web filtering
- Security updates
- User awareness training
- Application controls
- Monitoring and detection capabilities
The objective is simple:
Prevent malware from compromising the confidentiality, integrity, and availability of information and systems.
Because recovering from malware is always harder than preventing it.
A8.8 Management of technical vulnerabilities
How do I identify and fix security weaknesses before attackers exploit them?
A8.8 requires organisations to obtain information about technical vulnerabilities, assess the risks they create, and take appropriate action to address them.
In simple terms:
You can’t fix a weakness if you don’t know it exists.
Every piece of technology contains vulnerabilities. Including
- Operating systems.
- Applications.
- Cloud platforms.
- Firewalls.
- Websites.
- Mobile apps.
- Network devices.
Sometimes these vulnerabilities are discovered by security researchers. Sometimes by vendors. Sometimes by attackers.
The important thing is that organisations have a process to:
- Identify vulnerabilities
- Assess their impact
- Prioritise remediation
- Apply fixes where appropriate
- Monitor for emerging threats
The objective is simple:
Reduce the risk of attackers exploiting known weaknesses in your technology estate.
Because attackers don’t usually look for new ways in. They often look for old weaknesses nobody fixed.
Click here to read the full article.
A8.9 Configuration Management
How do I ensure systems are configured securely and remain secure as the business grows and changes?
A8.9 requires organisations to establish, document, implement, and monitor secure configurations for hardware, software, services, and networks.
In simple terms:
Are your systems set up securely, or are you relying on default settings and good luck?
Every device, application, cloud platform, and operating system comes with configuration settings.
Some of those settings improve security, some reduce it and some are enabled by default simply to make installation easier.
The challenge is that attackers actively look for weak configurations because they’re often easier to exploit than software vulnerabilities.
Examples include:
- Default passwords
- Unnecessary services
- Open ports
- Excessive permissions
- Insecure cloud settings
- Weak authentication settings
- Unused accounts
- Misconfigured firewalls
The objective is simple:
Ensure systems are configured securely and remain configured securely throughout their lifecycle.
Because a perfectly secure system can become vulnerable through poor configuration.
A8.10 Information Deletion
How do I safely delete information when it’s no longer needed without creating legal, compliance, or security risks?
A8.10 requires organisations to securely delete information when it is no longer required.
This sounds simple; Just delete the file. Empty the recycle bin. Job done!
Except it isn’t. 😵
The reality is that information often exists in multiple places:
- Laptops
- Servers
- Cloud platforms
- Backups
- Shared drives
- Email systems
- Mobile devices
- Collaboration tools
And simply deleting a file doesn’t always mean the information is gone.
The control requires organisations to establish processes for identifying information that is no longer required and ensuring it is deleted in a secure and appropriate manner.
The objective is simple:
Reduce the risk of retaining information longer than necessary and prevent unauthorised access to information that should no longer exist.
Because keeping unnecessary information creates unnecessary risk.
A8.11 Data Masking
How do I allow people to use data without exposing sensitive personal or confidential information?
A8.11 requires organisations to use data masking techniques where appropriate to protect sensitive information.
Data masking is the process of hiding, obscuring, or replacing sensitive information so that it can still be used for legitimate purposes without exposing the actual data.
For example:
Instead of showing:
John Smith
john.smith@email.com
DOB: 01/01/1980
You might display:
J* S****
j**@email.com**
DOB: XX/XX/1980
Or replace real data entirely in test environments.
The control is particularly useful when:
- Using production data for testing
- Sharing reports internally
- Demonstrating systems
- Conducting training
- Providing access to third parties
- Limiting access to personal information
The objective is simple:
Reduce exposure of sensitive information while still allowing data to be used for legitimate business purposes.
Because not everyone needs to see everything.
A8.12 Data Leakage Prevention
How do I stop sensitive information from being accidentally or deliberately shared, exposed, or stolen?
A8.12 requires organisations to implement measures to prevent the unauthorised disclosure, extraction, or leakage of information.
In simple terms:
How do you stop sensitive information leaving the organisation when it shouldn’t?
Data leakage can occur in many ways:
- Emails sent to the wrong person
- Files uploaded to unauthorised cloud services
- Information copied to USB devices
- Screenshots shared externally
- Sensitive documents printed and removed
- Employees sharing information through personal accounts
- Deliberate theft of information
- Accidental disclosure
The reality is that not all information loss is caused by hackers.
In fact, many incidents are caused by everyday mistakes.
This control requires organisations to understand where sensitive information exists and implement appropriate safeguards to prevent it from being exposed.
The objective is simple:
Protect sensitive information from unauthorised disclosure, whether accidental or deliberate.
Because once information leaves your control, getting it back is rarely an option.
A8.13 Information Backup
How do I ensure critical business information can be recovered if something goes wrong?
A8.13 requires organisations to implement and manage backup processes that protect information against loss, corruption, destruction, or unavailability.
In simple terms:
If your data disappeared tomorrow, could you get it back?
Every organisation relies on information.
- Customer records.
- Financial data.
- Emails.
- Contracts.
- Projects.
- Documents.
- Intellectual property.
- And much much more…
The challenge is that information can be lost in many ways:
- Ransomware attacks
- Accidental deletion
- Corruption (due to aging)
- Hardware failures
- Software failures
- Human error
- Theft
- Fire
- Flood
- System outages
This control requires organisations to identify what information needs backing up, how often backups should occur, where backups should be stored, and how recovery will be achieved when needed.
The objective is simple:
Ensure information can be restored when it is lost, damaged, corrupted, or becomes unavailable.
Because a backup only has value if it works when you need it.
A8.14 Redundancy of Information Processing Facilities
How do I keep critical systems running when technology, infrastructure, or services fail?
A8.14 requires organisations to implement redundancy where appropriate to ensure the continued availability of information processing facilities.
In simple terms:
What happens if a critical system stops working?
Every organisation relies on technology. Technology like
- Servers.
- Networks.
- Cloud services.
- Internet connections.
- Applications.
- Storage systems.
The problem is that no technology is infallible…
- Hardware fails.
- Services go offline.
- Networks become unavailable.
- Power is interrupted.
- Suppliers experience outages.
This control requires organisations to identify critical systems and determine whether redundancy is necessary to reduce the risk of disruption.
Examples of redundancy may include:
- Multiple internet connections
- Failover servers
- Cloud resilience arrangements
- Backup power supplies
- Duplicate network infrastructure
- Geographic redundancy
- High-availability platforms
- Secondary data centres
The objective is simple:
Ensure critical business services remain available when components fail.
Because failure isn’t a question of if – It’s a question of when!
A8.15 Logging
What logs do I need to maintain for ISO27001 and why?
A8.15 requires organisations to create, protect, retain, and review logs that record activities, events, faults, exceptions, and security-related actions within information systems.
In simple terms:
If there was a security incident tomorrow, would you have any evidence to investigate it?
Logs are the digital equivalent of CCTV.
They help answer important questions such as:
- Who logged in?
- When did they log in?
- What did they access?
- What changes were made?
- What failed?
- What unusual activity occurred?
Without logs, organisations are often left guessing.
With logs, organisations have evidence.
The control requires organisations to determine what should be logged, how logs are protected, how long they should be retained, and how they are reviewed.
The objective is simple:
Create reliable records that support monitoring, investigations, incident response, and accountability.
Because if you don’t know what happened, it’s difficult to respond effectively.
A8.16 Monitoring Activities
What kind of monitoring do I need for ISO27001?
A8.16 requires organisations to monitor networks, systems, applications, and information processing activities for abnormal, suspicious, or unauthorised behaviour.
While A8.15 focuses on creating logs, A8.16 focuses on actually using them.
In simple terms:
There’s little point collecting information if nobody is paying attention to it.
Monitoring helps organisations identify:
- Suspicious user activity
- Unauthorised access attempts
- Malware infections
- Failed login attempts
- Unusual system behaviour
- Data exfiltration attempts
- Privilege misuse
- Security incidents in progress
The control doesn’t require every organisation to operate a 24/7 Security Operations Centre.
It does require organisations to determine what needs monitoring, how it will be monitored, and how potential security events will be investigated and escalated.
The objective is simple:
Detect security issues early enough to reduce their impact.
Because the faster you detect a problem, the more options you have to deal with it.
A8.17 Clock Synchronisation
How is Clock Syncronisation and how does it help with Security and ISO27001?
A8.17 requires organisations to synchronise the clocks of information processing systems to approved and accurate time sources.
At first glance, this can seem like one of the more technical controls in ISO27001.
But the principle is surprisingly simple:
If your systems don’t agree on the time, how can you trust the evidence they produce?
Think about what happens during a security incident.
You need to know:
- When did the attacker log in?
- When was the file accessed?
- When was the email sent?
- When did the system fail?
- When was the alert generated?
If one server is five minutes ahead, another is three minutes behind, and a cloud service is using a different timezone altogether, investigations quickly become confusing.
This control requires organisations to ensure that systems use reliable time sources and maintain consistent timestamps across their environment.
The objective is simple:
Ensure logs, monitoring data, security events, and system records are accurate, consistent, and reliable.
Because evidence is only useful if you can trust the timeline.
A8.18 Use of Privileged Utility Programs
What are privileged utility programs?
A8.18 requires organisations to restrict and control the use of privileged utility programs.
Privileged utility programs are tools that can perform powerful actions on systems, applications, databases, and networks.
Examples include:
- Database administration tools
- System diagnostic tools
- Password reset utilities
- Network scanning tools
- System configuration tools
- Backup and recovery utilities
- Command-line administration tools
- Remote administration software
These tools are often essential for IT operations.
The problem is that they can also bypass normal security controls.
In the wrong hands, they may allow someone to:
- Access sensitive information
- Modify system configurations
- Create or delete accounts
- Change permissions
- Extract data
- Disable security controls
- Disrupt business operations
The objective is simple:
Ensure privileged utility programs are only used by authorised individuals for legitimate business purposes.
Because the tools designed to help manage systems can also become some of the most dangerous tools in the environment.
A8.19 Installation of Software on Operational Systems
How do I stop unauthorised, unsafe, or unnecessary software from creating security risks in my business?
A8.19 requires organisations to control the installation of software on operational systems.
In simple terms:
Who is allowed to install software, and how do you know that software is safe?
Most cyber security incidents don’t start with sophisticated attacks.
They start with someone installing something they shouldn’t.
That might be:
- Unapproved software
- Free utilities downloaded from the internet
- Browser extensions
- File-sharing applications
- AI tools
- Remote access software
- Games
- Applications containing malware
This control requires organisations to establish rules around software installation, ensuring that software is authorised, tested where appropriate, and aligned with business requirements.
The objective is simple:
Prevent unauthorised, malicious, or inappropriate software from introducing security vulnerabilities, instability, or compliance risks.
Because every piece of software you install becomes part of your attack surface.
A8.20 Networks Security
What network security controls does ISO27001
A8.20 requires organisations to secure networks and network services to protect information as it is transmitted, processed, and accessed.
In simple terms:
How do you protect the digital roads that connect your systems, users, and information?
Every modern organisation depends on networks.
Whether it’s:
- The office network
- Wi-Fi
- Cloud connectivity
- Internet access
- Virtual Private Networks (VPNs)
- Remote working connections
- Third-party connections
Networks are the pathways that information travels across every day.
If those pathways aren’t protected, attackers may be able to:
- Access sensitive information
- Intercept communications
- Disrupt services
- Move through systems
- Spread malware
- Gain unauthorised access
The objective is simple:
Ensure networks are designed, managed, and protected in a way that reduces security risks and supports business operations.
Because if information is travelling across your network, your network becomes part of your security perimeter.
Click here to read the full article.
A8.21 Security of Network Services
What are the network services required in ISO27001?
A8.21 requires organisations to identify, define, implement, and monitor security requirements for network services.
While A8.20 focuses on protecting the network itself, A8.21 focuses on the services that operate across that network.
Examples include:
- Internet services
- Cloud connectivity
- VPN services
- Managed network services
- Telecommunications services
- Remote access services
- Network monitoring services
- Third-party network providers
The control requires organisations to understand:
- What network services are being used
- What security requirements apply
- Who is responsible for delivering the service
- How service performance and security are monitored
- What happens if the service fails
The objective is simple:
Ensure network services support the organisation’s security and business requirements.
Because your network is only as reliable as the services that support it.
A8.22 Segregation of Networks
What is network segregation? And why is network segregation important to ISO27001?
A8.22 requires organisations to segregate networks, network services, and network resources according to business and security requirements.
In simple terms:
Should everything really be connected to everything else?
For many organisations, the answer is no.
Different systems often have different levels of sensitivity and risk.
For example:
- Guest Wi-Fi
- Employee devices
- Production systems
- Finance systems
- Development environments
- Operational technology (OT)
- Cloud environments
- Third-party connections
If everything sits on the same network with unrestricted access, a problem in one area can quickly become a problem everywhere.
Network segregation helps create boundaries.
It limits access, it reduces risk and helps contain incidents when they occur.
The objective is simple:
Reduce the likelihood that unauthorised access, malware, or security incidents can spread throughout the organisation.
Because good security isn’t just about keeping attackers out.
It’s about limiting how far they can go if they get in.
Click here to read the full article.
A8.23 Web Filtering
What is web filtering?
A8.23 requires organisations to manage and control access to external websites in order to reduce information security risks.
In simple terms:
Not every website is safe, and not every website should be accessible from your business environment.
The internet is one of the most valuable business tools available.
It’s also one of the biggest sources of cyber security risk.
Employees can unknowingly visit websites that:
- Distribute malware
- Host phishing pages
- Steal credentials
- Deliver ransomware
- Encourage unsafe downloads
- Circumvent security controls
- Expose the organisation to legal or compliance risks
This control requires organisations to determine what web access restrictions are appropriate based on their risks and business needs.
Examples may include:
- Website filtering
- DNS filtering
- URL blocking
- Category-based filtering
- Safe browsing controls
- Browser security policies
- Monitoring internet usage
The objective is simple:
Reduce the likelihood of users accessing websites that could compromise information, systems, or business operations.
Because one click can sometimes be all it takes.
A8.24 Use of Cryptography
What is Cryptography and why is it important to ISO27001?
A8.24 requires organisations to establish and implement rules for the effective use of cryptography to protect information.
In simple terms:
If someone got hold of your information, could they actually read it?
Cryptography is the practice of protecting information by converting it into a format that can only be accessed by authorised individuals or systems.
Common examples include:
- Encryption of laptops
- Encrypted email
- Secure websites (HTTPS)
- Encrypted backups
- VPN encryption
- Mobile device encryption
- Encrypted cloud storage
- Digital certificates
The purpose of cryptography is to protect information when other controls fail.
For example:
- A laptop is stolen
- A backup device is lost
- Data is intercepted during transmission
- A storage device goes missing
- Information is shared across untrusted networks
The objective is simple:
Protect the confidentiality, integrity, and authenticity of information using appropriate cryptographic controls.
Because sometimes the safest information is information that cannot be understood by anyone who shouldn’t have access to it.
A8.25 Secure Development Life Cycle
What is a Secure Development Life Cycle (SDLC)?
A8.25 requires organisations to establish and apply rules for the secure development of software and systems throughout their lifecycle.
In simple terms:
How do you build security into technology instead of trying to bolt it on afterwards?
Many organisations only think about security after a system has been developed.
By then, fixing security weaknesses can be expensive, disruptive, and time-consuming.
This control encourages organisations to consider security from the very beginning.
Throughout:
- Design
- Development
- Testing
- Deployment
- Maintenance
- Change management
The secure development life cycle (SDLC) helps ensure that security is considered alongside functionality, performance, and usability.
The objective is simple:
Reduce vulnerabilities and security weaknesses by integrating security into every stage of development.
Because it’s usually easier, cheaper, and safer to build security in than retrofit it later.
A8.26 Application Security Requirements
What are the application security requriements in ISO27001?
A8.26 requires organisations to identify, specify, and approve information security requirements for applications before they are developed, acquired, or implemented.
In simple terms:
Have you defined what “secure” means before you buy, build, or deploy an application?
Many organisations focus heavily on functionality when selecting or developing software.
Questions like:
- Will it do the job?
- Is it easy to use?
- How much does it cost?
Are often asked.
Questions like:
- How will it protect information?
- How will access be controlled?
- How will data be stored?
- How will security incidents be managed?
Are often overlooked.
This control requires organisations to define security requirements at the start, rather than discovering gaps after implementation.
Examples might include requirements for:
- Authentication
- Access control
- Encryption
- Logging
- Backup
- Availability
- Privacy
- Regulatory compliance
- Integration security
The objective is simple:
Ensure security requirements are identified and addressed before applications become operational.
Because it’s much easier to define security expectations before implementation than fix security shortcomings afterwards.
A8.27 Secure System Architecture and Engineering Principles
What secure system engineering principles are important for ISO27001?
A8.27 requires organisations to apply secure architecture and engineering principles when designing, developing, implementing, and maintaining information systems.
In simple terms:
Are your systems secure by design, or are you relying on security controls being added later?
Every system has an architecture.
Whether it’s:
- A business application
- A cloud platform
- A network
- A customer portal
- An ERP system
- A website
- An operational technology environment
The decisions made during design have a significant impact on future security.
This control encourages organisations to think about security early and consistently throughout the lifecycle of systems.
Examples include:
- Defence in depth
- Least privilege
- Network segregation
- Secure authentication
- Resilience and redundancy
- Secure interfaces
- Data protection by design
- Secure defaults
The objective is simple:
Ensure systems are designed and engineered in a way that supports security, resilience, and business objectives.
Because fixing security problems after implementation is usually more expensive than designing securely from the outset.
A8.28 Secure Coding
Why is secure coding important to ISO27001?
A8.28 requires organisations to establish and apply secure coding principles to software development activities.
In simple terms:
How do you stop security vulnerabilities being written into the code in the first place?
Many cyber security incidents occur because software contains weaknesses that attackers can exploit.
Examples include:
- SQL Injection
- Cross-Site Scripting (XSS)
- Broken authentication
- Insecure APIs
- Hardcoded passwords
- Poor input validation
- Insecure error handling
- Inadequate access controls
The reality is that many vulnerabilities are introduced during development, often unintentionally.
This control requires organisations to define coding standards, provide guidance to developers, and ensure secure coding practices are applied throughout development activities.
The objective is simple:
Reduce security vulnerabilities by ensuring software is developed using secure coding principles.
Because the most effective vulnerability is the one that never gets written into the application.
A8.29 Security Testing in Development and Acceptance
What is security testing?
A8.29 requires organisations to define and perform security testing throughout development and before systems, applications, and changes are accepted into production.
In simple terms:
Have you tested for security, or are you simply hoping everything is secure?
Many organisations test whether a system works.
Far fewer test whether it can be exploited.
A system may function perfectly while still containing significant security weaknesses.
This control requires organisations to ensure security testing is planned, performed, and appropriate to the risks involved.
Examples may include:
- Vulnerability scanning
- Penetration testing
- Secure code reviews
- Configuration reviews
- Authentication testing
- Access control testing
- Security requirements verification
- User acceptance testing with security considerations
The objective is simple:
Identify and address security weaknesses before systems are released into operational use.
Because fixing vulnerabilities before go-live is significantly easier than fixing them after an incident.
A8.30 Outsourced Development
What is Outsourced Development important to ISO27001?
A8.30 requires organisations to direct, monitor, and review outsourced software development activities.
In simple terms:
If someone else is building your software, how do you know they’re doing it securely?
Many organisations rely on:
- Software development companies
- Freelance developers
- Offshore development teams
- Managed service providers
- SaaS vendors
- Third-party software suppliers
Outsourcing development can provide expertise, speed, and flexibility.
However, it does not outsource responsibility.
The organisation remains accountable for protecting information and ensuring security requirements are met.
This control requires organisations to establish appropriate oversight, including:
- Security requirements
- Contractual obligations
- Development standards
- Testing requirements
- Intellectual property protection
- Access controls
- Security reviews
- Supplier monitoring
The objective is simple:
Ensure outsourced development activities meet the organisation’s security requirements and do not introduce unnecessary risks.
Because while development may be outsourced, accountability remains in-house.
A8.31 Separation of Development, Test and Production Enviroments
What does ISO27001 expect from clause A8.31?
A8.31 requires organisations to separate development, testing, and production environments and apply appropriate controls to each.
In simple terms:
How do you stop experimentation in one environment causing problems in another?
Most organisations that develop, configure, or modify systems use different environments for different purposes.
For example:
- Development environments for creating changes
- Test environments for checking functionality
- Production environments for live business operations
The problem occurs when these environments are poorly separated.
This can lead to:
- Accidental changes to live systems
- Exposure of sensitive information
- Unauthorised access
- Testing on production systems
- Data integrity issues
- Service disruption
The control requires organisations to establish clear separation between environments and ensure information, access, and activities are managed appropriately.
The objective is simple:
Protect live business systems and information from risks introduced through development and testing activities.
Because customers should never become part of your testing process.
A8.32 Change Management
What is change management in ISO27001?
A8.32 requires organisations to manage changes to information processing facilities in a controlled manner.
In simple terms:
How do you make sure a change improves things rather than breaks them?
Every organisation changes its technology environment.
Examples include:
- Software updates
- Infrastructure changes
- Cloud migrations
- Configuration changes
- Security improvements
- New applications
- System upgrades
- Network modifications
The challenge is that even small changes can create significant consequences if they’re not properly planned, tested, reviewed, and approved.
This control requires organisations to establish processes that ensure changes are:
- Assessed
- Authorised
- Tested
- Implemented
- Documented
- Reviewed
The objective is simple:
Reduce the likelihood that changes introduce security weaknesses, operational failures, or unintended consequences.
Because many security incidents aren’t caused by attackers.
They’re caused by poorly managed changes.
A8.33 Test Information
Can I use live data in a test environment?
In a word, No.
A8.33 requires organisations to protect information used for testing and ensure that sensitive information is not exposed unnecessarily within development and test environments.
In simple terms:
Do your test systems contain information that shouldn’t be there?
One of the most common security mistakes organisations make is using live production data for testing.
Why?
Because it’s convenient.
Real data makes testing easier.
The problem is that test environments rarely have the same controls as production environments.
This creates risks such as:
- Unauthorised access to personal data
- Exposure of confidential information
- GDPR breaches
- Data leakage
- Excessive access permissions
- Uncontrolled copying of information
This control requires organisations to ensure that test information is appropriately protected and that production data is only used when absolutely necessary and under controlled conditions.
The objective is simple:
Protect sensitive information during development, testing, training, and support activities.
Because information remains sensitive regardless of where it is stored.
A8.34 Protection of Information Systems During Audit and Testing
How do I carry out audits, assessments, and security testing without disrupting business operations or creating new risks?
A8.34 requires organisations to plan and control audit testing activities to minimise the risk of disruption to operational systems and business processes.
In simple terms:
How do you test the business without breaking the business?
Audits and security assessments are important.
They help organisations:
- Verify controls are working
- Identify weaknesses
- Demonstrate compliance
- Improve security
- Validate processes
However, testing itself can introduce risk if it is not properly managed.
Examples include:
- Penetration testing
- Vulnerability assessments
- Technical audits
- Compliance audits
- Configuration reviews
- System inspections
Without proper planning, audit activities can:
- Cause system outages
- Affect performance
- Corrupt data
- Trigger security alerts
- Interrupt business operations
- Create unintended consequences
The control requires organisations to ensure testing activities are authorised, planned, coordinated, and controlled.
The objective is simple:
Gain assurance without creating unnecessary risk to operational systems.
Because the purpose of an audit is to improve security, not become a security incident.
