Control Mapping Readerplace a control, see the map

ISO 27001:2013 controls

114 controls held for ISO 27001:2013 (ISO/IEC 27001). Edition: ISO/IEC 27001:2013. Place a control statement and the reader picks the closest text here and the closest matches in the other frameworks. Open ISO 27001:2013 on the standards site.

CodeControlDomain
A.5.1.1Policies for information securityA.5 Information security policiesopen
A.5.1.2Review of the policies for information securityA.5 Information security policiesopen
A.6.1.1Information security roles and responsibilitiesA.6 Organization of information securityopen
A.6.1.2Segregation of dutiesA.6 Organization of information securityopen
A.6.1.3Contact with authoritiesA.6 Organization of information securityopen
A.6.1.4Contact with special interest groupsA.6 Organization of information securityopen
A.6.1.5Information security in project managementA.6 Organization of information securityopen
A.6.2.1Mobile device policyA.6 Organization of information securityopen
A.6.2.2TeleworkingA.6 Organization of information securityopen
A.7.1.1ScreeningA.7 Human resource securityopen
A.7.1.2Terms and conditions of employmentA.7 Human resource securityopen
A.7.2.1Management responsibilitiesA.7 Human resource securityopen
A.7.2.2Information security awareness, education and trainingA.7 Human resource securityopen
A.7.2.3Disciplinary processA.7 Human resource securityopen
A.7.3.1Termination or change of employment responsibilitiesA.7 Human resource securityopen
A.8.1.1Inventory of assetsA.8 Asset managementopen
A.8.1.2Ownership of assetsA.8 Asset managementopen
A.8.1.3Acceptable use of assetsA.8 Asset managementopen
A.8.1.4Return of assetsA.8 Asset managementopen
A.8.2.1Classification of informationA.8 Asset managementopen
A.8.2.2Labelling of informationA.8 Asset managementopen
A.8.2.3Handling of assetsA.8 Asset managementopen
A.8.3.1Management of removable mediaA.8 Asset managementopen
A.8.3.2Disposal of mediaA.8 Asset managementopen
A.8.3.3Physical media transferA.8 Asset managementopen
A.9.1.1Access control policyA.9 Access controlopen
A.9.1.2Access to networks and network servicesA.9 Access controlopen
A.9.2.1User registration and de-registrationA.9 Access controlopen
A.9.2.2User access provisioningA.9 Access controlopen
A.9.2.3Management of privileged access rightsA.9 Access controlopen
A.9.2.4Management of secret authentication information of usersA.9 Access controlopen
A.9.2.5Review of user access rightsA.9 Access controlopen
A.9.2.6Removal or adjustment of access rightsA.9 Access controlopen
A.9.3.1Use of secret authentication informationA.9 Access controlopen
A.9.4.1Information access restrictionA.9 Access controlopen
A.9.4.2Secure log-on proceduresA.9 Access controlopen
A.9.4.3Password management systemA.9 Access controlopen
A.9.4.4Use of privileged utility programsA.9 Access controlopen
A.9.4.5Access control to program source codeA.9 Access controlopen
A.10.1.1Policy on the use of cryptographic controlsA.10 Cryptographyopen
A.10.1.2Key managementA.10 Cryptographyopen
A.11.1.1Physical security perimeterA.11 Physical and environmental securityopen
A.11.1.2Physical entry controlsA.11 Physical and environmental securityopen
A.11.1.3Securing offices, rooms and facilitiesA.11 Physical and environmental securityopen
A.11.1.4Protecting against external and environmental threatsA.11 Physical and environmental securityopen
A.11.1.5Working in secure areasA.11 Physical and environmental securityopen
A.11.1.6Delivery and loading areasA.11 Physical and environmental securityopen
A.11.2.1Equipment siting and protectionA.11 Physical and environmental securityopen
A.11.2.2Supporting utilitiesA.11 Physical and environmental securityopen
A.11.2.3Cabling securityA.11 Physical and environmental securityopen
A.11.2.4Equipment maintenanceA.11 Physical and environmental securityopen
A.11.2.5Removal of assetsA.11 Physical and environmental securityopen
A.11.2.6Security of equipment and assets off-premisesA.11 Physical and environmental securityopen
A.11.2.7Secure disposal or re-use of equipmentA.11 Physical and environmental securityopen
A.11.2.8Unattended user equipmentA.11 Physical and environmental securityopen
A.11.2.9Clear desk and clear screen policyA.11 Physical and environmental securityopen
A.12.1.1Documented operating proceduresA.12 Operations securityopen
A.12.1.2Change managementA.12 Operations securityopen
A.12.1.3Capacity managementA.12 Operations securityopen
A.12.1.4Separation of development, testing and operational environmentsA.12 Operations securityopen
A.12.2.1Controls against malwareA.12 Operations securityopen
A.12.3.1Information backupA.12 Operations securityopen
A.12.4.1Event loggingA.12 Operations securityopen
A.12.4.2Protection of log informationA.12 Operations securityopen
A.12.4.3Administrator and operator logsA.12 Operations securityopen
A.12.4.4Clock synchronisationA.12 Operations securityopen
A.12.5.1Installation of software on operational systemsA.12 Operations securityopen
A.12.6.1Management of technical vulnerabilitiesA.12 Operations securityopen
A.12.6.2Restrictions on software installationA.12 Operations securityopen
A.12.7.1Information systems audit controlsA.12 Operations securityopen
A.13.1.1Network controlsA.13 Communications securityopen
A.13.1.2Security of network servicesA.13 Communications securityopen
A.13.1.3Segregation in networksA.13 Communications securityopen
A.13.2.1Information transfer policies and proceduresA.13 Communications securityopen
A.13.2.2Agreements on information transferA.13 Communications securityopen
A.13.2.3Electronic messagingA.13 Communications securityopen
A.13.2.4Confidentiality or non-disclosure agreementsA.13 Communications securityopen
A.14.1.1Information security requirements analysis and specificationA.14 System acquisition, development and maintenanceopen
A.14.1.2Securing application services on public networksA.14 System acquisition, development and maintenanceopen
A.14.1.3Protecting application services transactionsA.14 System acquisition, development and maintenanceopen
A.14.2.1Secure development policyA.14 System acquisition, development and maintenanceopen
A.14.2.2System change control proceduresA.14 System acquisition, development and maintenanceopen
A.14.2.3Technical review of applications after operating platform changesA.14 System acquisition, development and maintenanceopen
A.14.2.4Restrictions on changes to software packagesA.14 System acquisition, development and maintenanceopen
A.14.2.5Secure system engineering principlesA.14 System acquisition, development and maintenanceopen
A.14.2.6Secure development environmentA.14 System acquisition, development and maintenanceopen
A.14.2.7Outsourced developmentA.14 System acquisition, development and maintenanceopen
A.14.2.8System security testingA.14 System acquisition, development and maintenanceopen
A.14.2.9System acceptance testingA.14 System acquisition, development and maintenanceopen
A.14.3.1Protection of test dataA.14 System acquisition, development and maintenanceopen
A.15.1.1Information security policy for supplier relationshipsA.15 Supplier relationshipsopen
A.15.1.2Addressing security within supplier agreementsA.15 Supplier relationshipsopen
A.15.1.3Information and communication technology supply chainA.15 Supplier relationshipsopen
A.15.2.1Monitoring and review of supplier servicesA.15 Supplier relationshipsopen
A.15.2.2Managing changes to supplier servicesA.15 Supplier relationshipsopen
A.16.1.1Responsibilities and proceduresA.16 Information security incident managementopen
A.16.1.2Reporting information security eventsA.16 Information security incident managementopen
A.16.1.3Reporting information security weaknessesA.16 Information security incident managementopen
A.16.1.4Assessment of and decision on information security eventsA.16 Information security incident managementopen
A.16.1.5Response to information security incidentsA.16 Information security incident managementopen
A.16.1.6Learning from information security incidentsA.16 Information security incident managementopen
A.16.1.7Collection of evidenceA.16 Information security incident managementopen
A.17.1.1Planning information security continuityA.17 Information security aspects of business continuity managementopen
A.17.1.2Implementing information security continuityA.17 Information security aspects of business continuity managementopen
A.17.1.3Verify, review and evaluate information security continuityA.17 Information security aspects of business continuity managementopen
A.17.2.1Availability of information processing facilitiesA.17 Information security aspects of business continuity managementopen
A.18.1.1Identification of applicable legislation and contractual requirementsA.18 Complianceopen
A.18.1.2Intellectual property rightsA.18 Complianceopen
A.18.1.3Protection of recordsA.18 Complianceopen
A.18.1.4Privacy and protection of personally identifiable informationA.18 Complianceopen
A.18.1.5Regulation of cryptographic controlsA.18 Complianceopen
A.18.2.1Independent review of information securityA.18 Complianceopen
A.18.2.2Compliance with security policies and standardsA.18 Complianceopen
A.18.2.3Technical compliance reviewA.18 Complianceopen