ISO 27001 Annex A 5.11: Return of Assets – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.11 Return of Assets: A Practical Implementation Guide Recover organizational assets and information promptly when employment, contracts or roles end. This control ensures that personnel and external parties return organizational assets in their possession when their engagement changes or ends. Practical interpretation: Asset return includes more than laptops. It […]
ISO 27001 Annex A 5.12: Classification of Information – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.12 Classification of Information: A Practical Implementation Guide Apply protection according to information value, sensitivity, legal duties and business impact. Information classification provides a consistent basis for deciding how information should be accessed, stored, shared, retained and disposed of. Practical interpretation: A classification label is useful only when it […]
ISO 27001 Annex A 5.13: Labelling of Information – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.13 Labelling of Information: A Practical Implementation Guide Make information sensitivity visible and machine-readable so handling rules follow the information. Labelling translates classification decisions into markings or metadata that help people and systems apply appropriate protection. Practical interpretation: Labels must be consistent, usable and connected to action. A watermark […]
ISO 27001 Annex A 5.16: Identity Management – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.16 Identity Management: A Practical Implementation Guide Manage every human and non-human identity through a controlled, traceable lifecycle. Identity management ensures that identities are uniquely established, changed, monitored and removed in line with business relationships and access needs. Practical interpretation: An identity is not the same as an account. […]
ISO 27001 Annex A 5.17: Authentication Information – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.17 Authentication Information: A Practical Implementation Guide Issue, store, use and reset passwords, keys, tokens and secrets without exposing them. This control addresses allocation and management of authentication information used to prove an identity. Practical interpretation: Authentication information includes more than passwords. Secrets, recovery codes, cryptographic keys, tokens and […]
ISO 27001 Annex A 5.14: Information Transfer – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.14 Information Transfer: A Practical Implementation Guide Protect information whenever it moves between people, systems, organizations or physical locations. This control covers rules, agreements and safeguards for transferring information through electronic, physical and verbal channels. Practical interpretation: Transfer risk depends on the information, recipients, route and context. Approved channels, […]
ISO 27001 Annex A 5.15: Access Control – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.15 Access Control: A Practical Implementation Guide Establish consistent business rules for granting, using, reviewing and removing access. Access control policy sets the principles and lifecycle requirements used by identity, application, physical and privileged-access processes. Practical interpretation: Access control is a governance system, not only a technical setting. Business […]
ISO 27001 Annex A 5.18: Access Rights – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.18 Access Rights: A Practical Implementation Guide Grant, review, change and revoke access rights through accountable business decisions. This control focuses on provisioning and reviewing access rights in accordance with access-control policy and changing business needs. Practical interpretation: A valid account does not justify every entitlement. Each right should […]
ISO 27001 Annex A 5.19: Information Security in Supplier Relationships – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.19 Information Security in Supplier Relationships: A Practical Implementation Guide Manage security risk across the full supplier lifecycle, not only during procurement. This control establishes processes for identifying and managing information security risks arising from suppliers and their services. Practical interpretation: A questionnaire before contract signature is insufficient. Supplier […]
ISO 27001 Annex A 5.20: Addressing Information Security Within Supplier Agreements – Practical Implementation Guide
ISO/IEC 27001:2022 Annex A · Control 5.20 Addressing Information Security Within Supplier Agreements: A Practical Implementation Guide Translate supplier risk decisions into clear, enforceable contractual obligations. This control concerns agreeing relevant information security requirements with each supplier based on the relationship and associated risks. Practical interpretation: Generic confidentiality language rarely covers operational security. Agreements should […]