Skip to main content

Proof of competence

ISO 27001 Annex A 5.34: Privacy and Protection of Personally Identifiable Information (PII) – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.34 Privacy and Protection of Personally Identifiable Information (PII): A Practical Implementation Guide Govern personal information according to applicable privacy duties across its entire lifecycle. This control concerns identifying and meeting requirements for privacy and protection of personally identifiable information. Practical interpretation: Security supports privacy but does not replace […]

ISO 27001 Annex A 5.35: Independent Review of Information Security – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.35 Independent Review of Information Security: A Practical Implementation Guide Obtain objective assurance that the security approach remains suitable, adequate and effective. This control concerns independent review of the organization’s information security management and implementation at planned intervals or after significant change. Practical interpretation: Independence means reviewers do not […]

ISO 27001 Annex A 5.36: Compliance with Policies, Rules and Standards for Information Security – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.36 Compliance with Policies, Rules and Standards for Information Security: A Practical Implementation Guide Verify that security requirements are followed in practice and correct deviations consistently. This control concerns regular review of compliance with information security policies, topic-specific rules and standards. Practical interpretation: Policy publication does not prove compliance. […]

ISO 27001 Annex A 5.37: Documented Operating Procedures – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.37 Documented Operating Procedures: A Practical Implementation Guide Give operators clear, current instructions for security-relevant tasks that must be performed consistently. This control concerns documenting operating procedures for information-processing facilities and making them available to personnel who need them. Practical interpretation: Procedures should reduce reliance on memory and individual […]

ISO 27001 Annex A 5.26: Response to Information Security Incidents – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.26 Response to Information Security Incidents: A Practical Implementation Guide Contain harm, restore trusted operations and coordinate decisions through a disciplined response process. This control addresses responding to information security incidents according to established procedures. Practical interpretation: Fast action matters, but uncontrolled action can destroy evidence or increase impact. […]

ISO 27001 Annex A 5.27: Learning from Information Security Incidents – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.27 Learning from Information Security Incidents: A Practical Implementation Guide Convert incident experience into lasting improvements to risks, controls, technology and behavior. This control focuses on using knowledge gained from incidents to strengthen information security and reduce recurrence. Practical interpretation: A lessons-learned meeting is not complete until causes are […]

ISO 27001 Annex A 5.29: Information Security During Disruption – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 5.29 Information Security During Disruption: A Practical Implementation Guide Maintain essential security protections when normal operations, staffing or technology are disrupted. This control ensures that information security remains at an appropriate level during business disruption. Practical interpretation: Emergency operation often introduces shortcuts, alternative tools and elevated access. Continuity plans […]

ISO 27001 Annex A 6.1: Screening – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 6.1 Screening: A Practical Implementation Guide Use lawful, proportionate background screening to reduce personnel risk before and during sensitive engagements. This control concerns background verification checks on candidates and personnel, proportionate to business requirements, information sensitivity and applicable law. Practical interpretation: Screening is not a universal deep investigation. The […]

ISO 27001 Annex A 6.2: Terms and Conditions of Employment – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 6.2 Terms and Conditions of Employment: A Practical Implementation Guide Make information security responsibilities explicit, understandable and enforceable from the start of employment. This control concerns including relevant information security responsibilities in employment contractual arrangements. Practical interpretation: A generic confidentiality clause is rarely enough. Terms should reflect role, access, […]

ISO 27001 Annex A 6.3: Information Security Awareness, Education and Training – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 6.3 Information Security Awareness, Education and Training: A Practical Implementation Guide Give people the knowledge and practice needed to make secure decisions in their actual roles. This control concerns providing appropriate awareness, education and training and keeping it current. Practical interpretation: Annual generic training is a baseline, not the […]