Skip to main content

Proof of competence

ISO 27001 Annex A 7.6: Working in Secure Areas – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.6 Working in Secure Areas: A Practical Implementation Guide Set clear working rules that preserve the protection of restricted physical areas. This control concerns security measures for personnel and activities performed within secure areas. Practical interpretation: A strong door is ineffective if behavior inside exposes information or allows uncontrolled […]

ISO 27001 Annex A 7.7: Clear Desk and Clear Screen – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.7 Clear Desk and Clear Screen: A Practical Implementation Guide Reduce casual exposure, loss and misuse of information when workspaces or devices are unattended. This control concerns clear-desk rules for papers and removable media and clear-screen rules for information-processing facilities. Practical interpretation: The rule should match work patterns and […]

ISO 27001 Annex A 7.8: Equipment Siting and Protection – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.8 Equipment Siting and Protection: A Practical Implementation Guide Place and protect equipment to reduce physical, environmental and observational risk. This control concerns appropriate siting and protection of equipment from physical and environmental threats and unauthorized access. Practical interpretation: Equipment location affects theft, damage, observation, ventilation, maintenance and cable […]

ISO 27001 Annex A 7.9: Security of Assets Off-Premises – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.9 Security of Assets Off-Premises: A Practical Implementation Guide Protect organizational assets whenever they leave controlled premises. This control concerns protecting off-premises assets while traveling, at home, with third parties or in temporary locations. Practical interpretation: Protection should address custody, transport, storage, environmental conditions, theft, observation, connectivity and rapid […]

ISO 27001 Annex A 7.10: Storage Media – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.10 Storage Media: A Practical Implementation Guide Control removable and fixed media from acquisition through use, transport, reuse and destruction. This control concerns managing storage media according to classification and handling requirements. Practical interpretation: Media includes drives, tapes, removable devices and embedded storage. Risks remain even when media is […]

ISO 27001 Annex A 7.11: Supporting Utilities – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.11 Supporting Utilities: A Practical Implementation Guide Protect critical information processing from failures in power, cooling, water, communications and other utilities. This control concerns protecting information-processing facilities from power failures and disruptions caused by supporting utilities. Practical interpretation: Utility resilience requires known dependencies, capacity, maintenance, monitoring and tested failover—not […]

ISO 27001 Annex A 7.12: Cabling Security – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.12 Cabling Security: A Practical Implementation Guide Protect power and data cabling from interception, interference, damage and unauthorized connection. This control concerns protecting cables carrying power, data or supporting information services. Practical interpretation: Cable risk includes eavesdropping, accidental disconnection, sabotage, electromagnetic interference and exposed patching. Protection must cover routes, […]

ISO 27001 Annex A 7.13: Equipment Maintenance – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.13 Equipment Maintenance: A Practical Implementation Guide Maintain equipment reliably without exposing information or introducing unauthorized changes. This control concerns maintaining equipment correctly to preserve availability, integrity and confidentiality. Practical interpretation: Maintenance creates privileged physical access and may expose stored data. Scheduling, authorization, supplier control, records and post-maintenance verification […]

ISO 27001 Annex A 8.4: Access to Source Code – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.4 Access to Source Code: A Practical Implementation Guide Protect source code, build definitions and development assets from unauthorized access and change. This control concerns appropriately managing read and write access to source code, development tools and software libraries. Practical interpretation: Code access affects confidentiality and software integrity. Repository […]

ISO 27001 Annex A 7.14: Secure Disposal or Re-use of Equipment – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 7.14 Secure Disposal or Re-use of Equipment: A Practical Implementation Guide Remove sensitive data and organizational identifiers before equipment is discarded, sold, returned or reassigned. This control concerns verifying that information and licensed software have been removed or securely overwritten before equipment disposal or reuse. Practical interpretation: Factory reset, […]