Skip to main content

Proof of competence

ISO 27001 Annex A 8.2: Privileged Access Rights – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.2 Privileged Access Rights: A Practical Implementation Guide Restrict elevated access to justified, controlled and closely monitored use. This control concerns allocating and managing privileged access rights. Practical interpretation: Privilege should be exceptional, attributable and limited in scope and time. Normal work should not use administrative identities. What should […]

ISO 27001 Annex A 8.3: Information Access Restriction – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.3 Information Access Restriction: A Practical Implementation Guide Enforce approved access decisions so users and systems see only the information they need. This control concerns restricting access to information and associated assets according to access-control policy. Practical interpretation: Restriction operates at application, database, file, API and user-interface layers. Network […]

ISO 27001 Annex A 8.4: Access to Source Code – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.4 Access to Source Code: A Practical Implementation Guide Protect source code, build definitions and development assets from unauthorized access and change. This control concerns appropriately managing read and write access to source code, development tools and software libraries. Practical interpretation: Code access affects confidentiality and software integrity. Repository […]

ISO 27001 Annex A 8.5: Secure Authentication – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.5 Secure Authentication: A Practical Implementation Guide Use authentication methods that match access risk and resist common compromise paths. This control concerns implementing secure authentication technologies and procedures based on access restrictions and policy. Practical interpretation: Authentication security includes enrollment, factor choice, protocol, session handling, recovery, logging and user […]

ISO 27001 Annex A 8.6: Capacity Management – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.6 Capacity Management: A Practical Implementation Guide Monitor and plan resources so systems remain secure and available under expected and exceptional demand. This control concerns monitoring resource use and adjusting capacity to current and expected needs. Practical interpretation: Capacity shortage can become a security incident by disabling logging, backups, […]

ISO 27001 Annex A 8.7: Protection Against Malware – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.7 Protection Against Malware: A Practical Implementation Guide Prevent, detect and recover from malicious code across endpoints, servers, email, cloud and software delivery. This control concerns protection against malware supported by appropriate user awareness. Practical interpretation: Endpoint antivirus is one layer. Effective protection combines hardening, filtering, behavior detection, least […]

ISO 27001 Annex A 8.8: Management of Technical Vulnerabilities – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.8 Management of Technical Vulnerabilities: A Practical Implementation Guide Find, prioritize and remediate exploitable weaknesses according to asset exposure and business risk. This control concerns obtaining vulnerability information, assessing exposure and taking appropriate measures. Practical interpretation: A scanner list is not risk management. Vulnerabilities need asset context, exploitability, ownership, […]

ISO 27001 Annex A 8.9: Configuration Management – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.9 Configuration Management: A Practical Implementation Guide Define, deploy and monitor secure configurations throughout the technology lifecycle. This control concerns establishing, documenting, implementing, monitoring and reviewing configurations of hardware, software, services and networks. Practical interpretation: A baseline document is not enough. Configuration must be deployable, version-controlled, continuously compared and […]

ISO 27001 Annex A 8.10: Information Deletion – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.10 Information Deletion: A Practical Implementation Guide Delete information when it is no longer required and verify deletion across systems, copies and suppliers. This control concerns deleting information stored in systems, devices or other media when no longer required. Practical interpretation: Deleting a record in an application may leave […]

ISO 27001 Annex A 8.11: Data Masking – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.11 Data Masking: A Practical Implementation Guide Reduce exposure by replacing sensitive values while preserving necessary business or testing use. This control concerns using data masking in accordance with access-control policy, business requirements and law. Practical interpretation: Masking may be dynamic, static, tokenized, pseudonymized or redacted. The method must […]