Skip to main content

Proof of competence

ISO 27001 Annex A 8.13: Information Backup – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.13 Information Backup: A Practical Implementation Guide Create protected, recoverable copies of information and prove they meet business recovery needs. This control concerns maintaining and regularly testing backup copies according to agreed policy. Practical interpretation: A successful backup job does not prove recovery. Scope, retention, isolation, encryption, credentials, dependencies […]

ISO 27001 Annex A 8.11: Data Masking – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.11 Data Masking: A Practical Implementation Guide Reduce exposure by replacing sensitive values while preserving necessary business or testing use. This control concerns using data masking in accordance with access-control policy, business requirements and law. Practical interpretation: Masking may be dynamic, static, tokenized, pseudonymized or redacted. The method must […]

ISO 27001 Annex A 8.14: Redundancy of Information Processing Facilities – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.14 Redundancy of Information Processing Facilities: A Practical Implementation Guide Design and test redundancy so critical services tolerate component and location failures. This control concerns implementing sufficient redundancy in information-processing facilities to meet availability requirements. Practical interpretation: Duplicated components provide resilience only when failure domains, capacity, configuration, data consistency […]

ISO 27001 Annex A 8.15: Logging – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.15 Logging: A Practical Implementation Guide Generate, protect and retain useful records of security-relevant activity. This control concerns producing, storing, protecting and analyzing logs that record events, exceptions, faults and other relevant activity. Practical interpretation: More logs are not automatically better. Logging should answer defined detection, investigation, accountability and […]

ISO 27001 Annex A 8.16: Monitoring Activities – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.16 Monitoring Activities: A Practical Implementation Guide Observe systems, networks and applications to detect abnormal behavior and potential security incidents. This control concerns monitoring networks, systems and applications for anomalous behavior and taking appropriate action. Practical interpretation: Monitoring requires baselines, detections, context, trained analysts and response. Dashboards without ownership […]

ISO 27001 Annex A 8.17: Clock Synchronization – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.17 Clock Synchronization: A Practical Implementation Guide Keep system clocks accurate and consistent so logs, transactions and investigations can be trusted. This control concerns synchronizing clocks of information-processing systems to approved time sources. Practical interpretation: Time supports authentication, certificates, distributed processing and evidence. Sources, hierarchy, security, drift monitoring and […]

ISO 27001 Annex A 8.18: Use of Privileged Utility Programs – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.18 Use of Privileged Utility Programs: A Practical Implementation Guide Restrict powerful utilities that can bypass normal application and system controls. This control concerns tightly controlling utility programs capable of overriding system and application controls. Practical interpretation: Administrative shells, database tools, debuggers, recovery tools and vendor utilities may bypass […]

ISO 27001 Annex A 8.19: Installation of Software on Operational Systems – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.19 Installation of Software on Operational Systems: A Practical Implementation Guide Permit only authorized, tested and supportable software on production and operational systems. This control concerns securely managing software installation on operational systems. Practical interpretation: Installation changes attack surface, stability, licensing and support. It should follow ownership, approval, trusted […]

ISO 27001 Annex A 8.20: Network Security – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.20 Network Security: A Practical Implementation Guide Design, configure and monitor networks to protect information and connected services. This control concerns securing and managing networks and network devices to protect information in systems and applications. Practical interpretation: Network security spans architecture, device hardening, routing, access, encryption, monitoring, resilience and […]

ISO 27001 Annex A 8.21: Security of Network Services – Practical Implementation Guide

ISO/IEC 27001:2022 Annex A · Control 8.21 Security of Network Services: A Practical Implementation Guide Define and verify security requirements for every network service, whether internal or externally supplied. This control concerns identifying security mechanisms, service levels and management requirements for network services. Practical interpretation: Connectivity must have an owner, purpose, security properties and measurable […]