ISO/IEC 27001:2022 Annex A: the clauses behind the split
The Annex A controls of ISO/IEC 27001:2022, including 5.23 on information security for use of cloud services. The management clauses are named, not quoted, here.
Shown when ticked. The framework on the compliance library.
Control areas it anchors
11Every clause cited, quoted
12 of the 93 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ISO/IEC 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
- Role definitions
- Responsibility matrix
- Assignment records
- Authority delegation
- Roles not updated after staff changes
- No documented acceptance of responsibilities
- Unclear separation between ownership and operational duties
- Delegated authority not reflected in policy documents
ISO/IEC 27001 5.12 Classification of informationClassify information by confidentiality, integrity, availability and interested-party requirements.
- Classification policy
- Classification scheme
- Labeling guidelines
- Asset inventory with classification
- Training records
- Classification levels not aligned with business impact
- Inconsistent labeling across departments
- Missing periodic review of classifications
- Unclear ownership for classification decisions
ISO/IEC 27001 5.18 Access rightsProvision, review, modify and remove access rights in line with the access control policy.
- Access provision records
- Access review reports
- Access revocation logs
- Role definition documents
- Reviews lack documented corrective actions
- Access changes not tied to approved request workflow
- Legacy accounts remain active after employee departure
- Role definitions not updated to reflect current business processes
ISO/IEC 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
- Cloud service selection
- Cloud contract management
- Cloud security monitoring
- Cloud exit plan
- Relying solely on provider's security assurances
- No documented exit or data migration procedures
- Insufficient risk assessment before cloud onboarding
- Contracts missing specific security and audit clauses
ISO/IEC 27001 5.26 Response to information security incidentsRespond to incidents according to the documented procedures.
- Incident response plan
- Incident handling records
- Post incident analysis
- Stakeholder communication
- Plans not tested regularly
- Incident logs incomplete or inconsistent
- No formal post‑incident review process
- Communication with affected parties delayed
ISO/IEC 27001 8.8 Management of technical vulnerabilitiesObtain vulnerability information, evaluate exposure, and take appropriate remediation.
- Vulnerability feed logs
- Risk assessment reports
- Remediation ticket records
- Patch deployment evidence
- Relying on ad-hoc scans only
- Missing documented risk ranking for vulnerabilities
- No evidence of timely remediation verification
- Failure to retain proof of feed subscription
ISO/IEC 27001 8.10 Information deletionDelete information in systems, devices and media when no longer required.
- Deletion policy
- Media disposal log
- System deletion audit
- Data retention schedule
- Retaining data beyond approved period
- No evidence of secure erase verification
- Policies not aligned with actual practice
- Incomplete media disposal records
ISO/IEC 27001 8.12 Data leakage preventionApply data leakage prevention to systems and channels handling sensitive information.
- Dlp policy
- Dlp solution configuration
- Dlp monitoring reports
- Incident handling records
- Employee awareness training
- Policy not enforced across all data channels
- DLP rules outdated and misaligned with business processes
- Insufficient monitoring and alert retention
- Lack of documented response to DLP incidents
ISO/IEC 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
- Backup policy
- Backup schedule
- Backup test reports
- Retention records
- Access logs
- infrequent restore testing
- missing retention documentation
- undefined backup responsibilities
- inconsistent backup verification
ISO/IEC 27001 8.15 LoggingProduce, store, protect and analyse logs of activities, exceptions and faults.
- Log collection policy
- Log storage and protection
- Log review and analysis
- Log retention and disposal
- Inconsistent log collection across systems
- Insufficient protection of log integrity
- Irregular or undocumented log review
- Retention periods not aligned with policy
ISO/IEC 27001 8.22 Segregation of networksSegregate groups of services, users and systems in the network.
- Network segmentation policy
- Network topology diagrams
- Firewall rule set documents
- Segregation testing reports
- Informal or outdated network maps used instead of documented diagrams
- Inconsistent VLAN tagging and naming across locations
- Exceptions to segmentation not recorded or approved
- Segregation controls rarely tested after changes
ISO/IEC 27001 8.24 Use of cryptographyDefine and implement rules for effective use of cryptography and key management.
- Encryption policy
- Key management procedures
- Algorithm inventory
- Key usage records
- Missing documented key lifecycle
- Use of outdated or weak algorithms
- Inadequate segregation of duties for key handling
- Lack of regular key rotation evidence