Cloud Shared Responsibility Mapper
Framework

ISO/IEC 27001:2022 Annex A: the clauses behind the split

The Annex A controls of ISO/IEC 27001:2022, including 5.23 on information security for use of cloud services. The management clauses are named, not quoted, here.

Shown when ticked. The framework on the compliance library.

Control areas it anchors

11
AreaClause
Governance and policyISO/IEC 27001 5.2
Identity and accessISO/IEC 27001 5.18
Data classification and handlingISO/IEC 27001 5.12
Encryption and keysISO/IEC 27001 8.24
Network securityISO/IEC 27001 8.22
Logging and monitoringISO/IEC 27001 8.15
Vulnerability and patch managementISO/IEC 27001 8.8
Incident responseISO/IEC 27001 5.26
Business continuity and backupISO/IEC 27001 8.13
Supplier and subserviceISO/IEC 27001 5.23
AI use and data retentionISO/IEC 27001 8.10

Every clause cited, quoted

12 of the 93 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

What an assessor asks to see:
  • Role definitions
  • Responsibility matrix
  • Assignment records
  • Authority delegation
Where it usually falls short:
  • Roles not updated after staff changes
  • No documented acceptance of responsibilities
  • Unclear separation between ownership and operational duties
  • Delegated authority not reflected in policy documents
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 5.12 Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

What an assessor asks to see:
  • Classification policy
  • Classification scheme
  • Labeling guidelines
  • Asset inventory with classification
  • Training records
Where it usually falls short:
  • Classification levels not aligned with business impact
  • Inconsistent labeling across departments
  • Missing periodic review of classifications
  • Unclear ownership for classification decisions
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

What an assessor asks to see:
  • Access provision records
  • Access review reports
  • Access revocation logs
  • Role definition documents
Where it usually falls short:
  • Reviews lack documented corrective actions
  • Access changes not tied to approved request workflow
  • Legacy accounts remain active after employee departure
  • Role definitions not updated to reflect current business processes
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

What an assessor asks to see:
  • Cloud service selection
  • Cloud contract management
  • Cloud security monitoring
  • Cloud exit plan
Where it usually falls short:
  • Relying solely on provider's security assurances
  • No documented exit or data migration procedures
  • Insufficient risk assessment before cloud onboarding
  • Contracts missing specific security and audit clauses
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 5.26 Response to information security incidents

Respond to incidents according to the documented procedures.

What an assessor asks to see:
  • Incident response plan
  • Incident handling records
  • Post incident analysis
  • Stakeholder communication
Where it usually falls short:
  • Plans not tested regularly
  • Incident logs incomplete or inconsistent
  • No formal post‑incident review process
  • Communication with affected parties delayed
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.8 Management of technical vulnerabilities

Obtain vulnerability information, evaluate exposure, and take appropriate remediation.

What an assessor asks to see:
  • Vulnerability feed logs
  • Risk assessment reports
  • Remediation ticket records
  • Patch deployment evidence
Where it usually falls short:
  • Relying on ad-hoc scans only
  • Missing documented risk ranking for vulnerabilities
  • No evidence of timely remediation verification
  • Failure to retain proof of feed subscription
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.10 Information deletion

Delete information in systems, devices and media when no longer required.

What an assessor asks to see:
  • Deletion policy
  • Media disposal log
  • System deletion audit
  • Data retention schedule
Where it usually falls short:
  • Retaining data beyond approved period
  • No evidence of secure erase verification
  • Policies not aligned with actual practice
  • Incomplete media disposal records
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.12 Data leakage prevention

Apply data leakage prevention to systems and channels handling sensitive information.

What an assessor asks to see:
  • Dlp policy
  • Dlp solution configuration
  • Dlp monitoring reports
  • Incident handling records
  • Employee awareness training
Where it usually falls short:
  • Policy not enforced across all data channels
  • DLP rules outdated and misaligned with business processes
  • Insufficient monitoring and alert retention
  • Lack of documented response to DLP incidents
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

What an assessor asks to see:
  • Backup policy
  • Backup schedule
  • Backup test reports
  • Retention records
  • Access logs
Where it usually falls short:
  • infrequent restore testing
  • missing retention documentation
  • undefined backup responsibilities
  • inconsistent backup verification
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.15 Logging

Produce, store, protect and analyse logs of activities, exceptions and faults.

What an assessor asks to see:
  • Log collection policy
  • Log storage and protection
  • Log review and analysis
  • Log retention and disposal
Where it usually falls short:
  • Inconsistent log collection across systems
  • Insufficient protection of log integrity
  • Irregular or undocumented log review
  • Retention periods not aligned with policy
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

What an assessor asks to see:
  • Network segmentation policy
  • Network topology diagrams
  • Firewall rule set documents
  • Segregation testing reports
Where it usually falls short:
  • Informal or outdated network maps used instead of documented diagrams
  • Inconsistent VLAN tagging and naming across locations
  • Exceptions to segmentation not recorded or approved
  • Segregation controls rarely tested after changes
Source: ISO/IEC 27001:2022 Annex A
ISO/IEC 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

What an assessor asks to see:
  • Encryption policy
  • Key management procedures
  • Algorithm inventory
  • Key usage records
Where it usually falls short:
  • Missing documented key lifecycle
  • Use of outdated or weak algorithms
  • Inadequate segregation of duties for key handling
  • Lack of regular key rotation evidence
Source: ISO/IEC 27001:2022 Annex A