What are the ISO 27001 Controls?

Опубликовано: 23 Май 2026
на канале: Best Practice
15,568
121

This self-paced program is broken down into our 14-step method over 10 sessions, which will empower you to implement a robust management system in your organisation. You will gain access to course material, including example templates.

What are the ISO 27001 Controls?

Let's discuss the short description of each of the 14 sections:

A.5 Information security policies – controls on how the policies are written and reviewed.
A.6 Organization of information security – controls on how the responsibilities are assigned; also includes the controls for mobile devices and teleworking.
A.7 Human resources security – controls prior to employment, during, and after the employment.
A.8 Asset management – controls related to inventory of assets and acceptable use; also for information classification and media handling.
A.9 Access control – controls for the management of access rights of users, systems, and applications, and for the management of user responsibilities.
A.10 Cryptography – controls related to encryption and key management.
A.11 Physical and environmental security – controls defining secure areas, entry controls, protection against threats, equipment security, secure disposal, Clear Desk, and Clear Screen Policy, etc.
A.12 Operational security – lots of controls related to the management of IT production: change management, capacity management, malware, backup, logging, monitoring, installation, vulnerabilities, etc.
A.13 Communications security – controls related to network security, segregation, network services, transfer of information, messaging, etc.
A.14 System acquisition, development and maintenance – controls defining security requirements, and security in development and support processes.
A.15 Supplier relationships – controls on what to include in agreements, and how to monitor the suppliers.
A.16 Information security incident management – controls for reporting events and weaknesses, defining responsibilities, response procedures, and collection of evidence.
A.17 Information security aspects of business continuity management – control requiring the planning of business continuity, procedures, verification and reviewing, and IT redundancy.
A.18 Compliance – controls requiring the identification of applicable laws and regulations, intellectual property protection, personal data protection, and reviews of information security.

Download your Gap Analysis Checklist here:
https://www.bestpracticeeducation.com...

For more information on certifications visit our website:
https://bestpractice.biz/certificatio...

Follow and subscribe to:
Best Practice Website: https://bestpractice.biz/
Facebook:   / bestpracticecertification  
LinkedIn:   / best-practice-certification  
Instagram: @bestpractice.biz
TikTok: kobisimmat