ISO 27001 Controls and Domains
ISO 27001 is structured around 14 domains, comprising a total of 114 controls. These domains and controls form the backbone of an effective Information Security Management System (ISMS). Here's a high-level introduction:
Information Security Policies (2 controls): Establish and review security policies.
Organization of Information Security (7 controls): Set up a framework for managing security.
Human Resource Security (6 controls): Ensure security from pre-employment to termination.
Asset Management (10 controls): Manage assets and assign ownership.
Access Control (14 controls): Restrict access to information based on business needs.
Cryptographic Controls (2 controls): Ensure proper use and management of cryptography.
Physical and Environmental Security (15 controls): Protect physical areas and equipment.
Operational Security (14 controls): Secure operations and ensure system integrity.
Communications Security (7 controls): Secure network services and data transfer.
System Acquisition, Development, and Maintenance (13 controls): Integrate security in the development lifecycle.
Supplier Relationships (5 controls): Manage risks from supplier interactions.
Information Security Incident Management (7 controls): Plan and respond to security incidents.
Information Security Aspects of Business Continuity Management (4 controls): Maintain security during disruptions.
Compliance (8 controls): Ensure adherence to legal, regulatory, and contractual requirements.
These controls collectively help organizations manage information security risks and protect their information assets effectively.
Last updated