Skip to content

ISO 27001 Specific Security Domains

 

Learn about asset management, PAM, mobile device security, incident response, cloud security, business continuity, data leakage, and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a meeting if you are looking for an authorized certifying body for your ISO 27001 Certification. 

Table of Contents

How does ISO 27001 address asset management? 

 

Summary: ISO 27001:2022 addresses asset management through a cluster of Annex A Organizational controls requiring organizations to maintain a comprehensive asset inventory with clear ownership and appropriate handling procedures throughout each asset’s lifecycle. 

Control 5.9 (Inventory of Information and Other Associated Assets) requires organizations to maintain an up, to, date inventory of all information assets and other assets within the ISMS scope, with clearly assigned ownership for each asset. Control 5.10 (Acceptable Use of Information and Other Associated Assets) requires documented policies defining how information assets may and may not be used, covering employees, contractors, and third parties. Control 5.11 (Return of Assets) requires employees and contractors to return all organizational assets upon termination. Controls 5.12 (Classification), 5.13 (Labeling), and 5.14 (Information Transfer) complete the asset management framework, ensuring assets are categorized by sensitivity and handled appropriately. The asset inventory is foundational to the risk assessment, risks are identified in relation to specific assets, and an incomplete or outdated inventory is a common and significant audit finding. 

 

How does ISO 27001 address security awareness training for employees? 

 

ISO 27001:2022 makes security awareness training a mandatory requirement through Clause 7.2 (competence), Clause 7.3 (awareness), and Annex A Control 6.3 (Information Security Awareness, Education, and Training). 

Clause 7.2 requires all personnel performing work affecting information security to demonstrate appropriate competence, with evidence retained. Clause 7.3 requires all relevant persons to be aware of the information security policy and their individual contribution to ISMS effectiveness. Control 6.3 requires organizations to develop and deliver security awareness training to all employees and relevant contractors at hire and at regular intervals, with content current and relevant to each job function. Topics must include phishing recognition, data handling procedures, incident reporting, password hygiene, and organizational security policies. Training completion records, including who was trained, what was covered, and when, must be maintained and reviewed by external auditors. 

 

How does ISO 27001 address Privileged Access Management (PAM)? 

 

Summary: ISO 27001:2022 addresses privileged access management, the governance of accounts with elevated system permissions such as administrator and root access, through a set of controls requiring restriction, monitoring, and regular review of privileged accounts. 

Control 8.2 (Privileged Access Rights) specifically requires that privileged access be allocated on a need, to, use basis, reviewed regularly, and revoked when no longer required. Control 5.15 (Access Control) establishes the overarching access control policy framework. Control 5.18 (Access Rights) requires formal user access provisioning and periodic review processes for all accounts. Control 8.5 (Secure Authentication) requires strong authentication mechanisms, including multi, factor authentication, for privileged accounts. Control 8.18 (Use of Privileged Utility Programs) addresses management of system utilities that could bypass security controls. Together, these controls require organizations to implement a comprehensive PAM program that limits the reach of compromised credentials.

 

How does ISO 27001 address mobile device security? 

 

ISO 27001:2022 addresses mobile device security through Annex A Control 8.1 (User Endpoint Devices), which covers all user endpoint devices including laptops, smartphones, and tablets, whether corporate, owned or employee, owned (BYOD). The control requires organizations to enforce endpoint security policies covering: encryption and screen lock requirements, restrictions on unauthorized applications, operating system and application patch currency, procedures for reporting lost or stolen devices, and separation of corporate and personal data on BYOD devices. Control 6.7 (Remote Working) also intersects with mobile security, addressing security obligations for employees working on mobile devices outside organizational premises. Control 5.10 (Acceptable Use) must include specific provisions for mobile device use. Organizations should document their mobile device management policies and, where appropriate, implement mobile device management (MDM) software to enforce configurations and enable remote data wiping if a device is lost.

 

How does ISO 27001 address password and authentication management? 

 

ISO 27001:2022 addresses password and authentication management primarily through Annex A Control 8.5 (Secure Authentication), which requires organizations to implement authentication mechanisms appropriate to the sensitivity of the systems and the risks involved. The control requires: minimum password complexity, length, and uniqueness standards; prohibition of weak or previously breached passwords; use of multi, factor authentication (MFA) for remote access, privileged accounts, and high, risk systems; secure password storage through strong hashing algorithms; and secure processes for managing forgotten or compromised credentials. Control 8.2 (Privileged Access Rights) requires that privileged accounts, which carry the greatest risk if compromised, use the strongest available authentication controls, with MFA as the baseline expectation. Auditors commonly find shared accounts, externally accessible systems without MFA, and default vendor credentials left unchanged, all of which represent major gaps against this control. 

 

How does ISO 27001 address vulnerability management? 

 

Summary: ISO 27001:2022 requires a systematic vulnerability management process through Annex A Control 8.8, supported by threat intelligence (Control 5.7) and continuous monitoring (Control 8.16). 

Control 8.8 (Management of Technical Vulnerabilities) requires organizations to identify, evaluate, and remediate technical vulnerabilities in a timely manner. The process must include: monitoring for newly identified vulnerabilities through regular scanning, threat intelligence subscriptions, and vendor security advisories (notifications from software and hardware vendors about known security flaws); assessing the risk each vulnerability represents; and taking appropriate action, patching, tightening system settings to reduce the attack surface (configuration hardening), or implementing alternative protective measures (compensating controls) when patching is not immediately possible, within defined timeframes based on risk severity. Control 5.7 (Threat Intelligence) ensures the organization stays informed about emerging vulnerabilities and attack techniques. Control 8.16 (Monitoring Activities) supports detection of anomalous behavior that may indicate exploitation of an unpatched vulnerability. 

 

How does ISO 27001 address penetration testing? 

 

ISO 27001:2022 does not explicitly mandate penetration testing, but it is widely recognized as a best, practice mechanism for satisfying several Annex A controls and providing hands, on evidence of control effectiveness. Control 8.8 (Management of Technical Vulnerabilities) requires organizations to evaluate vulnerabilities and test controls, and penetration testing, which simulates real attacks to find gaps that automated scanners miss, is one of the most rigorous methods of doing so. Control 5.36 (Compliance with Policies, Rules, and Standards for Information Security) requires organizations to verify that security controls are operating as intended, and penetration test results provide direct evidence of whether controls hold up under simulated attack conditions. Many ISO 27001 certified organizations conduct annual penetration tests as inputs to their risk assessment and control improvement processes.  

 

How does ISO 27001 address access control? 

 

Summary: ISO 27001:2022 addresses access control comprehensively through a series of Annex A controls requiring that access to information and systems be granted, managed, reviewed, and revoked based on documented policy and the principle of least privilege. 

Control 5.15 (Access Control) requires organizations to establish and implement access control policies governing how access is granted based on business and security requirements. Control 5.16 (Identity Management) requires a lifecycle process for managing user identities from provisioning through deprovisioning. Control 5.17 (Authentication Information) governs management of authentication credentials. Control 5.18 (Access Rights) requires formal provisioning, review, and revocation of access rights with periodic reviews to remove unnecessary or excessive permissions. Control 8.2 (Privileged Access Rights) addresses elevated access for administrators. Control 8.3 (Information Access Restriction) requires limiting access to information and applications based on least privilege. Control 8.5 (Secure Authentication) mandates strong authentication mechanisms. Together, these controls require a comprehensive access governance program that limits access to information on a need, to, know, least, privilege basis. 

 

How does ISO 27001 address incident response and incident management? 

 

Summary: ISO 27001:2022 addresses information security incident management through Annex A Controls 5.24 through 5.28, covering the full incident lifecycle from planning and preparation through response, lessons learned, and evidence collection. 

Control 5.24 (Incident Management Planning and Preparation) requires documented incident response procedures, an assigned response team, and trained personnel who know how to identify and report security events. Control 5.25 (Assessment and Decision on Information Security Events) requires a process to determine whether events constitute incidents requiring formal response. Control 5.26 (Response to Information Security Incidents) requires a structured response covering containment, eradication, recovery, and communication with stakeholders and relevant authorities. Control 5.27 (Learning from Information Security Incidents) requires post, incident analysis and capture of lessons learned to strengthen controls and prevent recurrence. Control 5.28 (Collection of Evidence) addresses forensic evidence collection and preservation for potential legal proceedings. Organizations must document their incident response procedures, train the response team, and exercise the plan, all of which auditors verify during the certification audit. 

 

How does ISO 27001 address business continuity and disaster recovery? 

 

ISO 27001:2022 addresses the information security aspects of business continuity through Annex A Controls 5.29 and 5.30. Control 5.29 (Information Security During Disruption) requires organizations to plan how information security will be maintained during and after a disruptive event, ensuring controls remain effective when normal operations are interrupted by cyberattacks, natural disasters, or system failures. Control 5.30 (ICT Readiness for Business Continuity), one of the 11 new controls in ISO 27001:2022, requires organizations to plan, implement, maintain, and test technology system resilience to ensure critical systems can continue operating at required levels during disruption, aligned with business continuity objectives. Organizations must document ICT continuity plans, conduct regular recovery testing including backup restoration tests, and formally define recovery time objectives (how quickly systems must be restored) and recovery point objectives (how much data loss is acceptable) for critical systems. For comprehensive business continuity management beyond ISO 27001’s ICT, focused scope, organizations may additionally pursue ISO 22301. 

 

How does ISO 27001 address physical security? 

 

Summary: ISO 27001:2022 addresses physical security through 14 controls in the Physical Controls theme of Annex A (Category 7), requiring organizations to protect information processing facilities and sensitive information from unauthorized physical access, environmental hazards, and theft. 

Control 7.1 (Physical Security Perimeters) requires defined and implemented physical security perimeters around information processing facilities. Control 7.2 (Physical Entry) requires access controls, such as key cards, biometrics, or visitor management systems, to prevent unauthorized physical access to secure areas. Control 7.4 (Physical Security Monitoring), newly introduced in ISO 27001:2022, requires continuous surveillance and monitoring of secure areas. Control 7.7 (Clear Desk and Clear Screen) requires policies ensuring sensitive information is not left unattended. Control 7.8 (Equipment Siting and Protection) addresses equipment placement to minimize environmental risk exposure. Controls 7.9 (Security of Assets Off, Premises) and 7.10 (Storage Media) address the security of equipment and media used outside organizational premises. Together, these controls protect against physical threats including unauthorized access, theft, and environmental damage.

 

How does ISO 27001 address cryptography and encryption? 

 

ISO 27001:2022 addresses cryptography through Annex A Control 8.24 (Use of Cryptography), requiring organizations to define and implement a cryptography policy governing the appropriate use of encryption to protect information based on its classification and risk level. The policy must address approved encryption algorithms and minimum key lengths, requirements for encrypting data at rest (in storage) and data in transit (during transmission), cryptographic key management, including key generation, distribution, storage, rotation, and secure deletion, and specific scenarios where encryption is mandatory. Organizations must also address secure communications channels (TLS protocol versions and VPN configurations), use of public key infrastructure (PKI) and digital certificates, and, where appropriate, hardware security modules for managing cryptographic keys at high assurance levels. Auditors verify that the cryptography policy exists, is implemented, and that sensitive data is demonstrably encrypted in accordance with it, for example, through evidence of full, disk encryption on laptops, encrypted database configurations, and current TLS configurations on customer, facing systems. 

 

How does ISO 27001 address supply chain and supplier security? 

 

Summary: ISO 27001:2022 significantly strengthened supply chain security requirements compared to the 2013 version, reflecting the recognized reality that third, party relationships represent one of the most significant categories of information security risk. 

The core controls are: Control 5.19 (Information Security in Supplier Relationships), requiring a formal policy and process managing security risks across the full supplier lifecycle; Control 5.20 (Addressing Information Security Within Supplier Agreements), requiring that contracts include security obligations, data handling requirements, incident notification timelines, and audit rights; Control 5.21 (Managing Information Security in the ICT Supply Chain), addressing risks from technology and software supply chains, reflecting concerns about vulnerabilities introduced through third, party software components; Control 5.22 (Monitoring, Review, and Change Management of Supplier Services), requiring ongoing performance monitoring rather than one, time onboarding due diligence; and Control 5.23 (Information Security for Use of Cloud Services), specifically governing cloud providers. Together these controls require organizations to assess, contract with, monitor, and manage every significant third party that processes or accesses sensitive information. 

 

How does ISO 27001 address threat intelligence? 

 

ISO 27001:2022 introduced Annex A Control 5.7 (Threat Intelligence) as one of its 11 new controls, requiring organizations to gather, analyze, and act on threat intelligence relevant to their environment. Control 5.7 requires organizations to collect information about the methods and patterns attackers use (TTPs, tactics, techniques, and procedures), disclosed vulnerabilities, industry, specific threat reports, and government security advisories. Crucially, this intelligence must be used to inform the organization’s risk assessment, control selection, and incident response planning, not merely collected passively. Organizations can source threat intelligence through commercial feeds, freely available open, source intelligence (OSINT), sector, specific threat sharing groups known as ISACs (Information Sharing and Analysis Centers), and US government agencies such as CISA. This control reflects the understanding that a static risk assessment alone is insufficient, organizations need current awareness of the evolving threat landscape to maintain an effective ISMS. 

 

How does ISO 27001 address data leakage prevention? 

 

ISO 27001:2022 introduced Annex A Control 8.12 (Data Leakage Prevention) as one of its 11 new controls, formally incorporating data loss prevention (DLP) requirements into the standard for the first time. Control 8.12 requires organizations to implement controls across systems, networks, and endpoint devices that detect and prevent unauthorized disclosure or exfiltration of sensitive information. DLP measures required include: monitoring of data moving across the network, sent via email, and transferred to external locations; data classification, informed rules that block unauthorized transfer of sensitive data; and alerting mechanisms to notify security teams of potential leakage events. The control is closely linked to data classification (Control 5.12), organizations must know what data is sensitive and where it resides before DLP controls can be configured effectively. Common implementation tools include endpoint DLP agents, email gateway DLP rules, and cloud access security brokers. Auditors verify both a documented DLP policy and technical evidence of DLP controls in operation. 

 

How does ISO 27001 address cloud service security? 

 

ISO 27001:2022 introduced Annex A Control 5.23 (Information Security for Use of Cloud Services) as one of its 11 new controls, specifically addressing the security requirements for cloud computing across the full cloud service lifecycle. 

Control 5.23 requires organizations to establish processes covering: selecting cloud services through a security, informed process, establishing security requirements in cloud service agreements, managing security configurations of cloud environments, monitoring security events and performance in cloud services, and safely exiting cloud services with appropriate data migration and deletion. A core requirement is clearly documenting the shared responsibility model for each cloud provider, establishing which security controls the provider manages and which remain the organization’s responsibility. Cloud providers should be assessed through the supplier security management controls (5.19, 5.22) and evaluated for their own security certifications such as ISO 27001 or SOC 2 Type II as part of ongoing due diligence. Multi, cloud environments increase the complexity of this control but do not reduce the obligation. 

 

How does ISO 27001 address secure software development? 

 

Summary: ISO 27001:2022 introduced Control 8.28 (Secure Coding) as one of its 11 new controls, formally incorporating secure software development requirements into the standard, supported by broader development lifecycle controls in Controls 8.25 and 8.26. 

Control 8.28 requires organizations that develop software to establish and follow secure coding principles throughout the software development lifecycle (SDLC). Required practices include training developers in secure coding techniques, preventing and fixing common vulnerabilities including those in the OWASP Top 10 (such as SQL injection, cross, site scripting, and insecure authentication), conducting security, focused code reviews, and using automated testing tools. Control 8.25 (Secure Development Life Cycle) provides the broader governance framework for SDLC security, requiring defined rules across planning, design, implementation, testing, and deployment phases. Control 8.26 (Application Security Requirements) requires security requirements to be defined and incorporated into software specifications before development begins. Together, these controls require organizations to integrate security into the software development process from the start, rather than treating it as a post, deployment afterthought.

 

How does ISO 27001 address data backup and recovery? 

 

ISO 27001:2022 addresses data backup and recovery through Annex A Control 8.13 (Information Backup), requiring organizations to maintain backup copies of information, software, and system images based on a documented backup policy. The policy must define what must be backed up, backup frequency and retention periods, storage location of backups (including whether copies are held off, site or in a separate cloud region), encryption requirements for backup data, and, critically, procedures for regularly testing backup restoration to verify that backups are complete and actually recoverable. The testing requirement is essential: many organizations discover during a ransomware incident that backups were corrupted, incomplete, or could not be restored within an acceptable timeframe. Control 5.30 (ICT Readiness for Business Continuity) requires backup processes to be designed in alignment with the organization’s recovery time objective (RTO, how quickly systems must be restored) and recovery point objective (RPO, how much data loss is acceptable). Auditors review backup policies, evidence of regular execution, and restoration test records. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties