# ISO 27002:2022 Information Security Controls - Code of Practice

## Executive Summary

ISO/IEC 27002:2022 is the international code of practice for information security controls. It provides implementation guidance for information security management, supporting the requirements specified in ISO/IEC 27001. The standard contains 93 information security controls organized into four themes: Organizational, People, Physical, and Technological controls.

**Current Version:** ISO/IEC 27002:2022 (published February 2022)  
**Supersedes:** ISO/IEC 27002:2013  
**Companion to:** ISO/IEC 27001:2022 (Annex A references these controls)  
**Published by:** International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)

**Major Changes from 2013 Version:**
- Reduced from 114 controls (14 domains) to 93 controls (4 themes)
- Reorganized for better usability and modern security landscape
- Added 11 new controls addressing emerging threats
- Enhanced attributes system for better control selection
- Improved implementation guidance

---

## 1. Standard Overview

### 1.1 Purpose and Scope

ISO 27002 provides:

- **Implementation Guidance**: Practical advice on implementing information security controls
- **Best Practice Recommendations**: Industry-recognized security practices
- **Control Descriptions**: What each control aims to achieve
- **Implementation Guidance**: How to implement each control effectively
- **Reference Documentation**: Supporting ISO 27001 Annex A requirements

**Who Should Use ISO 27002:**
- Information security professionals implementing ISMS
- Organizations seeking practical security guidance
- Auditors assessing control effectiveness
- Risk managers selecting appropriate controls
- System architects designing secure systems

### 1.2 Relationship to ISO 27001

**ISO 27001 (Requirements)** ← References → **ISO 27002 (Guidance)**

```
ISO 27001 Annex A lists 93 controls (what to implement)
         ↓
ISO 27002 provides implementation guidance (how to implement)
         ↓
Organizations select applicable controls based on risk assessment
         ↓
Statement of Applicability (SoA) documents selections
```

**Key Differences:**
- ISO 27001: Certifiable standard with mandatory requirements
- ISO 27002: Guidance document, not directly certifiable
- ISO 27001: Specifies that controls must be implemented
- ISO 27002: Explains how to implement controls effectively

### 1.3 Control Attributes System

Each control in ISO 27002:2022 has five attributes to aid selection:

**1. Control Type**
- **Preventive**: Prevents security incidents before they occur
- **Detective**: Identifies security incidents during or after occurrence
- **Corrective**: Reduces impact and enables recovery from incidents

**2. Information Security Properties**
- **Confidentiality (C)**: Protects information from unauthorized disclosure
- **Integrity (I)**: Ensures accuracy and completeness of information
- **Availability (A)**: Ensures information accessible when needed

**3. Cybersecurity Concepts**
- **Identify**: Understanding security context and risks
- **Protect**: Implementing safeguards
- **Detect**: Discovering security events
- **Respond**: Taking action on detected events
- **Recover**: Restoring normal operations

**4. Operational Capabilities**
- Which organizational functions are relevant to the control
- Examples: Governance, Asset management, Protection, Defense, Resilience, etc.

**5. Security Domains**
- Governance and ecosystem
- Protection
- Defence
- Resilience

---

## 2. Organizational Controls (37 Controls)

### 5.1 Policies for Information Security

**Control Type:** Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Protect  
**Operational Capabilities:** Governance  

**Purpose:**
Provide management direction and support for information security in accordance with business requirements and relevant laws and regulations.

**Implementation Guidance:**

**Policy Framework Structure:**
```
Level 1: Information Security Policy (High-level, board-approved)
    ↓
Level 2: Domain Policies (Specific security areas)
    ↓
Level 3: Standards (Technical specifications)
    ↓
Level 4: Procedures (Step-by-step instructions)
    ↓
Level 5: Guidelines (Best practice recommendations)
```

**Essential Policy Elements:**
- Clear objectives aligned with business strategy
- Management commitment statement
- Security principles and approach
- Roles and responsibilities overview
- Compliance requirements reference
- Consequence of non-compliance
- Policy review and update procedures

**Policy Content Requirements:**
- Scope and applicability
- Effective date and version control
- Approval authority and date
- Review frequency (minimum annually)
- References to supporting documents
- Definitions of key terms
- Escalation and exception procedures

**Implementation Steps:**
1. Obtain executive sponsorship
2. Conduct gap analysis against requirements
3. Draft policy framework
4. Stakeholder consultation
5. Legal and compliance review
6. Management approval
7. Communication and training
8. Monitoring and enforcement
9. Regular review and update

**Metrics:**
- Policy review currency (% policies reviewed on schedule)
- Policy acknowledgment rate (% employees acknowledged)
- Policy exception rate
- Time from policy change to implementation

**Common Pitfalls:**
- Overly complex or technical language
- Lack of management support
- Policies not kept current
- No enforcement mechanisms
- Insufficient communication

---

### 5.2 Information Security Roles and Responsibilities

**Control Type:** Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Protect  
**Operational Capabilities:** Governance  

**Purpose:**
Define and allocate information security responsibilities throughout the organization.

**Implementation Guidance:**

**Core Security Roles:**

**1. Board of Directors / Senior Management**
- Ultimate accountability for information security
- Approve security strategy and policies
- Allocate resources
- Review security performance
- Oversee risk management

**2. Chief Information Security Officer (CISO)**
- Overall responsibility for security program
- Security strategy development
- Risk management oversight
- Incident response coordination
- Compliance management
- Security metrics reporting

**3. Information Security Manager**
- Day-to-day security operations
- Policy development and maintenance
- Security awareness programs
- Vendor security management
- Security project management

**4. Data/Information Owner**
- Classify information assets
- Define access requirements
- Approve access requests
- Review access rights periodically
- Determine retention requirements

**5. System/Application Owner**
- Security of specific systems
- Implement security controls
- User access management
- System security monitoring
- Patch and update management

**6. Security Operations Team**
- 24/7 security monitoring
- Incident detection and response
- Vulnerability management
- Security tool administration
- Log analysis

**7. All Employees**
- Follow security policies
- Protect assigned assets
- Report security incidents
- Complete security training
- Practice secure behaviors

**RACI Matrix Example:**
```
Activity                  | CISO | Sec Mgr | Sys Owner | All Staff
-------------------------|------|---------|-----------|----------
Security Policy          |  A   |    R    |     C     |     I
Access Requests          |  I   |    C    |     A/R   |     -
Incident Response        |  A   |    R    |     C     |     I
Security Training        |  A   |    R    |     -     |     R
Risk Assessment          |  R   |    R    |     C     |     I

R = Responsible, A = Accountable, C = Consulted, I = Informed
```

**Implementation Requirements:**
- Documented roles and responsibilities
- Job descriptions include security duties
- Clear escalation paths
- Separation of duties where appropriate
- Conflict of interest management
- Regular review and updates

**Metrics:**
- % of roles with defined security responsibilities
- Time to fill critical security positions
- Security accountability coverage
- Role clarity score (survey-based)

---

### 5.3 Segregation of Duties

**Control Type:** Preventive  
**Security Properties:** C, I  
**Cybersecurity Concepts:** Protect  
**Operational Capabilities:** Protection  

**Purpose:**
Reduce the risk of fraudulent, erroneous, or unauthorized actions by dividing tasks and associated privileges among multiple people.

**Implementation Guidance:**

**Key Principles:**
- No single person controls entire critical process
- Authorization separate from execution
- Custody separate from record-keeping
- Monitoring separate from operations

**Common Segregation Requirements:**

**Financial Systems:**
- Separate: Request, Approve, Execute, Record, Reconcile
- Example: Purchase requisition → approval → ordering → receiving → payment → accounting

**IT Systems:**
- Separate: Development, Testing, Production access
- Separate: Security administration, System administration
- Separate: Database administration, Application development
- Separate: Change request, Change approval, Change implementation

**Security Functions:**
- Separate: Security monitoring, Security operations
- Separate: Access provisioning, Access review
- Separate: Security audit, Security management

**Conflict Matrix Example:**
```
Role A vs Role B         | Conflict | Mitigation
------------------------|----------|---------------------------
Developer + Prod Admin  | HIGH     | Separate roles mandatory
Approver + Requester    | HIGH     | Separate roles mandatory
Admin + Auditor         | HIGH     | Separate roles mandatory
Developer + Tester      | MEDIUM   | Manager review required
Support + Development   | LOW      | Monitoring sufficient
```

**Implementation Options:**

**1. Physical Segregation**
- Different people perform different functions
- Ideal but may not be feasible in small organizations

**2. Technical Segregation**
- System-enforced separation through access controls
- Role-based access control (RBAC)
- Workflow approvals

**3. Compensating Controls** (when segregation not feasible)
- Enhanced monitoring and logging
- Management review and oversight
- Periodic audits
- Dual control requirements
- Rotation of duties

**Small Organization Approach:**
When staff limitations prevent full segregation:
- Document conflicts of interest
- Implement compensating controls
- Management review of conflicted activities
- Periodic independent reviews
- Consider outsourcing conflicted functions

**Implementation Steps:**
1. Identify critical processes and risks
2. Map current roles and access
3. Identify conflicts and risks
4. Design segregation requirements
5. Implement technical controls
6. Document exceptions and compensating controls
7. Monitor and review effectiveness

**Metrics:**
- Number of segregation violations detected
- % of critical processes with proper segregation
- Time to remediate identified conflicts
- Exception/waiver count and status

---

### 5.4 Management Responsibilities

**Control Type:** Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Protect  
**Operational Capabilities:** Governance  

**Purpose:**
Require management to support information security in accordance with policies, standards, and procedures.

**Implementation Guidance:**

**Management Security Responsibilities:**

**Strategic Level:**
- Endorse security objectives
- Allocate adequate resources
- Integrate security into business planning
- Review security performance regularly
- Provide visible security leadership

**Operational Level:**
- Ensure policy compliance in their area
- Conduct risk assessments for their domain
- Implement required security controls
- Report security incidents
- Participate in security awareness
- Support security initiatives

**Team Level:**
- Communicate security requirements to staff
- Ensure staff complete security training
- Monitor compliance with security policies
- Address security issues promptly
- Lead by example in security practices

**Management Security Activities:**

**1. Resource Allocation**
- Budget for security tools and services
- Adequate security staffing
- Training and development
- Technology investments
- Professional services when needed

**2. Performance Management**
- Include security in job descriptions
- Security objectives in performance reviews
- Recognition for good security practices
- Consequences for violations
- Security awareness assessments

**3. Risk Management**
- Identify risks in area of responsibility
- Participate in risk assessments
- Implement risk treatment plans
- Monitor residual risks
- Escalate emerging risks

**4. Incident Management**
- Recognize and report incidents
- Support incident response
- Provide resources for response
- Learn from incidents
- Implement improvements

**5. Compliance Oversight**
- Understand applicable requirements
- Ensure compliance in their area
- Address non-compliance
- Support audits and assessments
- Maintain evidence of compliance

**Management Training Requirements:**
- Information security fundamentals
- Relevant policies and procedures
- Risk management principles
- Incident recognition and reporting
- Regulatory compliance requirements
- Security leadership practices

**Documentation Requirements:**
- Management security charter
- Management security responsibilities matrix
- Escalation procedures
- Performance review templates including security
- Training completion records

**Metrics:**
- Management security training completion rate
- Management participation in security reviews
- Incident reporting rate by management
- Security objective achievement rate
- Management security assessment scores

---

### 5.5 Contact with Authorities

**Control Type:** Preventive, Detective  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Respond  
**Operational Capabilities:** Governance  

**Purpose:**
Maintain appropriate contacts with relevant authorities for incident reporting, receiving security advice, and regulatory compliance.

**Implementation Guidance:**

**Relevant Authorities:**

**1. Law Enforcement**
- Local police (cybercrime units)
- National cybercrime agencies (FBI, NCA, etc.)
- Interpol (for international incidents)
- When to contact: Criminal activity, cyberattacks, fraud, data theft

**2. Regulatory Bodies**
- Data protection authorities (DPA, ICO, CNIL, etc.)
- Financial regulators (SEC, FCA, etc.)
- Industry-specific regulators
- When to contact: Data breaches, compliance violations, reportable incidents

**3. Emergency Services**
- Fire department
- Ambulance services
- Disaster response teams
- When to contact: Physical emergencies, facility incidents, safety threats

**4. Utility Providers**
- Electricity suppliers
- Telecommunications providers
- Internet service providers
- When to contact: Service disruptions, infrastructure issues

**5. Security Organizations**
- CERT/CSIRT teams
- Industry ISACs (Information Sharing and Analysis Centers)
- Security vendors
- When to contact: Threat intelligence, vulnerability information, incident support

**6. Professional Bodies**
- ISO certification bodies
- Professional associations
- Standards organizations
- When to contact: Compliance guidance, certification issues

**Authority Contact Register:**
```
Authority Type | Organization | Contact Person | Phone | Email | When to Contact | SLA
--------------|-------------|----------------|-------|-------|----------------|-----
Law Enforce   | FBI         | Agent Smith    | ...   | ...   | Cybercrime     | N/A
Regulator     | ICO         | DPO Team       | ...   | ...   | Data Breach    | 72hrs
CERT          | National... | SOC Team       | ...   | ...   | Incident       | N/A
ISP           | Provider X  | NOC            | ...   | ...   | Service Down   | 4hrs
```

**Implementation Requirements:**

**1. Establish Relationships**
- Identify relevant authorities
- Make initial contact before incidents
- Understand reporting procedures
- Clarify expectations and requirements
- Exchange contact information
- Participate in liaison programs

**2. Maintain Contact Information**
- Central contact database
- 24/7 emergency contacts
- Alternative contact methods
- Contact verification (test periodically)
- Update when changes occur
- Include in incident response plan

**3. Define Reporting Procedures**
- What incidents require notification
- Timeframes for reporting
- Required information to provide
- Who is authorized to contact
- Escalation procedures
- Documentation requirements

**4. Regular Communication**
- Participate in information sharing programs
- Attend security briefings
- Subscribe to alerts and advisories
- Share relevant threat intelligence
- Maintain relationships

**Regulatory Reporting Requirements:**

**GDPR Data Breach Notification:**
- Authority: Supervisory authority (DPA)
- Timeframe: Within 72 hours of awareness
- Trigger: Personal data breach likely to result in risk
- Information: Nature, categories, numbers, consequences, measures

**SEC Cybersecurity Disclosure:**
- Authority: Securities and Exchange Commission
- Timeframe: 4 business days (material incidents)
- Trigger: Material cybersecurity incidents
- Information: Material impact, timing, scope

**PCI DSS Breach Notification:**
- Authority: Payment card brands, acquirer
- Timeframe: Immediately upon discovery
- Trigger: Suspected compromise of cardholder data
- Information: Forensics, impact, remediation

**Metrics:**
- Authority contact list currency
- Incident notification compliance rate
- Response time from authorities
- Number of information exchanges
- Relationship quality assessment

---

### 5.6 Contact with Special Interest Groups

**Control Type:** Preventive, Detective  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Protect, Detect  
**Operational Capabilities:** Governance  

**Purpose:**
Maintain appropriate contacts with special interest groups, security forums, and professional associations to stay informed about security trends and threats.

**Implementation Guidance:**

**Types of Special Interest Groups:**

**1. Information Sharing and Analysis Centers (ISACs)**
- Industry-specific threat intelligence sharing
- Examples: FS-ISAC (Financial), H-ISAC (Healthcare), IT-ISAC (Tech)
- Benefits: Early warning, threat intelligence, incident collaboration
- Membership requirements vary by sector

**2. Computer Emergency Response Teams (CERTs/CSIRTs)**
- National CERTs (e.g., US-CERT, CERT-UK)
- Industry CERTs
- Vendor CERTs
- Benefits: Incident response support, vulnerability notifications, best practices

**3. Professional Associations**
- (ISC)² - Information security professionals
- ISACA - IT audit and governance
- IAPP - Privacy professionals
- ISSA - Information Systems Security Association
- Benefits: Training, certification, networking, research

**4. Security Forums and Conferences**
- Black Hat, DEF CON, RSA Conference
- Industry-specific events
- Regional security meetups
- Benefits: Latest research, threat trends, peer networking

**5. Vendor Security Communities**
- Microsoft Security Response Center
- Cisco Security
- AWS Security Bulletins
- Benefits: Product-specific security updates, patches, advisories

**6. Standards Bodies**
- ISO/IEC committees
- NIST
- Cloud Security Alliance
- OWASP
- Benefits: Standards development, best practices, guidance documents

**Participation Strategy:**

**Formal Membership:**
- Join relevant ISACs for your industry
- Professional association memberships
- Vendor partner programs
- Standards committee participation

**Information Consumption:**
- Subscribe to security mailing lists
- Follow threat intelligence feeds
- Monitor security research publications
- Attend webinars and conferences

**Active Contribution:**
- Share anonymized threat intelligence
- Participate in working groups
- Present at conferences
- Contribute to open source security projects
- Publish security research

**Information Sharing Framework:**

**What to Share:**
- Threat indicators (IoCs)
- Attack methodologies (TTPs)
- Vulnerability information
- Lessons learned from incidents
- Best practices and controls

**What NOT to Share:**
- Confidential business information
- Customer personal data
- Trade secrets
- Information prohibited by contracts
- Classified information

**Sharing Protocols:**
- Use Traffic Light Protocol (TLP):
  - TLP:CLEAR (White) - Can be shared publicly
  - TLP:GREEN - Community-wide distribution
  - TLP:AMBER - Limited distribution
  - TLP:AMBER+STRICT - Very limited distribution
  - TLP:RED - Recipients only, cannot be shared

**Implementation Requirements:**

**1. Membership Management**
- Identify relevant groups for organization
- Evaluate membership benefits and costs
- Obtain management approval
- Designate representatives
- Track memberships and renewals

**2. Information Management**
- Centralize threat intelligence
- Disseminate to relevant teams
- Act on critical information promptly
- Maintain confidentiality per agreements
- Archive for future reference

**3. Participation Governance**
- Define what can be shared externally
- Approval process for information sharing
- Legal review of sharing agreements
- Confidentiality agreements
- Record of shared information

**4. Value Measurement**
- Track actionable intelligence received
- Measure incident prevention from shared intelligence
- Cost-benefit analysis of memberships
- Survey participant satisfaction

**Program Structure:**
```
Threat Intelligence Program
    ↓
Join ISACs + Professional Groups + Vendor Communities
    ↓
Collect Intelligence → Analyze → Disseminate → Act
    ↓
Share Back (Anonymized) → Build Community Value
    ↓
Measure Effectiveness → Adjust Participation
```

**Metrics:**
- Number of relevant groups joined
- Threat intelligence items received and actioned
- Incidents prevented through early warning
- Member participation rate
- ROI on membership costs

---

### 5.7 Threat Intelligence

**Control Type:** Detective, Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Detect, Protect  
**Operational Capabilities:** Defence  

**Purpose:**
Collect and analyze threat intelligence to understand the threat landscape and proactively defend against threats.

**Implementation Guidance:**

**Threat Intelligence Types:**

**1. Strategic Threat Intelligence**
- High-level trends and motivations
- Geopolitical factors
- Industry targeting
- Threat actor profiles
- Used by: Executives, Board, Risk Management

**2. Tactical Threat Intelligence**
- TTPs (Tactics, Techniques, Procedures)
- Attack patterns and methodologies
- Threat actor capabilities
- Campaign information
- Used by: Security Teams, SOC, Incident Response

**3. Operational Threat Intelligence**
- Specific campaigns and attacks
- Threat actor activities
- Targeted organizations
- Attack timelines
- Used by: SOC, Threat Hunters, IR Teams

**4. Technical Threat Intelligence**
- Indicators of Compromise (IoCs)
- IP addresses, domains, hashes
- Malware samples and signatures
- Vulnerability information
- Used by: Security Tools, SIEM, EDR, Firewalls

**Threat Intelligence Sources:**

**Open Source Intelligence (OSINT):**
- Public threat feeds (AlienVault OTX, Abuse.ch, etc.)
- Security blogs and research
- Vulnerability databases (CVE, NVD)
- Social media and forums
- Dark web monitoring
- Cost: Free
- Quality: Variable, requires validation

**Commercial Intelligence:**
- Vendor threat feeds (Recorded Future, Mandiant, etc.)
- Threat intelligence platforms
- Industry reports
- Managed intelligence services
- Cost: Subscription-based
- Quality: High, validated, contextualized

**Community Sharing:**
- ISAC feeds
- Industry partnerships
- CERT notifications
- Peer organization sharing
- Cost: Membership fees
- Quality: Relevant to industry

**Internal Intelligence:**
- Security logs and events
- Incident response findings
- Honeypots and deception tech
- Vulnerability scans
- Penetration test results
- Cost: Operational costs
- Quality: Highly relevant to organization

**Threat Intelligence Lifecycle:**

```
1. Planning & Direction
   - Define intelligence requirements (PIR/EEI)
   - Identify threat priorities
   - Determine collection needs
        ↓
2. Collection
   - Gather data from sources
   - OSINT, commercial feeds, internal logs
   - Automated and manual collection
        ↓
3. Processing
   - Normalize data formats
   - Deduplicate information
   - Enrich with context
   - Correlate across sources
        ↓
4. Analysis
   - Identify patterns and trends
   - Assess relevance and priority
   - Validate indicators
   - Create actionable intelligence
        ↓
5. Dissemination
   - Distribute to relevant teams
   - Appropriate format for audience
   - Timely delivery
   - Secure channels
        ↓
6. Feedback
   - Assess intelligence value
   - Refine requirements
   - Improve process
   - Loop back to Planning
```

**Threat Intelligence Platform (TIP) Capabilities:**

**Core Functions:**
- Aggregate data from multiple sources
- Normalize and enrich indicators
- Correlate and deduplicate
- Store in centralized repository
- API integration with security tools

**Analysis Features:**
- Threat scoring and prioritization
- Relationship mapping
- Campaign tracking
- Attribution analysis
- Visualization dashboards

**Integration Points:**
- SIEM (push indicators for detection)
- Firewalls and IDS/IPS (block malicious IPs/domains)
- EDR (identify compromised endpoints)
- Email security (block malicious senders/links)
- Web proxy (block malicious URLs)
- Threat hunting tools

**Implementation Framework:**

**Phase 1: Foundation (Months 1-3)**
- Define threat intelligence requirements
- Identify free and commercial sources
- Establish collection mechanisms
- Set up basic TIP or repository

**Phase 2: Integration (Months 4-6)**
- Integrate feeds with security tools
- Automate indicator blocking
- Create alert rules in SIEM
- Establish analysis workflows

**Phase 3: Maturation (Months 7-12)**
- Hire or train threat intelligence analysts
- Develop custom intelligence collection
- Participate in intelligence sharing
- Advanced hunting and analysis

**Phase 4: Optimization (Ongoing)**
- Continuous improvement of sources
- Advanced analytics and ML
- Predictive intelligence
- Strategic intelligence program

**MITRE ATT&CK Framework Integration:**
- Map threats to ATT&CK TTPs
- Prioritize defenses based on relevant TTPs
- Guide threat hunting activities
- Measure coverage of detection rules
- Communicate threats in standard language

**Key Performance Indicators:**

**Collection Metrics:**
- Number of intelligence sources
- Volume of indicators collected
- Indicator freshness (age)
- Source reliability score

**Analysis Metrics:**
- Time to process intelligence
- False positive rate
- Indicators validated and actioned
- Intelligence reports produced

**Action Metrics:**
- Indicators blocked at perimeter
- Threats detected early
- Incidents prevented
- Time from intelligence to action

**Value Metrics:**
- Cost avoidance from prevented incidents
- Reduction in dwell time
- Improvement in detection rate
- ROI on TIP investment

**Best Practices:**
- Automate collection and processing
- Focus on actionable intelligence
- Tailor intelligence to audience
- Integrate with incident response
- Measure and demonstrate value
- Share intelligence responsibly
- Maintain operational security
- Continuous learning and improvement

---

### 5.8 Information Security in Project Management

**Control Type:** Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify, Protect  
**Operational Capabilities:** Protection  

**Purpose:**
Integrate information security into project management to ensure security is addressed throughout the project lifecycle.

**Implementation Guidance:**

**Security in Project Lifecycle:**

```
Project Initiation
├─ Security requirements identification
├─ Initial security risk assessment
├─ Security budget allocation
└─ Security resource planning
    ↓
Project Planning
├─ Detailed security requirements
├─ Security architecture design
├─ Privacy impact assessment
├─ Compliance requirements analysis
├─ Security testing plan
└─ Security acceptance criteria
    ↓
Project Execution
├─ Security control implementation
├─ Secure coding practices
├─ Security code reviews
├─ Configuration management
└─ Security testing
    ↓
Project Closure
├─ Security acceptance testing
├─ Security documentation
├─ Transition to operations
├─ Security training
└─ Lessons learned
```

**Security Requirements Integration:**

**Functional Security Requirements:**
- Authentication mechanisms
- Authorization and access control
- Encryption requirements
- Audit logging
- Data protection
- Session management
- Error handling

**Non-Functional Security Requirements:**
- Performance under attack
- Security scalability
- Availability and resilience
- Security maintainability
- Compliance with standards
- Security usability

**Requirements Documentation:**
- User stories with security acceptance criteria
- Security use cases and abuse cases
- Threat models
- Security architecture documentation
- Data flow diagrams with trust boundaries

**Security Roles in Projects:**

**Project Manager:**
- Ensure security integrated into project plan
- Allocate security resources and budget
- Track security tasks and milestones
- Escalate security issues
- Report security status

**Security Architect:**
- Define security architecture
- Review designs for security
- Approve security controls
- Guide implementation
- Conduct security reviews

**Security Engineer:**
- Implement security controls
- Configure security tools
- Conduct security testing
- Remediate vulnerabilities
- Document security configuration

**Developer:**
- Follow secure coding standards
- Implement security requirements
- Participate in code reviews
- Fix security defects
- Unit test security functions

**QA/Tester:**
- Execute security test cases
- Perform vulnerability testing
- Verify security requirements
- Report security defects
- Regression test security fixes

**Security Gates/Checkpoints:**

**Gate 1: Project Initiation**
- Security requirements identified: □
- Initial risk assessment completed: □
- Security budget approved: □
- Security resources assigned: □
- Approval to proceed: □

**Gate 2: Design Complete**
- Security architecture reviewed: □
- Threat model completed: □
- Privacy impact assessment done: □
- Security controls designed: □
- Approval to build: □

**Gate 3: Development Complete**
- Code security reviews done: □
- Security testing completed: □
- Vulnerabilities remediated: □
- Security documentation complete: □
- Approval to deploy: □

**Gate 4: Deployment Ready**
- Security acceptance testing passed: □
- Security configuration verified: □
- Operations team trained: □
- Incident response plan ready: □
- Approval to release: □

**Security Assessment Activities:**

**Threat Modeling:**
- Identify assets and threats
- Use STRIDE or PASTA methodology
- Document threats and mitigations
- Prioritize based on risk
- Update as project evolves

**Security Architecture Review:**
- Review system design
- Identify security gaps
- Evaluate control effectiveness
- Check compliance with standards
- Document findings and recommendations

**Secure Code Review:**
- Manual code inspection
- Automated static analysis (SAST)
- Focus on security-critical code
- Check against secure coding standards
- Track and remediate findings

**Security Testing:**
- Dynamic application security testing (DAST)
- Penetration testing
- Fuzzing
- Authentication and authorization testing
- Encryption verification
- Security configuration testing

**Agile/DevOps Integration:**

**Sprint Planning:**
- Include security user stories
- Estimate security tasks
- Identify security dependencies
- Allocate security resources

**Sprint Execution:**
- Daily security check-ins
- Continuous security testing
- Automated security scans in CI/CD
- Security peer reviews

**Sprint Review:**
- Demo security features
- Security acceptance review
- Update security backlog

**Sprint Retrospective:**
- Review security practices
- Identify security improvements
- Update security standards

**DevSecOps Practices:**
- Security as code
- Automated security testing in pipeline
- Continuous security monitoring
- Rapid remediation
- Security metrics in dashboards

**Project Security Documentation:**

**Required Documents:**
- Security requirements specification
- Security architecture document
- Threat model
- Privacy impact assessment
- Security test plan and results
- Security configuration guide
- Security operations manual
- Incident response procedures
- Security training materials

**Metrics:**
- % of projects with security requirements
- Security gate compliance rate
- Security defects by severity
- Time to remediate security issues
- Security test coverage
- Cost of security in projects

---

### 5.9 Inventory of Information and Other Associated Assets

**Control Type:** Preventive, Detective  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Identify  
**Operational Capabilities:** Governance  

**Purpose:**
Identify, document, and maintain an inventory of information and other assets associated with information systems and processing facilities.

**Implementation Guidance:**

**Asset Categories:**

**1. Information Assets**
- Databases (customer, financial, operational)
- Documents (contracts, designs, plans)
- System documentation
- Research and intellectual property
- Archives and backups
- Authentication credentials

**2. Software Assets**
- Operating systems
- Business applications
- Utilities and tools
- Development tools
- Mobile applications
- Firmware

**3. Hardware Assets**
- Servers (physical and virtual)
- Network devices (routers, switches, firewalls)
- End-user devices (desktops, laptops, mobile)
- IoT devices
- Storage devices
- Removable media

**4. Network Assets**
- Network segments and VLANs
- Wireless networks
- VPN connections
- Internet connections
- Cloud connectivity

**5. Services**
- Cloud services (SaaS, PaaS, IaaS)
- Outsourced services
- Support and maintenance contracts
- Professional services

**6. People**
- Employees and contractors
- Administrators
- Key personnel
- Third-party staff

**7. Intangible Assets**
- Brand and reputation
- Knowledge and expertise
- Business processes
- Relationships

**Asset Inventory Attributes:**

**Essential Attributes:**
- Unique asset identifier
- Asset name and description
- Asset type/category
- Location (physical/logical)
- Owner (responsible party)
- Custodian (who manages it)
- Classification level
- Criticality/importance
- Status (active, retired, in development)
- Acquisition date
- Lifecycle stage

**Extended Attributes:**
- Dependencies (what it relies on)
- Dependents (what relies on it)
- Supported processes
- Compliance requirements
- Maintenance schedule
- Support contacts
- Cost/value
- Risk rating
- Last update date

**Asset Classification:**

**Confidentiality Levels:**
- Public: Can be freely disclosed
- Internal: Internal use only
- Confidential: Limited distribution
- Restricted/Secret: Highly sensitive
- Top Secret: Mission-critical sensitive

**Integrity Levels:**
- Low: Minor impact if modified
- Medium: Significant impact
- High: Critical accuracy required
- Critical: Life/safety or financial critical

**Availability Levels:**
- Low: Days to recover acceptable
- Medium: Hours to recover required
- High: Minutes to recover required
- Critical: No downtime acceptable (HA required)

**Asset Inventory Methods:**

**Automated Discovery:**
- Network scanning tools
- Asset management systems
- Configuration management databases (CMDB)
- Software asset management (SAM) tools
- Cloud asset management tools
- Mobile device management (MDM)

**Manual Documentation:**
- Physical inventory audits
- Stakeholder interviews
- Document reviews
- Process mapping
- Contract reviews

**Integration Points:**
- IT service management (ITSM)
- Configuration management
- Vulnerability management
- Change management
- Incident management
- Financial asset tracking

**Asset Lifecycle Management:**

```
Acquisition
├─ Identify need
├─ Obtain approval
├─ Procure asset
├─ Register in inventory
└─ Assign owner
    ↓
Deployment
├─ Configure securely
├─ Apply baseline
├─ Assign to user/location
└─ Update inventory
    ↓
Operations
├─ Monitor and maintain
├─ Update as changes occur
├─ Regular inventory verification
└─ Periodic recertification
    ↓
Retirement
├─ Decommission properly
├─ Sanitize data
├─ Update inventory status
├─ Dispose securely
└─ Document disposal
```

**Asset Register Example:**

```
Asset ID | Name | Type | Owner | Classification | Location | Status | Last Verified
---------|------|------|-------|---------------|----------|--------|---------------
DB-001   | CRM  | DB   | Sales | Confidential  | AWS-US   | Active | 2025-10-01
SRV-023  | Mail | Svr  | IT    | Internal      | DC1      | Active | 2025-10-01
DOC-456  | Plan | Doc  | Exec  | Restricted    | SharePt  | Active | 2025-09-15
```

**Implementation Requirements:**

**Governance:**
- Asset inventory policy
- Asset owner responsibilities
- Inventory update procedures
- Regular review requirements
- Exception process

**Process:**
- Initial inventory creation
- Ongoing maintenance process
- Change integration
- Periodic verification (e.g., quarterly)
- Decommissioning procedures

**Technology:**
- Asset inventory tool/database
- Integration with discovery tools
- Reporting capabilities
- Access controls
- Audit logging

**Roles:**
- Asset owners (business responsibility)
- Custodians (technical management)
- Inventory administrators (maintain database)
- Auditors (verify accuracy)

**Inventory Accuracy Measures:**
- Reconciliation with financial asset register
- Physical verification sampling
- Discovery tool validation
- User attestation
- Surprise audits

**Integration with Risk Management:**
- Use inventory as basis for risk assessment
- Identify critical assets for protection
- Prioritize security investments
- Focus monitoring on high-value assets
- Plan business continuity based on dependencies

**Metrics:**
- Inventory completeness (% assets registered)
- Inventory accuracy (% correct information)
- Asset owner assignment (% assets with owners)
- Update timeliness (time from change to update)
- Verification compliance (% verified on schedule)
- Unknown assets discovered in scans

**Common Challenges:**
- Shadow IT (unmanaged assets)
- Cloud service sprawl
- BYOD and personal devices
- IoT proliferation
- Transient development environments
- Third-party hosted assets

**Best Practices:**
- Automate discovery where possible
- Integrate with existing tools
- Make inventory accessible to stakeholders
- Regular reconciliation
- Clear ownership assignment
- Lifecycle integration
- Cloud and on-premise coverage
- Include third-party hosted assets

---

### 5.10 Acceptable Use of Information and Other Associated Assets

**Control Type:** Preventive  
**Security Properties:** C, I, A  
**Cybersecurity Concepts:** Protect  
**Operational Capabilities:** Protection  

**Purpose:**
Identify, document, and implement rules for acceptable use of information and assets to prevent unauthorized use and security incidents.

**Implementation Guidance:**

**Acceptable Use Policy (AUP) Components:**

**1. Scope and Applicability**
- Who: All employees, contractors, partners, third parties
- What: All information assets and systems
- When: At all times, on/off premises
- Where: Corporate and personal devices for business use

**2. Acceptable Uses**
- Business purposes as assigned
- Incidental personal use (if permitted, with limits)
- Professional development (if approved)
- Authorized testing and research

**3. Prohibited Uses**
- Unauthorized access or disclosure
- Personal gain or commercial activity
- Illegal activities
- Harassment or discrimination
- Circumventing security controls
- Installing unauthorized software
- Sharing credentials
- Excessive personal use
- Resource-intensive activities (gaming, crypto mining)
- Prohibited content (adult, violent, discriminatory)

**Specific Policy Areas:**

**Email Use:**
Acceptable:
- Business communication
- Professional external communication
- Limited personal use (lunch arrangements, emergency)

Prohibited:
- Chain letters, spam, jokes (excessive)
- Political or religious solicitation
- Confidential information to personal accounts
- Auto-forwarding to external accounts
- Mass distribution without approval

**Internet Use:**
Acceptable:
- Business research
- Professional development
- Reasonable personal use during breaks

Prohibited:
- Illegal downloads
- Prohibited content access
- Excessive streaming
- P2P file sharing
- Bypassing content filters
- Visiting malicious sites

**Social Media:**
Acceptable:
- Official business accounts (authorized)
- Professional networking (LinkedIn)
- Personal accounts (off-hours, own devices)

Prohibited:
- Posting confidential information
- Speaking on behalf of company (unauthorized)
- Harassment or unprofessional content
- Disclosing vulnerabilities
- Sharing proprietary information

**Mobile Device Use:**
Acceptable:
- Approved personal devices (BYOD)
- Company-issued devices
- Secure access to corporate resources
- Business applications

Prohibited:
- Jailbreaking/rooting devices
- Storing confidential data on personal devices (without encryption)
- Sharing devices with unauthorized users
- Removing security controls
- Using unauthorized apps with corporate data

**Removable Media:**
Acceptable:
- Approved encrypted USB drives
- Business purpose only
- Registered devices
- Scanned for malware

Prohibited:
- Unknown or untrusted devices
- Personal USB drives for business data
- Unencrypted sensitive data
- Unauthorized data transfer

**Cloud Services:**
Acceptable:
- Approved cloud services (sanctioned list)
- Company accounts only
- Data classification appropriate for service

Prohibited:
- Unauthorized cloud storage (shadow IT)
- Personal cloud accounts for business data
- Storing restricted data in unapproved services
- Sharing confidential data via unapproved services

**AI and Generative AI Tools:**
Acceptable:
- Approved AI tools (enterprise licenses)
- Non-confidential data only
- Following AI use policy
- Appropriate oversight and review

Prohibited:
- Entering confidential data into public AI tools
- Using AI to make decisions without human oversight
- Unauthorized AI tools
- Relying on AI outputs without verification
- Creating deepfakes or misleading content

**Remote Access:**
Acceptable:
- Approved VPN and remote access tools
- Secure home networks
- Company-issued or approved devices
- Following remote work security policy

Prohibited:
- Using unsecured networks without VPN
- Allowing family/friends to use business devices
- Accessing from untrusted locations
- Leaving devices unattended
- Sharing VPN credentials

**Data Handling:**
Acceptable:
- Access data per business need
- Protect per classification
- Encrypt sensitive data
- Secure disposal when done

Prohibited:
- Accessing data out of curiosity
- Sharing without authorization
- Storing in unauthorized locations
- Copying to personal devices
- Retaining after no longer needed

**Implementation Requirements:**

**1. Policy Development**
- Comprehensive coverage of assets and uses
- Clear language, avoid technical jargon
- Specific examples of acceptable and prohibited
- Proportionate to risks
- Regular updates for new technologies

**2. Communication and Training**
- Include in employee onboarding
- Annual refresher training
- Prominent posting (intranet)
- Summary reference cards
- Just-in-time reminders
- Management emphasis

**3. Acknowledgment**
- Annual policy acknowledgment required
- Electronic signature and tracking
- Record retention
- New hire acknowledgment
- Post-update acknowledgment

**4. Monitoring and Enforcement**
- Automated monitoring tools
- Data Loss Prevention (DLP)
- Web filtering
- Email filtering
- User activity monitoring
- Anomaly detection

**5. Enforcement and Consequences**
- Progressive discipline
- Verbal warning
- Written warning
- Suspension
- Termination
- Legal action (for serious violations)

**6. Exception Process**
- Request and approval workflow
- Business justification required
- Risk assessment
- Compensating controls
- Time-limited exceptions
- Regular review

**Monitoring Technologies:**

**Data Loss Prevention (DLP):**
- Monitor data in motion (email, web, cloud)
- Monitor data at rest (endpoints, servers, cloud)
- Monitor data in use (applications, copy/paste)
- Alert or block policy violations

**User and Entity Behavior Analytics (UEBA):**
- Baseline normal user behavior
- Detect anomalies (unusual access, time, location)
- Alert on risky behaviors
- Support investigations

**Web Filtering:**
- Block prohibited categories
- Allow business-appropriate sites
- Log all web access
- Report on usage patterns

**Email Security:**
- Scan for sensitive data
- Block prohibited content
- Detect and quarantine threats
- Monitor for policy violations

**Endpoint Detection and Response (EDR):**
- Monitor endpoint activities
- Detect suspicious behaviors
- Block malicious actions
- Provide forensic data

**Balancing Privacy and Monitoring:**
- Clear notification that monitoring occurs
- Legitimate business purpose
- Proportionate to risk
- Respect local privacy laws
- Limit personal data collection
- Secure monitoring data
- Limited access to monitoring data
- Regular review of monitoring scope

**User Awareness Messages:**

**Login Banners:**
"This system is for authorized use only. All activity is monitored and logged. Unauthorized use may result in disciplinary action and prosecution."

**Email Signatures:**
"Company email is for business use. This email may be monitored per company policy."

**Periodic Reminders:**
"Reminder: Follow our Acceptable Use Policy when using company resources."

**Metrics:**
- Policy acknowledgment rate
- Training completion rate
- Policy violation incidents
- Violation by type and user
- Average time to detect violations
- Repeat violators
- Exception requests and approvals

---

[Due to length constraints, I'll continue with a structured summary of remaining controls. The full document would include this level of detail for all 93 controls]

## 3. People Controls (8 Controls)

### 6.1 Screening
### 6.2 Terms and Conditions of Employment
### 6.3 Information Security Awareness, Education and Training
### 6.4 Disciplinary Process
### 6.5 Responsibilities After Termination or Change of Employment
### 6.6 Confidentiality or Non-Disclosure Agreements
### 6.7 Remote Working
### 6.8 Information Security Event Reporting

## 4. Physical Controls (14 Controls)

### 7.1 Physical Security Perimeters
### 7.2 Physical Entry
### 7.3 Securing Offices, Rooms and Facilities
### 7.4 Physical Security Monitoring
### 7.5 Protecting Against Physical and Environmental Threats
### 7.6 Working in Secure Areas
### 7.7 Clear Desk and Clear Screen
### 7.8 Equipment Siting and Protection
### 7.9 Security of Assets Off-Premises
### 7.10 Storage Media
### 7.11 Supporting Utilities
### 7.12 Cabling Security
### 7.13 Equipment Maintenance
### 7.14 Secure Disposal or Re-use of Equipment

## 5. Technological Controls (34 Controls)

### 8.1 User Endpoint Devices
### 8.2 Privileged Access Rights
### 8.3 Information Access Restriction
### 8.4 Access to Source Code
### 8.5 Secure Authentication
### 8.6 Capacity Management
### 8.7 Protection Against Malware
### 8.8 Management of Technical Vulnerabilities
### 8.9 Configuration Management
### 8.10 Information Deletion
### 8.11 Data Masking
### 8.12 Data Leakage Prevention
### 8.13 Information Backup
### 8.14 Redundancy of Information Processing Facilities
### 8.15 Logging
### 8.16 Monitoring Activities
### 8.17 Clock Synchronization
### 8.18 Use of Privileged Utility Programs
### 8.19 Installation of Software on Operational Systems
### 8.20 Networks Security
### 8.21 Security of Network Services
### 8.22 Segregation of Networks
### 8.23 Web Filtering
### 8.24 Use of Cryptography
### 8.25 Secure Development Life Cycle
### 8.26 Application Security Requirements
### 8.27 Secure System Architecture and Engineering Principles
### 8.28 Secure Coding
### 8.29 Security Testing in Development and Acceptance
### 8.30 Outsourced Development
### 8.31 Separation of Development, Test and Production Environments
### 8.32 Change Management
### 8.33 Test Information
### 8.34 Protection of Information Systems During Audit Testing

---

## 6. Control Attributes Reference Matrix

| Control | Type | Security Props | Cyber Concepts | Automation Potential |
|---------|------|---------------|----------------|---------------------|
| 5.1 | Preventive | C,I,A | Identify, Protect | Low |
| 5.2 | Preventive | C,I,A | Identify, Protect | Low |
| 5.3 | Preventive | C,I | Protect | Medium |
| 5.7 | Detective, Preventive | C,I,A | Identify, Detect, Protect | High |
| 5.9 | Preventive, Detective | C,I,A | Identify | High |
| 5.10 | Preventive | C,I,A | Protect | Medium |
| 6.3 | Preventive | C,I,A | Protect | Medium |
| 7.1 | Preventive | C,I,A | Protect | Low |
| 7.4 | Detective | C,I,A | Detect | High |
| 8.1 | Preventive | C,I,A | Protect | High |
| 8.2 | Preventive | C,I | Protect | High |
| 8.5 | Preventive | C,I | Protect | High |
| 8.7 | Preventive, Detective | C,I,A | Protect, Detect | High |
| 8.9 | Preventive | C,I,A | Protect | High |
| 8.15 | Detective | C,I,A | Detect | High |
| 8.16 | Detective | C,I,A | Detect | High |
| 8.24 | Preventive | C,I | Protect | High |
| 8.28 | Preventive | C,I,A | Protect | Medium |

---

## 7. Implementation Framework

### 7.1 Control Selection Process

**Step 1: Identify Applicable Controls**
- Start with all 93 Annex A controls
- Consider risk assessment results
- Review regulatory requirements
- Assess business context

**Step 2: Applicability Assessment**
- Determine if control is applicable
- Document justification for exclusion
- Consider dependencies
- Evaluate feasibility

**Step 3: Implementation Planning**
- Define implementation approach
- Allocate resources
- Set timeline
- Assign responsibilities

**Step 4: Implementation**
- Deploy controls per plan
- Document implementation
- Train personnel
- Test effectiveness

**Step 5: Verification**
- Verify implementation
- Test control operation
- Document evidence
- Address gaps

### 7.2 Implementation Priorities

**Tier 1: Foundation Controls (Implement First)**
- 5.1 - Policies
- 5.2 - Roles and responsibilities
- 5.9 - Asset inventory
- 6.3 - Security awareness training
- 8.5 - Authentication
- 8.7 - Anti-malware
- 8.15 - Logging
- 8.16 - Monitoring

**Tier 2: Critical Security Controls**
- 5.7 - Threat intelligence
- 8.2 - Privileged access
- 8.3 - Access restriction
- 8.8 - Vulnerability management
- 8.9 - Configuration management
- 8.13 - Backup
- 8.20 - Network security
- 8.24 - Cryptography

**Tier 3: Enhanced Protection**
- 5.3 - Segregation of duties
- 7.1-7.14 - Physical controls
- 8.11 - Data masking
- 8.12 - DLP
- 8.22 - Network segregation
- 8.25-8.30 - Secure development

**Tier 4: Advanced and Specialized**
- 5.6 - Special interest groups
- 8.4 - Source code access
- 8.11 - Data masking
- 8.23 - Web filtering
- 8.30 - Outsourced development

---

## 8. Control Measurement and Metrics

### 8.1 Control Effectiveness Metrics

**Preventive Control Metrics:**
- Incident prevention rate
- Policy compliance rate
- Configuration compliance rate
- Patch compliance rate
- Training completion rate

**Detective Control Metrics:**
- Mean time to detect (MTTD)
- Detection rate
- False positive rate
- Alert volume
- Coverage percentage

**Corrective Control Metrics:**
- Mean time to respond (MTTR)
- Mean time to remediate
- Recovery time objective (RTO) achievement
- Recovery point objective (RPO) achievement

### 8.2 Control Maturity Assessment

**Level 0: Non-existent**
- Control not implemented
- No awareness of need

**Level 1: Initial/Ad-hoc**
- Control implemented on case-by-case basis
- No standardized approach
- Reactive rather than proactive

**Level 2: Repeatable**
- Control implementation follows procedures
- Some standardization
- Not consistently applied

**Level 3: Defined**
- Control fully documented
- Standardized across organization
- Consistently applied

**Level 4: Managed**
- Control effectiveness measured
- Metrics tracked
- Management oversight

**Level 5: Optimized**
- Continuous improvement
- Automated where possible
- Industry-leading practices

---

## 9. Integration with Frameworks

### 9.1 NIST Cybersecurity Framework Mapping

| NIST CSF Function | ISO 27002 Controls |
|-------------------|-------------------|
| Identify | 5.1, 5.2, 5.7, 5.9, Risk assessment |
| Protect | 5.10, 6.1-6.8, 7.1-7.14, 8.1-8.4, 8.7, 8.9, 8.24 |
| Detect | 5.7, 7.4, 8.7, 8.15, 8.16 |
| Respond | 5.5, 6.8, Incident management |
| Recover | 8.13, 8.14, Business continuity |

### 9.2 CIS Critical Security Controls Mapping

| CIS Control | ISO 27002 Controls |
|-------------|-------------------|
| CIS 1: Asset Inventory | 5.9 |
| CIS 2: Software Inventory | 5.9, 8.19 |
| CIS 3: Data Protection | 8.10, 8.11, 8.24 |
| CIS 4: Secure Configuration | 8.9 |
| CIS 5: Account Management | 8.2, 8.5 |
| CIS 6: Access Control | 8.3, 8.4 |
| CIS 7: Continuous Vulnerability Management | 8.8 |
| CIS 8: Audit Log Management | 8.15, 8.16 |

### 9.3 GDPR Article 32 Security Mapping

| GDPR Requirement | ISO 27002 Controls |
|-----------------|-------------------|
| Pseudonymisation and encryption | 8.11, 8.24 |
| Confidentiality | 8.2, 8.3, 8.5 |
| Integrity | 8.9, 8.28 |
| Availability | 8.6, 8.13, 8.14 |
| Resilience | 8.14, Business continuity |
| Testing and assessment | Audit controls |

---

## 10. Documentation Requirements

### 10.1 Control Documentation Template

For each implemented control, document:

**Control Information:**
- Control number and name
- Control type and attributes
- Applicability status
- Implementation status

**Implementation Details:**
- Implementation approach
- Responsible parties
- Tools and technologies used
- Procedures and processes
- Integration points

**Evidence:**
- Configuration documentation
- Logs and records
- Training records
- Test results
- Audit trails

**Effectiveness:**
- Metrics and KPIs
- Measurement results
- Continuous improvement activities

### 10.2 Statement of Applicability (SoA)

The SoA must include for each control:
- Control number and name
- Inclusion/exclusion decision
- Justification for decision
- Implementation status
- Reference to implementing procedures

---

## 11. Compliance Checklist

### 11.1 Organizational Controls Checklist

- [ ] 5.1: Information security policies documented and approved
- [ ] 5.2: Roles and responsibilities defined and assigned
- [ ] 5.3: Segregation of duties implemented where required
- [ ] 5.4: Management responsibilities established
- [ ] 5.5: Authority contacts maintained
- [ ] 5.6: Special interest group participation
- [ ] 5.7: Threat intelligence program operational
- [ ] 5.8: Security in project management
- [ ] 5.9: Asset inventory maintained
- [ ] 5.10: Acceptable use policy implemented

[Continues for all 93 controls...]

---

## 12. References and Resources

### 12.1 Primary Standards
- ISO/IEC 27002:2022 - Information security controls
- ISO/IEC 27001:2022 - ISMS requirements
- ISO/IEC 27003 - ISMS implementation guidance
- ISO/IEC 27005 - Information security risk management

### 12.2 Supporting Standards
- ISO/IEC 27017 - Cloud security controls
- ISO/IEC 27018 - Cloud privacy controls
- ISO/IEC 27701 - Privacy information management
- ISO/IEC 29100 - Privacy framework

### 12.3 Regulatory References
- GDPR (EU) 2016/679
- HIPAA Security Rule
- PCI DSS v4.0
- SOX Section 404
- NIST SP 800-53
- CIS Controls v8

---

## Document Control

**Document Version:** 1.0  
**Last Updated:** October 2025  
**Next Review Date:** October 2026  
**Document Owner:** Information Security Department  
**Classification:** Internal Use

**Revision History:**

| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | Oct 2025 | Security Team | Initial ISO 27002:2022 comprehensive document |

---

## Appendix A: Control Quick Reference

### New Controls in 2022 Version

**5.7** Threat intelligence (NEW)  
**5.23** Information security for use of cloud services (NEW)  
**5.30** ICT readiness for business continuity (NEW)  
**7.4** Physical security monitoring (ENHANCED)  
**8.9** Configuration management (ENHANCED)  
**8.10** Information deletion (NEW)  
**8.11** Data masking (NEW)  
**8.12** Data leakage prevention (NEW)  
**8.16** Monitoring activities (ENHANCED)  
**8.23** Web filtering (NEW)  
**8.28** Secure coding (NEW)

### Controls Removed/Merged from 2013 Version

Removed or consolidated into other controls:
- Mobile device policy (merged into 8.1)
- Teleworking (merged into 6.7)
- Electronic messaging (covered in 5.10)
- Many others reorganized for better structure

---

*This document provides comprehensive implementation guidance for ISO 27002:2022 information security controls. Organizations should adapt guidance to their specific context, risk profile, and operational requirements.*