

ISO27001:2022 Annex A
New Controls Guidance
What you need to consider during implementation
5.7 Threat Intelligence
Purpose
To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken.
Governance Considerations
The standard expects organisations to analyse threats in 3 layers
- Strategic - focused on understanding changes in the landscape
- Tactical - focused on attacker methodologies, tools and technologies
- Operational - focused on specific attacks and their indicators
Vendor Solution Considerations
Any vendor solution implemented will need to be able to
- Categorise threats against objectives
- Identify, collect and filter from different information sources
- Process the information for analysis
- Provide meaningful, actionable insights
- Provide a mechanism to communicate and share insights
5.23 Information security for use of cloud services
Purpose
To specify and manage information security for the use of cloud services.
Governance Considerations
Organisations should be able to articulate the following, in relation to cloud services
- Security and assurances requirements
- Selection criteria and scope
- Roles and responsibilities for users
- How controls are segregated with the organisation
- How controls, interfaces and changes are managed on different vendors
- How security incidents are handled
- The approach used for monitoring, reviewing and evaluating vendors
- An exit strategy
Vendor Solution Considerations
Vendor agreements should contain provisions for the following
- Use of accepted industry standards
- Access control mechanisms
- Malware protection mechanisms
- Option to store sensitive data in specific jurisdictions
- Dedicated support for security incidents
- Information security requirements for subcontractors
- Support for timely exit scenarios
- Backup support
- Access to organisational data at termination
5.30 ICT readiness for business continuity
Purpose
To ensure the availability of the organization’s information and other associated assets during disruption.
Governance Considerations
Organisations need to conduct a Business Impact Analysis (BIA) to determine the following
- Recovery Time Objective (RTO) - the amount of time after a disaster in which business operation is restored or resources are again available for use
- Recovery Point Objective (RPO) - how much information loss the organisation can afford
Vendor Solution Considerations
Solutions should ensure
- Services are categorised against criticality, performance and capacity
- Timeframes are achievement based on the agreed RTO
- Staff are competent and have adequate authroity to restore critical services
- Thresholds are defined for incidents that may lead to disruption
7.4 Physical security monitoring
Purpose
To detect and deter unauthorized physical access.
Governance Considerations
Organisations need to ensure the following
- Local laws and regulations are complied with
- Design of monitoring is kept confidential
- Mointoring systems should be protected against unauthroised access
Vendor Solution Considerations
Vendors could include the following types of monitoring
- Video surveillance
- Motion, contact and sound detectors
8.9 Configuration management
Purpose
To ensure hardware, software, services and networks function correctly with required security settings, and configuration is not altered by unauthorized or incorrect changes.
Governance Considerations
Organisations need to ensure the following
- Configuration management is applied across hardware, software, networks and other systems
- Standard templates are used
Vendor Solution Considerations
Vendor solutions should include the following features
- Audit Logging
- Asset owner records
- Template version control
- Ability to cross reference against other assets
8.10 Information deletion
Purpose
To prevent unnecessary exposure of sensitive information and to comply with legal, statutory, regulatory and contractual requirements for information deletion.
Governance Considerations
Organisations need to ensure the following
- Deletion methods are appropriate for each type of data and medium
- Evidence is collected on deletions
- Local laws and regulations are followed
Vendor Solution Considerations
Vendor solutions should allow the following
- Determining when deletions occur
- Removal of obselete records, files and copies
- Guaranteed permanence of deletions
- Use of certified disposal providers
- Disposal mechanisms for different types of medium
8.11 Data Masking
Purpose
To limit the exposure of sensitive data including PII, and to comply with legal, statutory, regulatory and contractual requirements.
Governance Considerations
Organisations need to ensure the following exist
- A framework for determining the strength required for data masking, pseudonymization or anonymization
- Access controls mechanisms for data access
- Agreements and restrictions on access
- Prevention of re-identification mechanisms
- Audit trail for processed data
Vendor Solution Considerations
Vendor solution techniques to look out for
- Pseudonymisation of field values
- Anonymisation of field values
- Encryption of field values
- Deletion of field values
- Variation of field values
- Hashing of field values
8.12 Data leakage prevention
Purpose
To detect and prevent the unauthorized disclosure and extraction of information by individuals or systems.
Governance Considerations
Organisations need to ensure the following
- Information is properly classified
- All channels for data leakage are monitored
- Have measures to prevent leakage
- Local laws and regulations are followed
Vendor Solution Considerations
Vendor solutions should allow the following
- Identification and monitoring of unauthorised disclosures
- Detection of sensitive data leakage
- Blockage of user and networks enabling leakage
8.16 Monitoring activities
Purpose
To detect anomalous behaviour and potential information security incidents.
Governance Considerations
Organisations need to ensure the following
- Monitoring scope and level are in accordance with business and legal requirements
- Retention periods are applied to monitored records
- Baselines are established to determine anomalies
Vendor Solution Considerations
Vendor solutions should allow monitoring of the following
- network and application traffic
- access
- critical systems and files
- logs
- code execution permissions
- resource utilisation
8.23 Web filtering
Purpose
To protect systems from being compromised by malware and to prevent access to unauthorized web resources.
Governance Considerations
Organisations need to ensure the following
- Specific websites can be blocked
- Rules exist to define appropriate use
Vendor Solution Considerations
Vendor solutions should allow filtering based on the following
- IP address
- Domain
- Categories of undesirable websites
8.28 Secure coding
Purpose
To ensure software is written securely thereby reducing the number of potential information security vulnerabilities in the software.
Governance Considerations
Organisations need to ensure the following exist
- Established practices and processes
- Eastablished baselines
- Rules on use of third party components
- Monitoring of threats and vulnerabilities
Vendor Solution Considerations
Vendor solutions should allow the following
- Testing during and after devlopment
- Integration of processes at planning, coding and maintenance stage
© 2023
